Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 774/1152
5.9
CVE-2026-79676

NLTK versions before 3.10.3 contain a path traversal vulnerability in corpus readers that reopen root-derived paths usin

5.9
CVE-2026-79785

X-AnyLabeling's model downloader disabled TLS certificate verification. download_with_retry in anylabeling/services/auto

5.9
CVE-2026-13217

The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp.c reconstructs a session handle and PDU id from the uid field of a CALLR

5.9
CVE-2026-79013

Improper input validation in Sync in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive

5.9
CVE-2026-79122

Information leak in SignIn in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informa

5.9
CVE-2026-79126

Incorrect provision of specified functionality in Proxy in Google Chrome on on Windows prior to 152.0.7977.65 allowed an

5.9
CVE-2026-79208

Missing authorization in HTTP2 in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to leak sensitive infor

5.9
CVE-2026-80206

NLTK before 3.10.3 contains a regular expression denial of service (ReDoS) vulnerability in the tgrep module. The _tgrep

5.9
CVE-2026-32593

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th

5.9
CVE-2026-79940

Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions prior to 7.20.30.50, contains an Improper Access Con

5.9
CVE-2026-74774

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Improper Certificate Validation vulnerability. An unauthe

5.9
CVE-2026-47857

In Reactor Core, applications that use the Flux.windowTimeout operator with fairBackpressure enabled are vulnerable to a

5.9
CVE-2026-47863

In Reactor Core, applications that use the Flux.bufferTimeout operator with fairBackpressure enabled are vulnerable to a

5.9
CVE-2026-47881

Spring Batch's FlatFileItemReader supports files where a single logical record spans multiple physical lines — for examp

5.9
CVE-2026-76549

The UpdraftPlus: WP Backup & Migration Plugin WordPress plugin before 1.26.7 does not have CSRF checks in one of its bac

5.9
CVE-2026-75159

An unauthenticated client that can reach a MongoDB Connector for BI deployment configured with Kerberos authentication m

5.9
CVE-2026-80211

FrontAccounting through 2.4.20 stores and verifies user passwords as unsalted MD5 digests. admin/users.php passes md5($_

5.9
CVE-2026-59276

Several components in Spring Security compare security-sensitive values using standard string equality (String.equals())

5.9
CVE-2026-59294

ResourceCacheService.getCacheName() builds the on-disk filename by appending the URI fragment verbatim, without strippin

5.9
CVE-2026-80179

A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing

5.9
CVE-2026-33604

An attacker that can get Dovecot to relay a message, for example through Sieve redirect or submission relay, can use a c

5.9
CVE-2026-40019

An unauthenticated attacker can send a truncated quoted argument to the ManageSieve login process, which makes it spin i

5.9
CVE-2026-40205

An attacker that holds an OAuth2 token granting only part of the required scopes can authenticate, because when more tha

5.9
CVE-2026-82235

filebrowser through 2.63.23 fails to validate named pipes in directory archive and public download handlers, allowing at

5.9
CVE-2025-36271

IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could a

5.9
CVE-2025-36290

IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate valid

5.9
CVE-2025-64649

IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle te

5.9
CVE-2026-55854

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to

5.9
CVE-2026-55856

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3

5.9
CVE-2026-55857

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3

5.9
CVE-2026-55858

MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3

5.9
CVE-2026-55859

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2db

5.9
CVE-2026-55860

MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2db

5.8
CVE-2026-20026

Multiple Cisco products are affected by a vulnerability in the processing of DCE/RPC requests that could allow an u

5.8
CVE-2026-21859

Mailpit is an email testing tool and API for developers. Versions 1.28.0 and below have a Server-Side Request Forgery (S

5.8
CVE-2026-22772

Fulcio is a certificate authority for issuing code signing certificates for an OpenID Connect (OIDC) identity. Prior to

5.8
CVE-2025-60011

An Improper Check for Unusual or Exceptional Conditions vulnerability in the routing protocol daemon (rpd) of Juniper Ne

5.8
CVE-2025-12718

The Quick Contact Form plugin for WordPress is vulnerable to Open Mail Relay in all versions up to, and including, 8.2.6

5.8
CVE-2026-23845

Mailpit is an email testing tool and API for developers. Versions prior to 1.28.3 are vulnerable to Server-Side Request

5.8
CVE-2026-1180

A flaw was identified in Keycloak’s OpenID Connect Dynamic Client Registration feature when clients authenticate using p

5.8
CVE-2026-21927

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affec

5.8
CVE-2026-21935

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affec

5.8
CVE-2025-68898

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cjjparadoxmax Syne

5.8
CVE-2026-24137

sigstore framework is a common go library shared across sigstore services and clients. In versions 1.10.3 and below, the

5.8
CVE-2026-1467

A flaw was found in libsoup, an HTTP client library. This vulnerability, known as CRLF (Carriage Return Line Feed) Injec

5.8
CVE-2026-1536

A flaw was found in libsoup. An attacker who can control the input for the Content-Disposition header can inject CRLF (C

5.8
CVE-2026-1539

A flaw was found in the libsoup HTTP library that can cause proxy authentication credentials to be sent to unintended de

5.8
CVE-2026-24928

Out-of-bounds write vulnerability in the file system module. Impact: Successful exploitation of this vulnerability may a

5.8
CVE-2026-25904

The Pydantic-AI MCP Run Python tool configures the Deno sandbox with an overly permissive configuration that allows the

5.8
CVE-2026-25905

The Python code being run by 'runPython' or 'runPythonAsync' is not isolated from the rest of the JS code, allowing any

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started