Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 777/1152
5.8
CVE-2026-57691

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eli Anti-Malware S

5.8
CVE-2026-47160

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.36.0, Vaultwarden's /icons/{domain}/icon.png en

5.8
CVE-2026-62314

Anubis is a Web AI Firewall Utility that challenges users' connections in order to protect upstream resources from scrap

5.8
CVE-2026-63096

Dendrite through 0.13.8 contains a server-side request forgery vulnerability that allows unauthenticated attackers to ca

5.8
CVE-2026-45709

Mailpit is an email testing tool and API for developers. The fix for GHSA-6jxm-fv7w-rw5j (CVE-2026-23845, "Server-Side R

5.8
CVE-2026-63428

HeyForm is an open-source form builder. Prior to version 3.0.0-rc.9, `completeSubmission` accepts a `hiddenFields: [{id,

5.8
CVE-2026-15811

A vulnerability was found in kronosnet's (version <=1.34) cryptographic configuration management. The framework does not

5.8
CVE-2026-46975

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 19.3-19.31, 21

5.8
CVE-2026-61079

Vulnerability in Oracle GoldenGate (component: Libraries). Supported versions that are affected are 19.1.0.0.0-19.30.0.

5.8
CVE-2026-63226

Printers and Multifunction Printers (MFPs) provided by Ricoh Company, Ltd. do not implement restrictions on SSH port for

5.8
CVE-2026-9680

Improper exposure of the MCP server in alibabacloud-rds-openapi-mcp-server allows remote attackers to invoke exposed MCP

5.8
CVE-2026-17736

Insufficient validation of untrusted input in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remot

5.8
CVE-2026-17745

Out of bounds read in Skia in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the ren

5.8
CVE-2026-17746

Use after free in GPU in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised the r

5.8
CVE-2026-17770

Out of bounds read in Media in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker who had compromised

5.8
CVE-2026-17776

Policy bypass in Receiver in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rend

5.8
CVE-2026-17806

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack

5.8
CVE-2026-17809

Insufficient validation of untrusted input in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attack

5.8
CVE-2026-17866

Type Confusion in Tab in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised t

5.8
CVE-2026-17890

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

5.8
CVE-2026-17891

Use after free in ANGLE in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker who had compromised

5.8
CVE-2026-17893

Insufficient validation of untrusted input in Updater in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote at

5.8
CVE-2026-17906

Insufficient validation of untrusted input in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacke

5.8
CVE-2026-17908

Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 151.0.7922.72 allowed a remo

5.8
CVE-2026-18369

A flaw was found in Dogtag PKI's ACME responder where the HTTP-01 challenge validator accepts IP address literals as dns

5.8
CVE-2026-10686

Zephyr's IPv6 forwarding path re-sent routed unicast packets without ever decrementing the IPv6 hop limit. Both routing

5.8
CVE-2026-68585

SiYuan versions before v3.7.3 contain a metadata disclosure vulnerability in the /api/block/getBlockInfo endpoint that r

5.8
CVE-2026-10526

The EmbedPress WordPress plugin before 4.6.1 does not validate user-supplied URLs before making server-side requests th

5.8
CVE-2026-48071

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

5.8
CVE-2026-16949

The Term Pages WordPress plugin before 2.0.0 does not properly sanitise and escape a parameter before using it in a SQL

5.8
CVE-2026-71959

Bitwarden Server before 2026.7.2 does not verify that the caller is a member of the organization identified in a POST /c

5.8
CVE-2026-73243

kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /add

5.8
CVE-2026-72788

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the UILayout filter that fails to prope

5.8
CVE-2026-72790

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/notebook/getNotebookInfo endpoint that

5.8
CVE-2026-72791

SiYuan v3.7.4-alpha.1 (a pre-release; the endpoint does not exist in stable v3.7.3 or earlier) contains an information d

5.8
CVE-2026-72792

SiYuan before v3.7.4 contains an information disclosure vulnerability in the /api/tag/getTag endpoint that returns tag l

5.8
CVE-2026-72796

SiYuan before v3.7.4 contains an access control bypass vulnerability where static-file routes in the server mux bypass p

5.8
CVE-2026-72797

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getEncryptedNotebookStatus endpoint

5.8
CVE-2026-72799

SiYuan before v3.7.4 (affected <=v3.7.2) fails to enforce publish-access filters on five filetree path-resolution endpoi

5.8
CVE-2026-72800

SiYuan versions before v3.7.4 fail to apply publish-access filtering to the getAttributeViewKeysByID endpoint, allowing

5.8
CVE-2026-72803

SiYuan versions before v3.7.4 fail to enforce publish-access checks in the getBlockAttrs and batchGetBlockAttrs endpoint

5.8
CVE-2026-72805

SiYuan versions before v3.7.4 fail to enforce publish-access checks on getBlockBreadcrumb, getRefText, and getBlockTreeI

5.8
CVE-2026-72806

SiYuan versions before v3.7.4 contain an authentication bypass vulnerability in the FilterViewByPublishAccess filter tha

5.8
CVE-2026-72808

SiYuan versions up to and including v3.7.2 (fixed in v3.7.4) contain an information disclosure vulnerability in the /api

5.8
CVE-2026-19130

A flaw was found in the provider-credential-controller component of multicluster-engine (MCE). An attacker with specific

5.8
CVE-2026-73605

SiYuan versions before v3.7.4 contain a path traversal vulnerability in the getUniqueFilename endpoint that allows anony

5.8
CVE-2026-73606

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/block/getRefIDs endpoint that

5.8
CVE-2026-73607

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the /api/storage/getOutlineStorage endp

5.8
CVE-2026-73609

SiYuan versions before v3.7.4 contain an information disclosure vulnerability in the getBookmarkLabels endpoint that ret

5.8
CVE-2026-73610

SiYuan before v3.7.4 contains an information disclosure vulnerability in the local storage filter that returns the admin

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started