Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 8/436
6.8
CVE-2026-16559

The YMC Filter WordPress plugin before 3.12.9 does not sanitize SVG files uploaded through one of its icon upload featur

6.8
CVE-2026-15047

The s2Member WordPress plugin before 260805 does not escape several shortcode attributes before outputting them inside

6.8
CVE-2026-57279

Cybozu Garoon contains a cross-site scripting vulnerability. If this vulnerability is exploited, an arbitrary script may

6.8
CVE-2026-19278

A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configu

6.8
CVE-2026-57262

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). Affected products use a static, hardcoded

6.8
CVE-2026-57263

A vulnerability has been identified in LOGO! Soft Comfort (All versions < V9). The project password feature in the affec

6.8
CVE-2026-18636

The Velociraptor gRPC API has a VFSGetBuffer endpoint which allows reading files from the datastore. To prevent users fr

6.8
CVE-2026-62699

Heap-based buffer overflow in Windows Universal Disk Format File System Driver (UDFS) allows an unauthorized attacker to

6.8
CVE-2026-62702

Null pointer dereference in Windows Graphics Kernel allows an unauthorized attacker to deny service over a network.

6.8
CVE-2026-49349

regclient is a Docker and OCI Registry Client in Go. Prior to version 0.11.5, credentials for a registry may be inadvert

6.8
CVE-2026-65939

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can create a LogToFile action specifying an arb

6.8
CVE-2026-65940

In WhatsUp Gold versions released before 2026.0.2, a privileged attacker can write arbitrary files to a web-accessible l

6.8
CVE-2026-17268

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to bypass security restrictions due to improper

6.8
CVE-2026-17616

IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Ident

6.8
CVE-2026-73419

NextAuth.js provides authentication for Next.js. Prior to@auth/core 0.41.3 and next-auth 4.24.15 and 5.0.0-beta.32, Auth

6.8
CVE-2026-71194

In OpenStack Designate before 22.0.2, the mDNS handler performs pool-blind lookups when resolving record queries and NOT

6.8
CVE-2026-73611

File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configure

6.8
CVE-2026-58440

Webhooks created by a collaborator keep firing after their repo access is revoked → ongoing real-time exfiltration of pr

6.8
CVE-2026-72666

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to unauthorized query execution against El

6.8
CVE-2026-14290

The Embed Google Photos album WordPress plugin through 2.2.1 does not escape a shortcode attribute value before outputti

6.8
CVE-2026-72835

filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated u

6.8
CVE-2026-73847

Emlog is an open source website building system. In 2.6.26 and earlier, missing CSRF protection on the AI Assistant exec

6.8
CVE-2026-74984

Race condition in the JavaScript Engine component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thund

6.8
CVE-2026-50576

ePA 3.x Integration implements the authorization workflow and writes Medical Information Objects to Germany's electronic

6.8
CVE-2026-60865

Vulnerability in the Service Delivery Platform product of Oracle Fusion Middleware (component: Messaging Enabler). Supp

6.8
CVE-2026-60895

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

6.8
CVE-2026-61308

Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE

6.8
CVE-2026-70751

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported

6.8
CVE-2026-70780

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported

6.8
CVE-2026-70843

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

6.8
CVE-2026-70972

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

6.8
CVE-2026-70982

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.8
CVE-2026-70983

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.8
CVE-2026-70990

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.8
CVE-2026-71007

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.8
CVE-2026-71008

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

6.8
CVE-2026-71029

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

6.8
CVE-2026-71084

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that

6.8
CVE-2026-15253

The Easy Media Replace WordPress plugin through 0.2.0 does not sanitise and escape an attachment title before outputting

6.8
CVE-2026-18202

The JetEngine WordPress plugin before 3.8.14 adds SVG to the site-wide list of allowed upload types without sanitising t

6.8
CVE-2026-50719

The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table fr

6.8
CVE-2026-18681

IBM Server Firmware FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H2 i

6.8
CVE-2026-55088

Etherpad is a real-time collaborative editor. From 2.6.0 until 3.1.0, Etherpad's src/node/hooks/express/tokenTransfer.ts

6.8
CVE-2026-18849

IBM OpenBMC FW1060.00 through FW1060.80 is affected by a vulnerability in the BMC firmware update process. An attacker w

6.8
CVE-2026-76827

A flaw was found in search-indexer. This vulnerability allows a registered and authenticated managed cluster to tamper w

6.8
CVE-2026-76252

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.13, an unauthenticated user who tricks another user

6.8
CVE-2026-19615

The Admin and Site Enhancements (ASE) WordPress plugin before 9.0.1 does not sanitise uploaded SVG files on every route

6.8
CVE-2026-19697

The GutenKit WordPress plugin before 2.5.0 does not sanitise uploaded SVG files on all of the upload paths it enables,

6.8
CVE-2026-74992

The Kirki WordPress plugin before 6.2.3 does not properly validate the files contained in archives uploaded by users wi

6.8
CVE-2026-18267

Kenwood DNR1007XR Firmware Update Link Following Code Execution Vulnerability. This vulnerability allows physically pres

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started