Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 80/129
9.8
CVE-2026-50774

An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.

9.8
CVE-2026-50775

A blind SSRF attack in DataHub v.1.5.0.1 allows a remote attacker to execute arbitrary code via the server retrieving an

9.8
CVE-2026-67678

File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 allows a remote attacker to execute arbitrary code

9.8
CVE-2026-68004

An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 allows a remote attacker to execute arbitrary code via RTMP pub

9.8
CVE-2026-39254

Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via

9.8
CVE-2026-39255

Buffer Overflow vulnerability in SteelSeries GG (macOS) v.107.0.0 allows a remote attacker to execute arbitrary code via

9.8
CVE-2026-47698

vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.6, lib/bridge.js and lib/setup-sandbox.js fail to block stac

9.8
CVE-2026-67917

zuraCast versions up to and including 0.23.7 contain a SQL injection vulnerability in the backup restore functionality.

9.8
CVE-2026-67926

An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI

9.8
CVE-2026-67965

An issue in Tneda W20E v.16.01.0.6(2782) allows a remote attacker to execute arbitrary code via the url_need_login funct

9.8
CVE-2026-67966

Tenda W20E V16.01.0.6(2782) /goform/telnet endpoint allows unauthenticated remote attackers to activate the Telnet daemo

9.8
CVE-2026-67967

Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) allows an attacker to execute arbitrary code. This is an in

9.8
CVE-2026-75110

MemOS is a memory operating system for LLMs and AI agents. In deployments where authentication is enabled (AUTH_ENABLED=

9.8
CVE-2026-42163

Mahara before 25.04.5 and 26.04.0 is vulnerable to unauthorized access to internal accounts via Learning Tools Interoper

9.8
CVE-2026-67854

SQL Injection vulnerability in Qcms v.6.0.6 allows a remote attacker to execute arbitrary code

9.8
CVE-2026-67868

A heap-based out-of-bounds write vulnerability exists in S2OPC 1.7.3 in server-side EventFilter handling during CreateMo

9.8
CVE-2026-67960

An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.

9.8
CVE-2026-38165

A Server-Side Template Injection (SSTI) vulnerability in the Velocity template engine configuration of xdocreport v0.9.2

9.8
CVE-2026-42164

Mahara before 25.04.5 and 26.04.0 is vulnerable in the Text block/section functionality when a call is crafted in a cert

9.8
CVE-2026-67919

An issue in Halo 2.25.4 allows a remote attacker to execute arbitrary code via the PluginEndpoint.java, installFromUri m

9.8
CVE-2026-15748

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1

9.8
CVE-2026-34884

SSRF via set_skywalking_url Tool and GraphQL expression injection vulnerability in Apache SkyWalking MCP. This issu

9.8
CVE-2026-75627

Bastillion fails to properly validate request URI paths in its controller dispatcher, allowing unauthenticated attackers

9.8
CVE-2026-75852

ArcadeDB versions before 26.8.1 fail to enforce SASL authentication on data commands in the MongoDB wire-protocol plugin

9.8
CVE-2026-75854

ArcadeDB versions before 26.8.1 contain a missing authentication vulnerability in the Redis wire-protocol plugin that al

9.8
CVE-2026-74936

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14

9.8
CVE-2026-74940

Use-after-free in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firefox

9.8
CVE-2026-74943

Use-after-free in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Fir

9.8
CVE-2026-74944

Use-after-free in the DOM: Core & HTML component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firef

9.8
CVE-2026-74964

Integer overflow in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 140.14, Firefox ESR

9.8
CVE-2026-74979

Mitigation bypass in the Add-ons Manager component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thun

9.8
CVE-2026-74985

Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.

9.8
CVE-2026-74987

Internally found bugs present in Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of these bugs showed eviden

9.8
CVE-2026-74988

Internally found bugs present in Firefox ESR 153.0 and Firefox 153. Some of these bugs showed evidence of memory corrupt

9.8
CVE-2026-74989

Internally found bugs present in Firefox 153. Some of these bugs showed evidence of memory corruption or another securit

9.8
CVE-2026-74990

Internally found bugs present in Firefox ESR 115.38, Firefox ESR 140.13, Firefox ESR 153.0 and Firefox 153. Some of thes

9.8
CVE-2026-32470

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

9.8
CVE-2026-59940

Seroval facilitates JS value stringification, including complex structures beyond JSON.stringify capabilities. Prior to

9.8
CVE-2026-73341

Unauthenticated PHP Object Injection in RegistrationMagic <= 6.0.9.7 versions.

9.8
CVE-2026-73366

Unauthenticated PHP Object Injection in Easy Google Maps <= 1.13.0 versions.

9.8
CVE-2026-73376

Unauthenticated PHP Object Injection in Ultimate Maps by Supsystic < 1.5.0 versions.

9.8
CVE-2026-73380

Unauthenticated PHP Object Injection in Popup by Supsystic <= 1.13.0 versions.

9.8
CVE-2026-73397

Unauthenticated Deserialization of untrusted data in Youzify <= 1.3.7 versions.

9.8
CVE-2026-73996

Unauthenticated Arbitrary File Upload in Masteriyo - LMS <= 2.3.2 versions.

9.8
CVE-2026-45117

MyBB is free and open source forum software. From 1.8.13 until 1.8.40, the installer module does not properly escape use

9.8
CVE-2026-67271

Dell PowerStore SDNAS, contains an Out-of-bounds Write vulnerability in the SMB/CIFS. An unauthenticated attacker with r

9.8
CVE-2021-43716

Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector

9.8
CVE-2021-43717

An issue exists in pson EH-TW5350 Epson iProjection.apk v3.2.6. If you identify a projector equipped with an iProjection

9.8
CVE-2026-52608

An incorrect access control vulnerability in reportico-web <= 8.1.0 allows an unauthenticated attacker to inject arbitra

9.8
CVE-2026-47627

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause path traversal. A succes

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started