Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 81/436
6.5
CVE-2026-17936

Inappropriate implementation in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who convinced

6.5
CVE-2026-17946

Uninitialized Use in Dawn in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had compromised the rend

6.5
CVE-2026-17953

Insufficient policy enforcement in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker

6.5
CVE-2026-17968

Uninitialized Use in WebXR in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to obtain potent

6.5
CVE-2026-17974

Insufficient policy enforcement in DevTools in Google Chrome prior to 151.0.7922.72 allowed a local attacker to bypass n

6.5
CVE-2026-17975

Inappropriate implementation in IME in Google Chrome on Mac prior to 151.0.7922.72 allowed a remote attacker to obtain p

6.5
CVE-2026-17985

Insufficient policy enforcement in Speech in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypass si

6.5
CVE-2026-17986

Insufficient policy enforcement in Bluetooth in Google Chrome prior to 151.0.7922.72 allowed a remote attacker who had c

6.5
CVE-2026-17988

Insufficient validation of untrusted input in Navigation in Google Chrome prior to 151.0.7922.72 allowed a remote attack

6.5
CVE-2026-17992

Uninitialized Use in Skia in Google Chrome on Windows prior to 151.0.7922.72 allowed a remote attacker to obtain potenti

6.5
CVE-2026-17999

Race in PictureInPicture in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to perform domain

6.5
CVE-2026-18001

Inappropriate implementation in WebGL in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potent

6.5
CVE-2026-18005

Inappropriate implementation in WebXR in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to obtain potent

6.5
CVE-2026-18014

Insufficient validation of untrusted input in DevTools in Google Chrome prior to 151.0.7922.72 allowed a remote attacker

6.5
CVE-2026-16092

The Improved Save Button plugin for WordPress is vulnerable to second-order SQL Injection via 'meta_key' Custom Field vi

6.5
CVE-2026-67246

A path traversal vulnerability was found in the Wallpaper component of ADM. The vulnerability occurs because user-contro

6.5
CVE-2026-67247

A path traversal vulnerability was found in the IHM Log handling of ADM. The vulnerability occurs because user-controlle

6.5
CVE-2026-11867

The Frontend Admin by DynamiApps WordPress plugin before 3.29.7 does not perform capability checks on its taxonomy term

6.5
CVE-2026-14923

The Sync Post With Other Site WordPress plugin before 1.9.3 does not correctly enforce the page-editing capability on a

6.5
CVE-2026-15382

The Ultimate Addons for WPBakery Page Builder WordPress plugin before 3.21.4 does not perform a capability or nonce chec

6.5
CVE-2026-16530

A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. A remote attacker can exploit a vulnerability in t

6.5
CVE-2026-54364

CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inj

6.5
CVE-2026-41187

Calico's apiserver wraps tier-scoped resources so that every operation runs through AuthorizeTierOperation, but the Dele

6.5
CVE-2026-15657

A vulnerability in the foreUP customer REST API allows any authenticated user to read cleartext payment-processor mercha

6.5
CVE-2026-23985

A Regular Expression Denial of Service (ReDoS) vulnerability exists in Apache Superset versions 1.5.0 through 5.0.0. The

6.5
CVE-2026-44616

LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupRealm constructed LDAP search filters without escap

6.5
CVE-2026-44617

LDAP filter injection vulnerability in Apache Zeppelin. LdapRealm used RFC 4514 distinguished-name escaping when constru

6.5
CVE-2026-48910

A carefully crafted editing request could trigger an XSS vulnerability on Apache JSPWiki when parsing errors on the mar

6.5
CVE-2026-10700

IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API th

6.5
CVE-2026-15974

SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitize

6.5
CVE-2026-68501

Sylius Mollie Plugin provides Mollie payment integration for Sylius applications. Prior to 2.2.8, 3.2.4, and 3.3.1, Syli

6.5
CVE-2026-64816

RapidRAW before 1.6.0 does not validate the lutPath field in preset files before passing it to File::open() in lut_proce

6.5
CVE-2026-56758

The ACSE layer contains a flaw in the processing of AARQ PDUs during MMS connection establishment. When parsing certain

6.5
CVE-2026-61893

A crafted IEC 60870-5-104 I-frame with TypeID 104 (C_TS_NA_1) and an inflated object count causes TestCommand_getFromBu

6.5
CVE-2026-63033

A crafted IEC 60870-5-104 I-frame with a declared object count exceeding what fits in the ASDU body causes InformationO

6.5
CVE-2026-63550

The MMS BER decoder contains a boundary-handling flaw in the processing of certain fields within confirmed-request mess

6.5
CVE-2026-65421

The MMS BER decoder contains a flaw in decoding fixed-width BER fields (boolean/integer): an attacker-supplied length v

6.5
CVE-2026-66349

The MMS server connection handler contains a flaw in its processing of BER-encoded request data. When an MMS confirmed

6.5
CVE-2026-66364

The GOOSE payload parser contains a boundary handling flaw that can be triggered by a single unauthenticated Layer 2 mu

6.5
CVE-2026-66369

The GOOSE parser contains an off-by-one boundary-handling flaw that can be triggered by a single unauthenticated Layer-

6.5
CVE-2026-66720

The GOOSE subscriber component improperly validates the UTC timestamp field in unauthenticated IEC 61850 GOOSE (EtherTy

6.5
CVE-2026-55497

Cloudreve is a self-hosted file management and sharing system. Prior to 4.17.0, the built-in thumbnail and avatar image

6.5
CVE-2026-14554

The Check & Log Email WordPress plugin before 2.0.15 does not properly sanitize and escape parameters before using them

6.5
CVE-2026-14834

The Mailgun for WordPress plugin before 2.2.1 does not perform any capability or nonce check on an unauthenticated AJAX

6.5
CVE-2026-14928

The JS Help Desk WordPress plugin before 3.1.4 does not perform authorization or ownership checks before returning supp

6.5
CVE-2026-14931

The JS Help Desk WordPress plugin before 3.1.4 grants a support-agent capability to the Contributor role on activation

6.5
CVE-2026-15209

The JS Help Desk WordPress plugin before 3.1.5 does not verify that the requesting user owns the ticket being loaded: a

6.5
CVE-2026-18203

A flaw was found in the group policy evaluation logic of Keycloak, an identity and access management solution. When a gr

6.5
CVE-2026-18208

A flaw was found in the OIDC token introspection endpoint of the keycloak-services component. Keycloak is an open-source

6.5
CVE-2026-44615

Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker wi

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started