Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

4,548 of 57,566 · Page 81/91
CVE-2026-74722

In the Linux kernel, the following vulnerability has been resolved: btrfs: fix memory leak in btrfs_do_encoded_write()

CVE-2026-74728

In the Linux kernel, the following vulnerability has been resolved: xfs: handle NULL b_addr in xfs_buf_free When xfs_b

CVE-2026-74729

In the Linux kernel, the following vulnerability has been resolved: soc: aspeed: lpc-snoop: Fix usercopy overflow in sn

CVE-2026-74732

In the Linux kernel, the following vulnerability has been resolved: drm/amd/display: Check for tg ops in dce110_set_avm

CVE-2026-77993

Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extension Page Builder CK is vuln

CVE-2026-77994

Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The Joomla extension Page Build

CVE-2026-78255

The HTTP media server running on DJI drones serves stored photos and videos through the `/v2` endpoint without authentic

CVE-2026-78306

DJI drones expose an unauthenticated DUML command interface over Bluetooth that allows an attacker within Bluetooth rang

CVE-2026-78321

The HTTP media server on DJI drones does not enforce sufficient limits on incoming connections or request rates. An atta

CVE-2026-78337

Unrestricted Upload of File with Dangerous Type in the company logo upload in Roskus Prospero Flow CRM before 5.15.13 al

CVE-2025-63080

Firmware in KAON PG5298A and PG5298B routers allow an authenticated user to send crafted JSON-RPC requests and perform o

CVE-2026-6017

Firmware in KAON PG5298A and PG5298B routers allow an unauthenticated user to query a specific endpoint and acquire sens

CVE-2026-78365

Authorization Bypass Through User-Controlled Key in the supplier API in Roskus Prospero Flow CRM 4.0.0 through 5.3.1 all

CVE-2026-77995

Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0 - The manipulation of

CVE-2026-78369

RansomLook contains a missing authentication vulnerability in the /admin/crypto/group/new endpoint. While the endpoint p

CVE-2026-78370

RansomLook contains an authorization flaw in its legacy database export functionality that can allow unauthenticated rem

CVE-2026-78372

RansomLook does not consistently enforce authorization checks when accessing groups, markets, and ransom notes marked

CVE-2026-78378

Ransomlook contains a Redis glob pattern injection vulnerability caused by insufficient neutralization of user-controlle

CVE-2026-78380

RansomLook fails to enforce the privacy status of ransomware groups and markets when distributing newly collected victim

CVE-2026-78381

RansomLook contains a path traversal vulnerability in the handling of the screen field associated with group posts. The

CVE-2026-78385

RansomLook contains insufficient resource validation in the analysis PDF generation functionality. Analysis documents ar

CVE-2026-78386

RansomLook exposed sensitive operator-side scraping configuration through multiple unauthenticated API responses. Locati

CVE-2026-76054

Invocation of Process Using Visible Sensitive Information in Black Duck blackduck-c-cpp 1.0.17 through 3.0.6 allows an a

CVE-2026-76055

Improper Neutralization of Special Elements used in an OS Command in the package manager component of Black Duck blackdu

CVE-2026-78387

RansomLook contains an authorization weakness in the web-based configuration editor exposed through the /admin/config en

CVE-2026-78391

RansomLook contains a stored cross-site scripting (XSS) vulnerability in the cryptocurrency wallet detail view. Cryptocu

CVE-2026-12554

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. The

CVE-2026-12555

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. The

CVE-2026-12556

Potential security vulnerabilities have been identified in HP Easy Start for macOS, versions prior to 2.16.7.260722. The

CVE-2026-78416

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code ex

CVE-2025-36939

Multiple vulnerabilities exist in OpenThread's handling of MLE packets. An authenticated attacker on the same Thread net

CVE-2026-15469

The use of hard-coded cryptographic key vulnerability has been identified in the mesh functionality of Deco XE75 v3, XE5

CVE-2026-18349

Improper protection against voltage and clock glitches vulnerability in Microchip SAMA5D4 allows Hardware Fault Injectio

CVE-2026-16348

An authenticated command injection vulnerability in TP-Link Archer BE800 V1 allows an attacker with administrative acces

CVE-2026-34491

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls M

CVE-2026-9254

An unauthenticated OS command injection vulnerability exists in the parental control functionality of Archer BE800 V1, B

CVE-2026-39975

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly

CVE-2026-78541

A stored OS command injection vulnerability exists in the parent-control module of TP-Link Archer BE3600 V1. An authenti

CVE-2026-78551

RansomLook contains multiple weaknesses in its authentication endpoint that allow an unauthenticated remote attacker to

CVE-2026-78553

RansomLook created its Flask session-signing key without explicitly restricting the file permissions. The secret_key fil

CVE-2026-78555

RansomLook exposed complete API keys in the HTML source of the authenticated /admin/apikeys administration page. Althoug

CVE-2026-75542

Incorrect Authorization vulnerability in the OAuth token endpoint in hexpm hexpm allows an API key holding the repositor

CVE-2026-75554

Insufficient Session Expiration vulnerability in the OAuth token refresh grant in hexpm hexpm allows a user removed from

CVE-2026-77634

CakePHP is a rapid development framework for PHP. Prior to versions 4.5.12, 4.6.5, 5.1.8, 5.2.14, and 5.3.7 on their res

CVE-2026-77635

CakePHP is a rapid development framework for PHP. Prior to versions 5.1.10, 5.2.15, and 5.3.7 on their respective releas

CVE-2026-45404

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From version 0.11.0 through 1.44.0, the OpenTracing bridge's

CVE-2026-77337

CakePHP Authentication is an authentication plugin for CakePHP that can also be used in PSR-7 based applications. Versio

CVE-2026-53532

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

CVE-2026-55371

OpenEXR is the reference implementation and specification for the EXR high-dynamic-range image file format, widely used

CVE-2026-16434

Adminer 4.6.0 through 5.5.0 (fixed in 5.5.1) contains an incomplete fix for a prior X-Forwarded-Prefix vulnerability (GH

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started