Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 82/436
6.5
CVE-2026-17348

In SERVER mode, pgAdmin 4 enforces authentication per route via the @pga_login_required decorator; the application's bef

6.5
CVE-2026-52371

A Server-Side Request Forgery (SSRF) in the xxl-job-admin/jobinfo/trigger component of xxl-job v3.4.0 allows authenticat

6.5
CVE-2026-45377

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3

6.5
CVE-2026-13329

The Buckaroo Woocommerce Payments Plugin WordPress plugin before 4.9.0 does not perform any capability check or nonce va

6.5
CVE-2026-14315

The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an authorization check on one of i

6.5
CVE-2026-14561

The Authora : Easy login with mobile number WordPress plugin before 1.7.7 does not keep its one-time login code confiden

6.5
CVE-2026-16087

The Icegram Engage – Popups, Optins, CTAs & Lead Generation plugin for WordPress is vulnerable to second-order SQL Injec

6.5
CVE-2026-17580

The Advanced Views – Display Custom Fields (ACF, Pods, MetaBox), Posts, CPT and Woo Products anywhere in Gutenberg, Elem

6.5
CVE-2026-6453

The CubeWP Framework plugin for WordPress is vulnerable to SQL Injection in all versions up to and including 1.1.30. Thi

6.5
CVE-2026-2411

Zephyr's Bluetooth host declares a GATT characteristic as two consecutive attributes: a Characteristic Declaration whose

6.5
CVE-2026-67292

FreeRDP before 3.29.0 contains a buffer over-disclosure vulnerability in the gateway WebSocket transport (libfreerdp/cor

6.5
CVE-2026-67337

better-auth versions before 1.4.9 contain a two-factor authentication bypass vulnerability when session.cookieCache is e

6.5
CVE-2026-9335

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improp

6.5
CVE-2026-13389

The webtoffee-cookie-consent WordPress plugin before 3.5.3 does not perform authorization checks on several of its REST

6.5
CVE-2026-18572

Keycloak provides authorization services that allow administrators to restrict access to resources based on time policie

6.5
CVE-2026-18573

A flaw was found in the keycloak-services component of Keycloak, which is used for managing authentication and authoriza

6.5
CVE-2026-68582

Vikunja versions >= 0.24.0 and <= 2.3.0 contain a broken object level authorization (BOLA) vulnerability in the task-col

6.5
CVE-2026-59638

In Bouncy Castle for Java before 1.85, JSSE hostname verifier CN-fallback enabled by default despite documented opt-in.

6.5
CVE-2026-20464

In hevc decoder, there is a possible out of bounds write due to an integer overflow. This could lead to remote escalatio

6.5
CVE-2026-20482

In wlan STA FW, there is a possible system becoming unresponsive due to logging. This could lead to remote (proximal/adj

6.5
CVE-2026-15254

The Simply Schedule Appointments WordPress plugin before 1.6.12.11 does not perform a capability check on an administrat

6.5
CVE-2026-16057

The Contest Gallery WordPress plugin before 30.0.7 does not perform per-object capability or nonce checks in one of its

6.5
CVE-2026-16563

The Academy LMS WordPress plugin before 3.8.3 does not verify course enrollment or lesson publication status when return

6.5
CVE-2026-63563

Sharp and Toshiba Tec MFPs (multifunction printers) for a certain market have been shipped with the user authentication

6.5
CVE-2026-69087

The Grav form plugin (getgrav/grav-plugin-form) before 9.1.13 contains an open redirect vulnerability. Since v9.1.11, th

6.5
CVE-2026-69092

Admidio versions before 5.0.11 contain a reflected cross-site scripting vulnerability in the SSO/SAML endpoint that echo

6.5
CVE-2026-68930

Russh is a Rust SSH client & server library. Prior to 0.62.5, russh dispatches channel-scoped Handler callbacks for reci

6.5
CVE-2025-9291

A certification validation weakness exists in communication between affected Omada devices and cloud controllers. Certif

6.5
CVE-2026-18655

Improper restriction of intended endpoints in the RabbitMQ broker connection tools of the Amazon MQ MCP Server (awslabs.

6.5
CVE-2026-58139

The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with S

6.5
CVE-2026-18737

Shlink contains a blind SQL injection vulnerability that allows any authenticated API key holder to inject arbitrary SQL

6.5
CVE-2026-69245

Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, SetCookie::matchesDomain() gives every subdomain of

6.5
CVE-2026-66312

Buffer over-read in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

6.5
CVE-2026-66314

Time-of-check time-of-use (toctou) race condition in Microsoft Edge (Chromium-based) allows an unauthorized attacker to

6.5
CVE-2026-66326

Missing authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to execute code over a network.

6.5
CVE-2026-8508

An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions throug

6.5
CVE-2026-14816

The GDPR Framework By Data443 WordPress plugin before 2.4.0 does not properly verify authorization or the identity of th

6.5
CVE-2026-16548

The Chat Widget: Floating Customer Support Button for 30+ Channels, Supporting SMS, Calls, and Chat WordPress plugin be

6.5
CVE-2026-14194

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bilin Software and Infor

6.5
CVE-2026-14465

Insufficient session expiration vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human

6.5
CVE-2026-18772

Improperly controlled sequential memory allocation vulnerability in Samsung Open Source rlottie allows Exponential Data

6.5
CVE-2026-18809

Information disclosure in Firefox for Android and Firefox Focus for Android. This vulnerability was fixed in Firefox 153

6.5
CVE-2026-63248

In Eclipse Milo versions 0.6.0 through 1.1.4, OPC UA server diagnostics nodes do not enforce access authorization. An an

6.5
CVE-2026-70368

A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log m

6.5
CVE-2026-67199

Perspective 5.0.0 contains a denial of service vulnerability that allows remote attackers to block the server event loop

6.5
CVE-2026-67618

marimo before 0.23.15 contains a configuration injection vulnerability that allows notebook authors to exfiltrate operat

6.5
CVE-2026-24077

Information Disclosure when processing wireless network channel switch information with improperly formatted length fiel

6.5
CVE-2026-24078

Information Disclosure when IPSec negotiation fails or is not established properly during NG-eCall SIP signaling.

6.5
CVE-2026-47620

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing

6.5
CVE-2026-47621

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause a race condition in the LoRA manager sing

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started