Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

4,548 of 57,566 · Page 82/91
CVE-2026-65633

Improper Authentication vulnerability in team-alembic AshAuthentication allows purpose-limited JWTs to be replayed as fu

CVE-2026-66882

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in team-alembic AshAuthentication allows

CVE-2026-17548

Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50 and all 2.2.0 versions allows an authenticated user who

CVE-2026-56092

The extension forces empty frontend-group and subpage-inheritance restrictions onto page records during indexer sub-requ

CVE-2026-56093

The extension's frontend detail-view document lookup does not apply the current site's siteHash filter or frontend user

CVE-2026-56094

The extension allows a request-provided additionalFilters parameter to register a named siteHash filter before the syste

CVE-2026-56095

The extension's indexer passed every field value returned by content object rendering through PHP's unserialize() functi

CVE-2026-56096

The extension passes the user-supplied search query parameter to Apache Solr without restricting advanced Solr query syn

CVE-2026-77127

The extension fails to restrict a backend AJAX endpoint for inline editing to fields the current user is permitted to se

CVE-2026-77128

The extension fails to enforce enable-field restrictions on a repository query parameter. An unauthenticated remote user

CVE-2026-77129

The extension passes an editor-configurable email subject string directly into a Fluid template source without restricti

CVE-2026-77130

The extension fails to properly validate the expiration of a client-supplied JWT token, allowing an attacker in control

CVE-2026-77131

When OpenSSL is unavailable on the server, the extension transmits TYPO3 system information in cleartext instead of encr

CVE-2026-77133

The extension fails to restrict which frontend usergroups a logged-in user may assign to their own account when the prof

CVE-2026-77134

The extension fails to require the dedicated admin confirmation token when processing an admin-approval request, so a re

CVE-2026-77135

The extension's user detail view fails to verify that a requested user record matches the configured or logged-in target

CVE-2026-77136

The extension passes the raw value of a form field configured as "This field contains the name of the sender" directly i

CVE-2026-77137

The extension fails to properly sanitize user input before using it in a database query. As a result, a low-privileged b

CVE-2026-77138

The extension fails to safely process untrusted client input of an attacker-controlled cookie directly to PHP's unserial

CVE-2026-77139

The extension fails to validate a client-supplied template element key before using it to build file paths for saving an

CVE-2026-77140

The extension validates the HMAC of a frontend employee edit link only in the action that renders the edit form, not in

CVE-2026-77141

The extension resolves the targeted club record from a user-supplied request argument in its frontend edit, update, and

CVE-2026-77142

The frontend company self-service editing feature relies on a template-level visibility flag to hide the edit form for c

CVE-2026-77143

The frontend topic editing flow does not verify on the server side that the requesting visitor owns the topic being modi

CVE-2026-77144

The frontend management plugin attributed a newly created event to the submitting user's organizer record only when the

CVE-2026-77145

The permission check for the frontend management update flow verified a different event than the one the request went on

CVE-2026-77146

The extension's invitation controller fails to stop processing after redirecting on invalid input (missing hash, non-exi

CVE-2026-12878

In affected versions of the Codefresh platform an authenticated user can utilize an API endpoint to elevate to Admin per

CVE-2026-12600

Denial-of-service (DoS) vulnerability in the internal JPEG2000 (JPX) decoding implementation of the Poppler fork develop

CVE-2026-57909

A path traversal vulnerability in WatchGuard Agent allows a remote, unauthenticated attacker on an adjacent network to e

CVE-2026-57910

Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agen

CVE-2026-77996

Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5.0.41 - Lack of escaping i

CVE-2026-77997

Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme Pro 1.0.0-5.0.41 - A miss

CVE-2026-63073

Issue summary: OpenSSL CMP response validation passed an unexpected response sender distinguished name directly as the f

CVE-2026-75803

Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ciphertext can report success without verifying th

CVE-2026-77998

Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Parameter in miniOrange SAML

CVE-2026-15310

When decompressing crafted zip files using the bzip/LZMA/Zstandard compressions, Python could use an attacker-controll

CVE-2026-16599

GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY authentication functionality. The server-supplied sequ

CVE-2026-55541

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, praisonai serve agents and praisonai serve unified p

CVE-2026-55624

MintyItanium Lost-Auction is an auction plugin for Minecraft. Prior to commit 88c920b05042929db334ba06d57f052b42d6b3f8,

CVE-2026-55580

mcp-shell is an MCP server for running shell commands securely, auditably, and on demand. Prior to 0.6.0, config.go init

CVE-2026-19912

The Kaltura HTML5 player (mwEmbed / html5lib) contains an unauthenticated remote code execution vulnerability caused by

CVE-2026-55557

browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download wr

CVE-2026-55637

genieacs-mcp is an MCP server for GenieACS written in Go. Prior to 0.3.2, the Streamable HTTP transport in cmd/server/ma

CVE-2026-80051

github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not validate that a scalar variable value matches its

CVE-2026-65979

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

CVE-2026-39113

Buffer Overflow vulnerability in SQLite affected version source snapshots/builds containing Fossil check-in 8bdc0d485e3a

CVE-2026-51368

An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remot

CVE-2026-52489

Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de1c0f8fd9 allows an attacker to execute arbitrary c

CVE-2026-52491

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the libtif

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started