Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 83/129
9.8
CVE-2026-66583

Unauthenticated PHP Object Injection in Forminator <= 1.57.0 versions.

9.8
CVE-2026-66672

Unauthenticated PHP Object Injection in Flatastic <= 2.0 versions.

9.8
CVE-2026-66682

Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.

9.8
CVE-2026-73993

Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.

9.8
CVE-2026-74001

Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.

9.8
CVE-2026-18482

Neo.mjs contains a command injection vulnerability within the FileSystemService.mjs component of the ai/mcp/server/file-

9.8
CVE-2026-15706

Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Bayla

9.8
CVE-2026-63037

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi

9.8
CVE-2026-63038

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi

9.8
CVE-2026-63039

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache InLong. Thi

9.8
CVE-2026-18265

OSNEXUS QuantaStor Missing Authentication Remote Code Execution Vulnerability. This vulnerability allows remote attacker

9.8
CVE-2026-55642

dbx is a cross-platform database client for databases. Prior to 0.5.51, dbx-web auth_middleware in crates/dbx-web/src/au

9.8
CVE-2026-43798

A single crafted SSH message gives an unauthenticated network attacker an out-of-bounds stack write of attacker-controll

9.8
CVE-2026-17040

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov

9.8
CVE-2026-17118

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a use-after

9.8
CVE-2026-17122

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack-bas

9.8
CVE-2026-17136

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a format st

9.8
CVE-2026-17141

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov

9.8
CVE-2026-17142

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary commands due to imprope

9.8
CVE-2026-17145

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to improper pr

9.8
CVE-2026-17152

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a buffer ov

9.8
CVE-2026-17157

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to a stack buf

9.8
CVE-2026-17160

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to execute arbitrary code due to an integer

9.8
CVE-2026-72843

The customer update route in EverShop is declared with "access": "public" in packages/evershop/src/modules/customer/api/

9.8
CVE-2026-77647

SPIP before 4.4.20 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August

9.8
CVE-2026-77649

The internment crate 0.8.7 for Rust can trigger execution of malicious code when compiling a project that uses the crate

9.8
CVE-2026-77650

The append-only-vec crate 0.1.9 for Rust can trigger execution of malicious code when compiling a project that uses the

9.8
CVE-2026-77651

The arrayref crate 0.3.10 for Rust can trigger execution of malicious code when compiling a project that uses the crate,

9.8
CVE-2026-77264

The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulne

9.8
CVE-2026-77806

SPIP before 4.4.21 allows unauthenticated remote attackers to execute arbitrary code, as exploited in the wild in August

9.8
CVE-2026-74581

In the Linux kernel, the following vulnerability has been resolved: net: ipv6: clear suppressed fib6 rule result fib6_

9.8
CVE-2026-76904

GeoTools is an open source Java library that provides tools for geospatial data. Starting in version 30.5 and prior to v

9.8
CVE-2026-77000

The WP Social Media Login WordPress plugin through 1.0.6 does not verify that a social login was actually completed with

9.8
CVE-2026-77001

The Social Login & Sharing buttons with Analytics By SoClever WordPress plugin through 1.2.0 does not perform any authen

9.8
CVE-2026-77002

The SmilePass Selfie Login WordPress plugin through 1.0.2 does not perform any server-side verification of the identity

9.8
CVE-2026-78003

The Mailgun for WordPress plugin for WordPress is vulnerable to Server-Side Request Forgery (SSRF) via path traversal in

9.8
CVE-2026-4703

The WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress is vulnerable to PHP Object Injection in all ve

9.8
CVE-2026-74586

In the Linux kernel, the following vulnerability has been resolved: sctp: clear new_transport when removing a peer sct

9.8
CVE-2026-74587

In the Linux kernel, the following vulnerability has been resolved: sctp: fix use-after-free of cached ASCONF chunk ad

9.8
CVE-2026-74588

In the Linux kernel, the following vulnerability has been resolved: sctp: keep chunk->transport in step with the list i

9.8
CVE-2026-74591

In the Linux kernel, the following vulnerability has been resolved: mm/filemap: __filemap_add_folio() restore index bef

9.8
CVE-2026-74597

In the Linux kernel, the following vulnerability has been resolved: ip6_tunnel: clear skb2->cb[] in ip6ip6_err() ip6ip

9.8
CVE-2026-74608

In the Linux kernel, the following vulnerability has been resolved: smb: client: Fix use-after-free in cifs_try_adding_

9.8
CVE-2026-74611

In the Linux kernel, the following vulnerability has been resolved: tls: rx: restore msg_iter before TLS 1.3 optimistic

9.8
CVE-2026-74616

In the Linux kernel, the following vulnerability has been resolved: xdp: reject clones that overrun skb_shared_info tai

9.8
CVE-2026-74617

In the Linux kernel, the following vulnerability has been resolved: dibs: initialise dibs->lock in dibs_dev_alloc() di

9.8
CVE-2026-74628

In the Linux kernel, the following vulnerability has been resolved: net/x25: fix use-after-free of the socket by its ti

9.8
CVE-2026-74662

In the Linux kernel, the following vulnerability has been resolved: inet: frags: publish queues before arming timer in

9.8
CVE-2026-74669

In the Linux kernel, the following vulnerability has been resolved: ipvs: clear IPv4 options after rebasing tunnel ICMP

9.8
CVE-2026-74688

In the Linux kernel, the following vulnerability has been resolved: sctp: clear control chunk transport if it is being

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started