Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 83/436
6.5
CVE-2026-69702

SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated a

6.5
CVE-2026-69704

Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsan

6.5
CVE-2026-70489

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automatio

6.5
CVE-2026-70491

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /ap

6.5
CVE-2026-70493

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built

6.5
CVE-2026-11421

The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CRM Support plugin for WordPress is vulnerable to SQL Inje

6.5
CVE-2026-15941

The plugin provides an Admin Search page that allows users with the `edit_posts` capability to run Relevanssi searches f

6.5
CVE-2026-7753

The Cost Calculator Builder plugin for WordPress is vulnerable to unauthorized access of sensitive data due to a missing

6.5
CVE-2026-16968

The GeoDirectory WordPress plugin before 2.8.168 does not restrict a user-search handler to users allowed to list users

6.5
CVE-2026-49004

The built-in PostgreSQL service on the mobile device suffers from misconfiguration flaws and command injection vulnerabi

6.5
CVE-2026-66275

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service

6.5
CVE-2026-66276

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to

6.5
CVE-2026-66277

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att

6.5
CVE-2026-67553

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service

6.5
CVE-2026-67554

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to

6.5
CVE-2026-67555

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att

6.5
CVE-2026-67591

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service

6.5
CVE-2026-68075

An authenticated attacker could exceed the session flow control incoming window potentially leading to denial of service

6.5
CVE-2026-68077

An authenticated attacker can craft a disposition frame with large or illegal ranges causing excessive CPU usage due to

6.5
CVE-2026-68078

It was not possible to govern the maximum number of transfer frames per incoming delivery, enabling an authenticated att

6.5
CVE-2026-68080

It was not possible to govern the rate at which the broker would respond to an echo flow, enabling an authenticated atta

6.5
CVE-2026-11454

The Groundhogg — CRM, Newsletters, and Marketing Automation plugin for WordPress is vulnerable to Insecure Direct Object

6.5
CVE-2026-11977

The WP Post Author – Author Box, Multiple Authors, Guest Authors & Custom Avatars plugin for WordPress is vulnerable to

6.5
CVE-2026-15281

The User Access Manager plugin for WordPress is vulnerable to Second-Order SQL Injection via the 'id' parameter of the w

6.5
CVE-2026-71205

changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP

6.5
CVE-2026-71208

KubeSphere's cluster-controller reconciliation (pkg/utils/clusterclient/clusterclient.go, addCluster) processes every Cl

6.5
CVE-2026-7726

The Layouts for WPBakery plugin for WordPress is vulnerable to unauthorized actions due to a missing capability check on

6.5
CVE-2026-14574

In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` rec

6.5
CVE-2026-71244

Paperless-ngx's MailAccountViewSet.test action, when called with an existing account's ID and a masked password field, r

6.5
CVE-2026-71247

Documenso's sign-field-with-token.ts, used by the live document-signing UI, allows a recipient with the ASSISTANT role t

6.5
CVE-2026-71251

Akaunting's shared download route (app/Http/Controllers/Common/Uploads.php::download, reachable at uploads/{id}/download

6.5
CVE-2026-0516

A improper neutralization of HTTP Headers for Scripting Syntax vulnerability in SonicOS could allow a remote attacker to

6.5
CVE-2026-71225

A flaw was found in libkcapi. When performing one-shot symmetric cipher operations on large inputs (over 64 KiB) in stat

6.5
CVE-2026-71260

ESPHome through 2026.7.0-dev discloses plaintext passwords via its web_server component. In WebServer::text_json_ (espho

6.5
CVE-2026-71273

OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request w

6.5
CVE-2026-71282

ChirpStack's SQLite-backend device tag filtering (chirpstack/src/storage/device.rs, in both get_count and list) interpol

6.5
CVE-2026-7456

The Udimi Tools plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability chec

6.5
CVE-2026-16100

A flaw was found in the user-event metrics recording of Keycloak. When metrics are enabled, the system records raw error

6.5
CVE-2026-48912

Improper Input Validation vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. A missing

6.5
CVE-2026-49331

A flaw was found in openshift/oauth-proxy. On paths configured to bypass authentication (skip-auth-regex), the proxy for

6.5
CVE-2026-50749

Improper Authorization vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.1. Any authentica

6.5
CVE-2026-20288

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with&nb

6.5
CVE-2026-20294

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, rem

6.5
CVE-2026-7646

IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other u

6.5
CVE-2026-10128

IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbit

6.5
CVE-2026-70439

Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appr

6.5
CVE-2026-7657

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and inef

6.5
CVE-2026-63457

A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.

6.5
CVE-2026-7658

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path t

6.5
CVE-2026-66885

Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's b

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started