Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

4,548 of 57,566 · Page 83/91
CVE-2026-53965

The MCP PHP SDK (Composer package mcp/sdk) is the official Model Context Protocol SDK for PHP. In versions 0.5.0 through

CVE-2026-72924

GitHub CLI (gh) is GitHub's official command line tool. Versions 2.28.0 through 2.97.0 bind the local listener created b

CVE-2026-75421

aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function.

CVE-2026-75465

The /api.php/user/get_list endpoint in Maccms v10 v2026.1000.4055 is vulnerable to an Incorrect Access Control issue. Th

CVE-2026-77357

Mesop is a Python-based UI framework that allows users to build web applications. Prior to 1.3.3, applications running i

CVE-2026-78898

Incorrect authorization in Downloads in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social

CVE-2026-78941

Information leak in Core in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rende

CVE-2026-78958

Uninitialized resource in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the

CVE-2026-78965

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin

CVE-2026-78974

UI misrepresentation in Linux Toolkit Theming in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveragi

CVE-2026-78984

Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the

CVE-2026-78986

Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the

CVE-2026-79004

Out of bounds read in Media in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re

CVE-2026-79007

Uninitialized resource in GPU in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the

CVE-2026-79011

UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engi

CVE-2026-79016

Observable discrepancy in SVG in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin d

CVE-2026-79025

Improper input validation in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis

CVE-2026-79032

Improper input validation in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis

CVE-2026-79088

Incorrect authorization in FileSystem in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging socia

CVE-2026-79118

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain cross-origin

CVE-2026-79186

Incorrect authorization in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised

CVE-2026-79289

Improper control of a resource through its lifetime in Workers in Google Chrome prior to 152.0.7977.65 allowed a remote

CVE-2026-32637

Velero is an open source tool for backing up, restoring, and migrating Kubernetes cluster resources and persistent volum

CVE-2026-38465

A Stored XSS vulnerability in the donor avatar mouse-over text feature in GazellePW (GazellePosterWall) commit 86c4bedf7

CVE-2026-38466

A Stored XSS vulnerability in the torrent remaster custom title feature in GazellePW (GazellePosterWall) commit 86c4bedf

CVE-2026-38467

A SQL injection vulnerability in the tags manager in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a486486

CVE-2026-38468

A SQL injection vulnerability in the country-code lookup endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691

CVE-2026-38469

A Stored XSS vulnerability in the custom bonus title feature in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97

CVE-2026-38470

A Broken access control vulnerability in the API user endpoint in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a

CVE-2026-38472

A Stored XSS vulnerability in forum reward comments in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864

CVE-2026-38473

A Stored XSS vulnerability in the subtitle deletion flow in GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42

CVE-2026-38474

GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d18446449 suffers from a Broken access control vulne

CVE-2026-62861

TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated non-guest workspace member can remove another work

CVE-2026-62862

Typebot is an open-source chatbot builder. In self-hosted versions up to and including 3.17.1, the default passwordless

CVE-2026-62865

Typebot is an open-source chatbot builder. In self-hosted versions prior to 3.18.0, the server-side Send Email integrati

CVE-2026-63403

Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the server is vulnerable to an unauth

CVE-2026-63404

Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vu

CVE-2026-80182

In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1 access token, application credential, or trust-scoped au

CVE-2026-80184

In OpenStack Keystone before 29.0.3, tokens obtained via delegated authentication mechanisms (OAuth1 access tokens, appl

CVE-2026-44476

Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, an attacker who knows only a dynamically register

CVE-2026-52776

Compliance-trestle (Trestle) is a tooling platform for managing compliance as code. In versions before 3.12.4 and versio

CVE-2026-80214

LibreNMS’s Virtualization Discovery module is vulnerable to command line injection. An authenticated admin user can exec

CVE-2026-15203

Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3

CVE-2026-77790

The RegistrationMagic WordPress plugin before 6.0.9.4 does not sanitise and escape a parameter before using it in a SQL

CVE-2026-15365

A pop-up logic flaw in a certain feature of Kids Mode allows users to bypass password verification and use Quick Apps ou

CVE-2026-15366

A control logic defect in a specific built-in webpage of Kids Mode allows users to view local gallery photos directly wi

CVE-2026-58108

The personal access token removal query selects from PersonalAccessTokenDB but filters on columns of Session, with no jo

CVE-2026-18664

When ranges are used for access control (i.e. of the form 1.2.3.4-1.2.3.25), because NSD wrongly compares the IP address

CVE-2026-18916

Any remote client can crash a NSD serve child, by throttling the TCP receive window after a TCP query. By continuously c

CVE-2026-19401

Any remote client can crash a (debugging/non-release build type) NSD serve child by sending it a special crafted message

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started