Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 832/1152
5.5
CVE-2026-70317

Use of uninitialized resource in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-70318

Improper input validation in Microsoft Office Excel allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-70319

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-70320

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally

5.5
CVE-2026-70322

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally

5.5
CVE-2026-70323

Improper input validation in Microsoft Office allows an unauthorized attacker to disclose information locally.

5.5
CVE-2026-70325

Improper input validation in Microsoft Office PowerPoint allows an unauthorized attacker to disclose information locally

5.5
CVE-2026-70348

Improper link resolution before file access ('link following') in Windows Management Services allows an authorized attac

5.5
CVE-2026-72971

Improper link resolution before file access ('link following') in Windows Container Isolation FS Filter Driver (unionfs.

5.5
CVE-2026-48790

Turso CLI is the command line interface (CLI) to the open-source database Turso. Versions prior to 1.0.26 persist the us

5.5
CVE-2026-14479

A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation

5.5
CVE-2026-19548

Multiple Use-After-Free vulnerabilities were found in the add_archive_element function in ld/ldmain.c of the GNU linker

5.5
CVE-2026-18097

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 for Linux, UNIX and Windows (includes DB2 Connect Server) could

5.5
CVE-2026-19502

MongoDB SQL Schema Builder CLI records its startup configuration to standard output and, when file logging is enabled, t

5.5
CVE-2026-19617

A flaw was found in libdm. A local attacker could craft a malicious Logical Volume Manager (LVM) metadata configuration

5.5
CVE-2026-19964

A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/

5.5
CVE-2026-49308

Permission control vulnerability in the clipboard module. Impact: Successful exploitation of this vulnerability may affe

5.5
CVE-2026-74873

openssl_encrypt versions before 1.4.0 expose passwords passed via the --password CLI argument in process listings access

5.5
CVE-2026-74890

openssl_encrypt versions before 1.4.0 contain an authentication bypass vulnerability in CamelliaCipher that disables HMA

5.5
CVE-2026-59911

Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Insertion of Sensitive Information into Log File vulnerabilit

5.5
CVE-2026-75055

In JetBrains IntelliJ IDEA before 2026.2.1 hadoop ResourceManager could read local files via XXE

5.5
CVE-2026-75058

In JetBrains IntelliJ IDEA before 2026.2.1 xXE was possible in the Eclipse settings importers

5.5
CVE-2026-75104

Hugging Face Transformers fails to validate shard filenames in checkpoint index files, allowing attackers to read arbitr

5.5
CVE-2026-64760

An information leakage was addressed with additional validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10.

5.5
CVE-2026-73834

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. Certain ACM wrapper

5.5
CVE-2026-75485

A flaw was found in the must-gather component of Red Hat Advanced Cluster Management for Kubernetes. The cluster Proxy o

5.5
CVE-2026-68922

MobSF is a mobile application security testing tool used. Prior to 4.5.1, find_icon_path_zip in mobsf/StaticAnalyzer/vie

5.5
CVE-2026-47630

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path travers

5.5
CVE-2026-62553

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

5.5
CVE-2026-62564

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

5.5
CVE-2026-62573

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

5.5
CVE-2026-70836

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

5.5
CVE-2026-71033

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

5.5
CVE-2026-71073

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/ODBC). The supported version that

5.5
CVE-2026-73973

Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0

5.5
CVE-2026-73974

linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfa

5.5
CVE-2026-49424

The Linux waitid() implementation translates a FreeBSD siginfo_t struct into a stack-declared Linux siginfo_t. It did n

5.5
CVE-2026-49425

The compat32 kevent() handler translates a 64-bit kevent struct into a stack- declared 32-bit struct. It did not first

5.5
CVE-2026-58084

To retrieve the previous timer value, the kernel calls realtimer_gettime(), which obtains the current time for the timer

5.5
CVE-2026-76227

Renovate versions from 42.68.1 before 42.96.3 (and from 42.68.1 before 43.4.4), including corresponding Docker images (r

5.5
CVE-2026-67266

Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged a

5.5
CVE-2026-67267

Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthoriz

5.5
CVE-2026-16855

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a heap bu

5.5
CVE-2026-16883

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to obtain sensitive information due to an out

5.5
CVE-2026-14978

HashiCorp go-slug 0.4.0 through 0.18.2 could allow a local attacker to bypass .terraformignore exclusions and cause sens

5.5
CVE-2026-76917

Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

5.5
CVE-2026-76918

SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

5.5
CVE-2026-76921

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

5.5
CVE-2026-76922

Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

5.5
CVE-2026-76923

Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started