Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 84/129
9.8
CVE-2026-74723

In the Linux kernel, the following vulnerability has been resolved: btrfs: lzo: reject inline extents without valid hea

9.8
CVE-2026-74727

In the Linux kernel, the following vulnerability has been resolved: ovpn: skip rehash for peers already removed from by

9.8
CVE-2026-74730

In the Linux kernel, the following vulnerability has been resolved: NFS: Pin the 'struct nfs_server' during a FREE_STAT

9.8
CVE-2026-13598

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, al

9.8
CVE-2026-5388

justhtml before 1.15.0 contains multiple security issues in URL sanitization helpers (clean_url_value/clean_url_in_js_st

9.8
CVE-2026-7808

justhtml before 1.16.0 contains multiple HTML sanitization bypass issues that can allow active/dangerous content (e.g.,

9.8
CVE-2026-8445

justhtml versions <= 1.11.0 (fixed in 1.12.0) do not sufficiently escape HTML-significant characters (angle brackets) in

9.8
CVE-2026-78183

DBD::Pg version 3.21.0 for Perl has a heap out-of-bounds write in quote_float. quote_float() allocates the length of th

9.8
CVE-2026-78168

A security vulnerability has been detected in EFM ipTIME T24000M up to 14.20.0. This affects the function httpcon_check_

9.8
CVE-2026-78211

4MOSAn GCB Doctor developed by 4MOSAn Security Technology has a OS Command Injection vulnerability. Unauthenticated remo

9.8
CVE-2026-28165

Unauthenticated Privilege Escalation in Digits <= 9.2 versions.

9.8
CVE-2026-32558

Unauthenticated Privilege Escalation in Affiliate Pro - Affiliate Program for WooCommerce & WordPress <= 8.9.1 versions.

9.8
CVE-2026-66587

Unauthenticated Local File Inclusion in WP Cafe Pro < 3.0.15 versions.

9.8
CVE-2026-66648

Unauthenticated Privilege Escalation in Jawn <= 1.4.2 versions.

9.8
CVE-2026-66650

Unauthenticated PHP Object Injection in FreightCo <= 1.1.15 versions.

9.8
CVE-2026-76070

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated

9.8
CVE-2026-76071

Netis NC63 firmware through V3.0.0.3327 contains a stack-based buffer overflow vulnerability that allows unauthenticated

9.8
CVE-2026-71300

Improper input validation vulnerability in Apache Camel Atmosphere Websocket component. This issue affects Apache Cam

9.8
CVE-2026-77915

rConfig Core 8.0.0 before 8.2.10 contains an authentication bypass vulnerability that allows unauthenticated attackers t

9.8
CVE-2026-78329

Improper input validation vulnerability in Apache Camel Undertow component. This issue affects Apache Camel: from 4.1

9.8
CVE-2026-71914

Multiple DrayTek VigorAP models contain a command injection vulnerability in the dray_apm component. The vulnerability i

9.8
CVE-2026-71921

Multiple DrayTek VigorSwitch models contain a pre-authentication command injection vulnerability in the setget.cgi inter

9.8
CVE-2026-52490

An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the proces

9.8
CVE-2026-32563

Subscriber PHP Object Injection in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

9.8
CVE-2026-78262

Unauthenticated PHP Object Injection in WP Project Manager <= 4.0.6 versions.

9.8
CVE-2026-78265

Unauthenticated PHP Object Injection in The Events Calendar <= 6.17.2 versions.

9.8
CVE-2026-78267

Unauthenticated Privilege Escalation in TranslatePress <= 3.3.2 versions.

9.8
CVE-2026-56705

Adminer before 5.4.3 fails to sanitize the server field before constructing a PDO DSN string, allowing unauthenticated a

9.8
CVE-2026-56710

Grav Login plugin versions before 1.0.16 fail to validate the target account's privilege level in the onApiUserListRowAc

9.8
CVE-2026-78676

GitPython before 3.1.59 fails to safely re-serialize multi-line git-config values during write operations, corrupting do

9.8
CVE-2026-13214

The OCPP 1.6 client in subsys/net/lib/ocpp/ocpp_j.c contains a stack buffer overflow in parse_getconfig_msg(). When hand

9.8
CVE-2026-78477

The Jawn theme for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This mak

9.8
CVE-2026-63586

The web-based management interface uses a modified uhttpd server with CGI shell scripts. The HTTP Basic Authentication u

9.8
CVE-2026-78568

The Total Donations plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 2.0.5 due

9.8
CVE-2026-78570

The Total Donations plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0

9.8
CVE-2026-49845

SQL injection in Hive Metastore direct SQL partition-name resolution in Apache Hive before 4.2.1 on all platforms allows

9.8
CVE-2026-79657

NLTK versions before 3.10.3 contain a remote code execution vulnerability in allowlisted pickle loaders that trust entir

9.8
CVE-2026-16286

Unrestricted upload of file with dangerous type vulnerability in TRtek Technological Products Computer Software Hardware

9.8
CVE-2022-51000

Nokogiri before 1.13.2 (CRuby, when using packaged libraries) ships vendored libxml2 2.9.12 and libxslt 1.1.34, which ar

9.8
CVE-2024-58378

Nokogiri before 1.15.6 and 1.16.x before 1.16.2 (CRuby, when using the packaged libxml2) is affected by a use-after-free

9.8
CVE-2025-71407

Nokogiri before 1.18.3 contains a stack buffer overflow vulnerability in libxml2 when reporting DTD validation errors wi

9.8
CVE-2026-55546

QWED-MCP is a deterministic verification gateway for MCP. Prior to 0.2.1, verify_math_expression() in src/qwed_mcp/engin

9.8
CVE-2026-79675

NLTK before 3.10.3 fails to validate JVM options passed through the per-call options parameter in the java() function, a

9.8
CVE-2026-79787

Alluxio's S3 REST proxy fails to verify AWS Signature Version 4 signatures in its default configuration, allowing unauth

9.8
CVE-2026-45018

Chainlit is a Python framework for building production-ready conversational AI applications. From 2.4.0rc0 until 2.12.0,

9.8
CVE-2026-79090

Improper privilege management in Actor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging soci

9.8
CVE-2026-79152

Incorrect authorization in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a local attacker to

9.8
CVE-2026-80104

DB-GPT builds the destination path for an uploaded skill from the multipart filename without constraining it to the uplo

9.8
CVE-2026-65637

Improper Input Validation vulnerability in Apache Tomcat due to incomplete fix for CVE-2026-32990. This issue affects

9.8
CVE-2026-65905

Authentication Bypass by Capture-replay vulnerability in Apache Tomcat's DIGEST authenticator. If, before windowSize req

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started