Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 85/129
9.8
CVE-2026-78619

Punk::Plugin::TOTP versions before 0.05 for Perl accept another account's recovery code at the two-factor challenge beca

9.8
CVE-2026-16639

Authentication Bypass Using an Alternate Path or Channel vulnerability in Drupal Internationalization Single Sign-On all

9.8
CVE-2026-16641

Vulnerability in Drupal Commerce Elavon. This issue affects Commerce Elavon versions: *.*.

9.8
CVE-2026-80138

ClipBucket V5's web installer fails to properly validate or escape the php_cli_filepath parameter before passing it to s

9.8
CVE-2026-19632

The TranslatePress – Translate Multilingual sites with AI Translation plugin for WordPress is vulnerable to Sensitive In

9.8
CVE-2026-18431

The Avada theme for WordPress is vulnerable to Arbitrary File Write in all versions up to, and including, 7.16 when the

9.8
CVE-2026-80235

EFence developed by Thinking Software Technology has an Arbitrary File Upload vulnerability. Unauthenticated remote atta

9.8
CVE-2026-59683

The OpenRGB network protocol allows to write attacker controlled strings into arbitrary file system paths (extension of

9.8
CVE-2026-80349

TarsWeb decides whether a request comes from a trusted local caller using a client-controlled header. app.js sets Koa's

9.8
CVE-2026-18080

The ERP: Complete HR, Accounting & CRM Suite Built for WooCommerce plugin for WordPress is vulnerable to Unrestricted Fi

9.8
CVE-2026-77552

A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Ent

9.8
CVE-2026-77557

A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Prote

9.8
CVE-2026-80203

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function

9.8
CVE-2026-74737

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ti: am65-cpsw-nuss: Fix port_id extr

9.8
CVE-2026-74743

In the Linux kernel, the following vulnerability has been resolved: macvlan: inherit needed_headroom and needed_tailroo

9.8
CVE-2026-74744

In the Linux kernel, the following vulnerability has been resolved: ipvlan: inherit needed_headroom and needed_tailroom

9.8
CVE-2026-74746

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: publish GC-visible tuple last

9.8
CVE-2026-74752

In the Linux kernel, the following vulnerability has been resolved: sctp: validate cookie AUTH state before use When c

9.8
CVE-2026-80519

In the Linux kernel, the following vulnerability has been resolved: ovpn: finish crypto callback cleanup before peer re

9.8
CVE-2026-80528

In the Linux kernel, the following vulnerability has been resolved: ceph: avoid fs reclaim while using current->journal

9.8
CVE-2026-80557

In the Linux kernel, the following vulnerability has been resolved: libceph: fix OOB read in decode_watchers() via miss

9.8
CVE-2026-80558

In the Linux kernel, the following vulnerability has been resolved: libceph: Avoid using invalid osd indices from prima

9.8
CVE-2026-80561

In the Linux kernel, the following vulnerability has been resolved: libceph: fix multiple unsafe decodes in decode_lock

9.8
CVE-2026-80586

In the Linux kernel, the following vulnerability has been resolved: mptcp: options: reset DSS fields in case of unexpec

9.8
CVE-2026-80587

In the Linux kernel, the following vulnerability has been resolved: mptcp: avoid combining some incoming suboptions So

9.8
CVE-2026-80589

In the Linux kernel, the following vulnerability has been resolved: block: stop the timeout timer when releasing a neve

9.8
CVE-2026-54569

SENAITE.CORE is the core framework for the SENAITE laboratory information management system. From 2.0.0 to 2.6.0, the SE

9.8
CVE-2026-80428

ILIAS deserialises stored session data for an unauthenticated caller. The Shibboleth back-channel endpoint at components

9.8
CVE-2026-81032

NebulaGraph exposes its runtime configuration over an unauthenticated HTTP service. Each daemon starts the web service d

9.8
CVE-2025-61163

Cohere North AI v1.1.5 was discovered to contain excessively permissive cross-domain policy with untrusted domains. This

9.8
CVE-2025-61165

An arbitrary file upload vulnerability in the /v1/my_drive/batch_upload component of cohere North AI v1.1.5 allows attac

9.8
CVE-2026-75325

DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/api/dwsurvey/none/' and '/api/dwsurvey/up/**' param

9.8
CVE-2025-70290

An issue was discovered in Denx U-Boot before 2026.04. An integer overflow vulnerability in the ZFS filesystem support c

9.8
CVE-2026-26448

Stomper 5e2741e is vulnerable to Use-After-Free. When a client sends multiple CONNECT frames on the same TCP connection,

9.8
CVE-2026-60004 KEV

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

9.8
CVE-2026-75329

The Netty configuration distribution service (port 8283) of super-diamond-server <= 1.3.3 has no authentication mechanis

9.8
CVE-2026-75330

The front-end interface /superdiamond/preview/{projectCode}/{module}/{type} of super-diamond-server <= 1.3.3 is vulnerab

9.8
CVE-2026-75336

Funiture 1.0.0 is vulnerable to SQL Injection in the backend tool interfaces /sys/tool/select.json and /sys/tool/update.

9.8
CVE-2026-75338

disconf (Distributed Configuration Management Platform) 2.6.36 is vulnerable to Incorrect Access Control. The config-fet

9.8
CVE-2026-47884

Use of XsltView in a Spring MVC application can result in SSRF and RCE attack if the application has an "/**" mapping th

9.8
CVE-2026-47890

Spring MVC and WebFlux applications are vulnerable to stream corruption when using Server-Sent Events (SSE) with view fr

9.8
CVE-2026-47891

A Spring WebFlux application that relies on the Aalto XML processor to parse XML input does not correctly enforce the ma

9.8
CVE-2026-47892

A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predi

9.8
CVE-2026-32566

Unauthenticated Privilege Escalation in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.63 versions.

9.8
CVE-2026-78286

Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.

9.8
CVE-2026-78292

Unauthenticated PHP Object Injection in Hash Form <= 1.4.1 versions.

9.8
CVE-2026-74232

Zbtlink L3_V2_8 firmware 3.0.0.4.528, Zbtlink WE826-T2 firmware 19.1101, Zbtlink ZBT-7628 firmware 1.0.0.2.007, Zbtlink

9.8
CVE-2026-74233

Zbtlink WE1326, WE357, WE5926, WE5926-WD, WE826-Q, WE826-T2, WE826-WD, WG108, and WG3526 firmware 19.1101, Zbtlink WE242

9.8
CVE-2026-81700

openssl_encrypt versions before 1.4.9 contain a signature verification vulnerability in gpg_runner.verify_detached that

9.8
CVE-2026-81701

openssl_encrypt versions before 1.4.9 use a denylist to identify trusted built-in plugins, allowing unsigned plugins in

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started