Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 85/436
6.5
CVE-2026-21079

Missing encryption of sensitive data in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to intercept tr

6.5
CVE-2026-21080

Cleartext storage of sensitive information in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access

6.5
CVE-2026-21083

Improper input validation in Smart Switch prior to version 3.7.72.6 allows adjacent attackers to access sensitive data.

6.5
CVE-2026-66404

DEEBOT PRO M1 and DEEBOT PRO K1VAC do not validate server certificates in MQTT communications. Operation logs and activi

6.5
CVE-2026-19404

A flaw was found in 389 Directory Server. The CleanAllRUV and Abort CleanAllRUV replication-maintenance extended operati

6.5
CVE-2026-65945

Logs contain replayable JWT tokens in Apache Ranger versions <= 2.8.0 Users are recommended to upgrade to version 2.9.0,

6.5
CVE-2026-6373

Exposure of sensitive system information to an unauthorized control sphere vulnerability in Zyxel Networks WAH7601 allow

6.5
CVE-2026-72726

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an authenticated u

6.5
CVE-2026-70622

tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnerability in the Builder::append_dir_all() function t

6.5
CVE-2026-72739

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the createCommand() function constructs

6.5
CVE-2026-72900

Metabase allows an authenticated, low-privileged attacker to read the entire Metabase application database.

6.5
CVE-2026-68871

The Yandex Lockbox secrets backend in Apache Airflow's Yandex provider resolved a team-scoped Connection or Variable id

6.5
CVE-2026-68872

The AWS Systems Manager Parameter Store and Secrets Manager backends in Apache Airflow's Amazon provider resolved a team

6.5
CVE-2026-71964

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component t

6.5
CVE-2026-69114

Spacebar Server before commit 8d126f4 contains a cross-channel message deletion vulnerability in the single-delete and b

6.5
CVE-2026-72873

Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, application.one in apps/dokploy/server/

6.5
CVE-2026-16456

A flaw was found in the `odh-model-controller`. An authenticated user with permissions to create custom resources can ex

6.5
CVE-2026-72907

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.111.0 and 16.22.0, the add_ac function

6.5
CVE-2026-72908

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.109.0 and 16.20.0, the get_tax_template

6.5
CVE-2026-73033

Sucuri Security WordPress plugin through version 2.7.3 contains a path traversal vulnerability in the pageIntegritySubmi

6.5
CVE-2026-58248

SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a speci

6.5
CVE-2026-24330

A flaw was found in wildfly-core. A remote attacker, authenticated as a 'deployer' account, can import and deploy a mali

6.5
CVE-2026-14548

The Ray Enterprise Translation WordPress plugin through 1.7.3 does not perform any capability or nonce checks on one of

6.5
CVE-2026-19391

A flaw was found in insights-core where the password redaction layer fails to recognize credentials not keyed under the

6.5
CVE-2026-19517

Improper Validation of Specified Quantity in Input and Allocation of Resources Without Limits or Throttling vulnerabilit

6.5
CVE-2026-19518

Improper Validation of Specified Quantity in Input vulnerability in Samsung Open Source rlottie allows Input Data Manipu

6.5
CVE-2026-72539

An information disclosure vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace mem

6.5
CVE-2026-72541

A missing authorization vulnerability in Windmill Labs Windmill through 1.783.0 allows any authenticated workspace membe

6.5
CVE-2026-72554

A broken access control vulnerability in Ladybird Web Solution Faveo Helpdesk 2.0.3 allows any self-registered customer

6.5
CVE-2026-72560

A server-side request forgery vulnerability in HumanSignal Label Studio through 1.24.0.dev0 exists because SSRF_PROTECTI

6.5
CVE-2026-72597

A server-side request forgery vulnerability in Friendica through the 2026.08-dev branch allows authenticated users with

6.5
CVE-2026-72598

A server-side request forgery vulnerability in Apioo Fusio 8.8.3 allows authenticated consumer-role users to make the se

6.5
CVE-2026-72604

A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete ar

6.5
CVE-2026-72608

A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated sta

6.5
CVE-2026-72771

n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when

6.5
CVE-2026-72780

Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey

6.5
CVE-2026-72782

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secre

6.5
CVE-2026-18638

Any authenticated Velociraptor user — including one holding only the readerrole — can terminate the entire server proces

6.5
CVE-2026-53414

Missing bounds check in the annotator function of Zoom Clients allows buffer over-read, which may allow a meeting partic

6.5
CVE-2026-20747

Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a deni

6.5
CVE-2026-40375

Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.

6.5
CVE-2026-47285

Improper neutralization of special elements used in a command ('command injection') in Visual Studio Code allows an unau

6.5
CVE-2026-48375

ColdFusion is affected by an Incorrect Authorization vulnerability that could result in an application denial-of-service

6.5
CVE-2026-48436

CAI Content Credentials is affected by an Improper Input Validation vulnerability that could result in a Security featur

6.5
CVE-2026-58639

Server-side request forgery (ssrf) in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over

6.5
CVE-2026-59138

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo

6.5
CVE-2026-61345

Null pointer dereference in Microsoft Remote Registry Service allows an authorized attacker to deny service over a netwo

6.5
CVE-2026-61918

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-61921

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-61924

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started