Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 859/1152
5.4
CVE-2026-64795

Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provide

5.4
CVE-2026-64871

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Cache Cleaner extension - Admi

5.4
CVE-2026-25427

Subscriber Broken Access Control in eRoom <= 1.7.1 versions.

5.4
CVE-2026-27391

Subscriber Broken Access Control in uListing <= 2.2.0 versions.

5.4
CVE-2026-61981

Unauthenticated Cross Site Request Forgery (CSRF) in Simple Link Directory Pro <= 15.0.8 versions.

5.4
CVE-2026-65463

Subscriber Insecure Direct Object References (IDOR) in Masteriyo - LMS <= 2.3.1 versions.

5.4
CVE-2026-65464

Unauthenticated Cross Site Request Forgery (CSRF) in GiveWP <= 4.16.3 versions.

5.4
CVE-2026-65478

Subscriber Broken Access Control in ListingPro <= 2.9.10 versions.

5.4
CVE-2026-65479

Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.

5.4
CVE-2026-65512

Cross-Site request forgery (CSRF) vulnerability in Melapress WP Activity Log and Melapress WP Activity Log Premium allow

5.4
CVE-2026-48530

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Classification Rules configuration

5.4
CVE-2026-48531

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Retention Policy configuration tha

5.4
CVE-2026-48532

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File History Retention Policy conf

5.4
CVE-2026-48534

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the IMAP Server configuration that all

5.4
CVE-2026-48535

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the Call Home proxy server configurati

5.4
CVE-2026-48536

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the General Settings SMTP configuratio

5.4
CVE-2026-48537

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the File Archive Assistant configurati

5.4
CVE-2026-48538

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the default import settings configurat

5.4
CVE-2026-48539

GFI Archiver before 15.13 contains a stored cross-site scripting vulnerability in the MailInsights scheduled report conf

5.4
CVE-2026-65696

Overseerr through 1.35.0 contains an authorization bypass through user-controlled key vulnerability in the push subscrip

5.4
CVE-2026-12689

The ProfileGrid WordPress plugin before 5.9.9.7 does not perform any authorization or ownership check on some of its pr

5.4
CVE-2026-57530

Milkdown before 7.21.3 contains a stored cross-site scripting vulnerability in the @milkdown/preset-commonmark and @milk

5.4
CVE-2026-57531

Milkdown before 7.21.3 contains a DOM cross-site scripting vulnerability in the @milkdown/plugin-emoji package that allo

5.4
CVE-2026-66338

A flaw was found in libsoup. The chunked transfer encoding parser uses a permissive parsing function for chunk sizes tha

5.4
CVE-2026-57978

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne

5.4
CVE-2026-65558

Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2.3.5 versions.

5.4
CVE-2026-66442

Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.

5.4
CVE-2026-48052

Papra is a minimalistic document management and archiving platform. Prior to version 26.5.0, an authenticated user who i

5.4
CVE-2026-66029

Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent

5.4
CVE-2026-66030

Ekushey Project Manager CRM through version 5.0 ccontains a stored cross-site scripting vulnerability that allows authen

5.4
CVE-2026-64647

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr

5.4
CVE-2026-66031

Ekushey Project Manager CRM through version 5.0 contains a stored cross-site scripting vulnerability that allows authent

5.4
CVE-2026-64648

Next.js is a React framework for building full-stack web applications. In versions 12.0.0 through 15.5.20 and 16.0.0 thr

5.4
CVE-2026-62828

Improper input validation in Microsoft Edge for Android allows an unauthorized attacker to perform tampering over a netw

5.4
CVE-2026-66746

Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulnerability that allows remote attackers to inject arb

5.4
CVE-2026-66751

Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vulnerability that allows any authenticated user to ar

5.4
CVE-2026-66752

tiny-http through 0.12.0 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchronize

5.4
CVE-2026-67181

Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnerability that allows remote attackers to desynchroni

5.4
CVE-2026-57511

SuperPlane before 0.30.0 contains an SMTP header injection vulnerability that allows unauthenticated attackers to inject

5.4
CVE-2026-14224

The Easy Appointments WordPress plugin before 3.12.28 does not verify that the appointment targeted by its customer-data

5.4
CVE-2026-63239

A hard-coded AWS IAM credentials vulnerability in Koollab LMS allowed an attacker to access shared multi-tenant S3 bucke

5.4
CVE-2026-16553

GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 19.0.5, 19.1 before 19.1.3, and 19.2

5.4
CVE-2026-18266

Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose

5.4
CVE-2026-17728

Inappropriate implementation in Extensions in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject a

5.4
CVE-2026-17734

Inappropriate implementation in Autofill in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to inject arb

5.4
CVE-2026-17761

Insufficient validation of untrusted input in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a re

5.4
CVE-2026-17779

Inappropriate implementation in Site Isolation in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to bypa

5.4
CVE-2026-17799

Insufficient validation of untrusted input in Safe Browsing in Google Chrome prior to 151.0.7922.72 allowed a remote att

5.4
CVE-2026-17812

Inappropriate implementation in DigitalCredentials in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to

5.4
CVE-2026-17874

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started