Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

6,448 of 57,566 · Page 86/129
9.8
CVE-2026-81702

openssl_encrypt before 1.4.9 fails to re-derive and validate fingerprints when loading identities from identity.json, al

9.8
CVE-2026-81707

openssl_encrypt before 1.4.9 fails to sanitize the email field of imported identity documents, allowing attackers to inj

9.8
CVE-2026-19092

The Tutor LMS WordPress plugin before 4.0.6 does not prevent request data from overwriting internal variables while rend

9.8
CVE-2026-37006

A vulnerability in the WebSocket endpoint of gpt-researcher v0.14.7 and before allows an unauthenticated remote attacker

9.8
CVE-2026-59313

Spring MVC applications using the functional web framework are vulnerable to stream corruption when using Server-Sent Ev

9.8
CVE-2026-81934

Redis contains a use-after-free vulnerability in the 'tlsProcessPendingData()' function, which handles the TLS pending-d

9.8
CVE-2026-69658

MQTT credentials and control traffic are transmitted in cleartext, exposing sensitive information to network-level atta

9.8
CVE-2026-71187

The Ebyte device relies on client side authentication logic that can be reproduced by unauthenticated users. An attacke

9.8
CVE-2026-73125

Ebyte device web management interface does not consistently enforce authentication before granting access to administra

9.8
CVE-2026-75337

The static resource interface /api/static/{deployKey}/ of Yu AI Code Mother v4.3 is vulnerable to path traversal. The us

9.8
CVE-2026-76179

An improper protection of authentication tokens vulnerability exists in certain Ebyte gateway products. Authentication

9.8
CVE-2026-76943

Xiiaozet LK100Wt contains an authentication weakness within an administrative service that may allow an attacker to byp

9.8
CVE-2026-78239

Xiiaozet LK100W exposes a critical management function that can be invoked without authentication, allowing a remote at

9.8
CVE-2026-82082

NUMail developed by Green-Computing has an OS Command Injection vulnerability. Unauthenticated remote attackers can inje

9.8
CVE-2026-76581

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including,

9.8
CVE-2026-78032

SOY CMS contains an issue with deserialization of untrusted data. An arbitrary code may be executed by an attacker with

9.8
CVE-2026-80600

In the Linux kernel, the following vulnerability has been resolved: batman-adv: dat: acquire ARP hw source only after s

9.8
CVE-2026-80609

In the Linux kernel, the following vulnerability has been resolved: qede: fix out-of-bounds check for cqe->len_list[]

9.8
CVE-2026-80612

In the Linux kernel, the following vulnerability has been resolved: net: lwtunnel: Drop skb metadata before LWT encapsu

9.8
CVE-2026-80617

In the Linux kernel, the following vulnerability has been resolved: net: airoha: fix foe_check_time allocation size fo

9.8
CVE-2026-80630

In the Linux kernel, the following vulnerability has been resolved: net/sched: sch_fq_codel: Do not call qdisc_tree_red

9.8
CVE-2026-80634

In the Linux kernel, the following vulnerability has been resolved: netfilter: flowtable: avoid num_encaps underflow on

9.8
CVE-2026-80668

In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_conntrack_expect: use conntrack GC to

9.8
CVE-2026-80673

In the Linux kernel, the following vulnerability has been resolved: ntfs: bound the look-ahead attribute-list entry in

9.8
CVE-2026-80674

In the Linux kernel, the following vulnerability has been resolved: ntfs: validate resident attribute lists and harden

9.8
CVE-2026-80681

In the Linux kernel, the following vulnerability has been resolved: vxlan: re-fetch eth header after route_shortcircuit

9.8
CVE-2026-80694

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: mtk_eth_soc: pass eth to mtk_handle_

9.8
CVE-2026-80714

In the Linux kernel, the following vulnerability has been resolved: ipvs: do not propagate one-packet flag to synced co

9.8
CVE-2026-37751

An OS command injection vulnerability in the killSessionSync function (lib/agent-runtime.ts) of 23blocks-OS ai-maestro v

9.8
CVE-2026-55559

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs inserts templateArgs from POST /api/instances an

9.8
CVE-2026-82266

Redpanda through 26.2.2 binds the Admin API to 0.0.0.0:9644 with admin_api_require_auth defaulting to false, treating un

9.8
CVE-2026-82277

Argo Rollouts dashboard through 1.10.0 binds to all interfaces and exposes mutating Rollout operations without authentic

9.8
CVE-2026-82329

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated at

9.8
CVE-2026-19286

IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcemen

9.8
CVE-2026-16259

The Uix UserCenter WordPress plugin through 1.0.3 does not verify that the account being modified through an unauthentic

9.8
CVE-2026-14494

The Sigma Forms Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.

9.8
CVE-2026-82448

Shinobi before commit 5a76c74f contains a hardcoded connection key in the child node service that allows unauthenticated

9.8
CVE-2026-82452

rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lac

9.8
CVE-2026-82460

Cloud Commander before 19.20.2 contains a directory traversal vulnerability in REST file-operation and markdown endpoint

9.8
CVE-2026-15369

The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versio

9.8
CVE-2026-15980

The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5.

9.6
CVE-2025-66398

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.19.0, an unauthenticate

9.6
CVE-2025-64419

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to version 4.0

9.6
CVE-2025-12543

A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The

9.6
CVE-2026-22783

Iris is a web collaborative platform that helps incident responders share technical details during investigations. Prior

9.6
CVE-2026-22794

Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.93, the server uses the Origin

9.6
CVE-2026-0500

Due to the usage of vulnerable third party component in SAP Wily Introscope Enterprise Manager (WorkStation), an unauthe

9.6
CVE-2026-23523

Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. Prior to 0.13.0

9.6
CVE-2026-23852

SiYuan is a personal knowledge management system. Versions prior to 3.5.4 have a stored Cross-Site Scripting (XSS) vulne

9.6
CVE-2025-53912

An arbitrary file read vulnerability exists in the encapsulatedDoc functionality of MedDream PACS Premium 7.3.6.870. A s

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started