Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 86/436
6.5
CVE-2026-62714

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62715

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62716

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62718

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62720

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62742

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62745

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62750

Partial string comparison in Windows HTTP Protocol Stack allows an unauthorized attacker to perform tampering over an ad

6.5
CVE-2026-62782

Out-of-bounds read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-62814

Integer underflow (wrap or wraparound) in Windows DHCP Server allows an unauthorized attacker to disclose information ov

6.5
CVE-2026-62837

Relative path traversal in Microsoft Office SharePoint allows an authorized attacker to disclose information over a netw

6.5
CVE-2026-62839

Insufficiently protected credentials in Microsoft Office SharePoint allows an authorized attacker to perform spoofing ov

6.5
CVE-2026-62902

Inclusion of functionality from untrusted control sphere in .NET allows an unauthorized attacker to disclose information

6.5
CVE-2026-62912

Deserialization of untrusted data in Microsoft Exchange Server allows an authorized attacker to deny service over a netw

6.5
CVE-2026-62915

Missing authorization in Microsoft Exchange Server allows an authorized attacker to bypass a security feature over a net

6.5
CVE-2026-63512

Incorrect authorization in Microsoft Office SharePoint allows an authorized attacker to perform tampering over a network

6.5
CVE-2026-63516

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over

6.5
CVE-2026-65769

Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to

6.5
CVE-2026-65785

Uncontrolled resource consumption in Windows DHCP Client allows an unauthorized attacker to deny service over an adjacen

6.5
CVE-2026-65794

Buffer over-read in Windows SMB Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-65806

Missing authorization in Azure CycleCloud allows an authorized attacker to disclose information over a network.

6.5
CVE-2026-65813

Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over

6.5
CVE-2026-66301

Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized

6.5
CVE-2026-70327

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-70328

Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-48411

Adobe Commerce is affected by an Incorrect Authorization vulnerability that could result in a Security feature bypass. A

6.5
CVE-2026-72712

Nmap versions up to and including 7.99 contains a denial of service vulnerability that allows remote attackers to crash

6.5
CVE-2026-73216

Coturn is a free open source implementation of TURN and STUN Server. Prior to 4.17.0, shutdown_client_connection() in sr

6.5
CVE-2026-18695

An issue in MongoDB Server's handling of certain query predicates against time-series collections with a metaField could

6.5
CVE-2026-18696

An issue in MongoDB Server's applyOps command could allow an authenticated user with specific non-default privileges to

6.5
CVE-2026-18699

An issue in MongoDB Server's query planner could allow an authenticated user with read-level privileges to cause the ser

6.5
CVE-2026-18700

An issue in MongoDB Server's geospatial validation could allow an authenticated user with write privileges to cause an i

6.5
CVE-2026-18701

An issue in MongoDB Server's query subsystem could allow an authenticated user with read privileges to cause the server

6.5
CVE-2026-18704

An issue in MongoDB Server's aggregation framework could allow an authenticated user with only read privileges to perfor

6.5
CVE-2026-18705

An issue in MongoDB Server's Atlas Vector Search feature could allow an authenticated user with read access to one view

6.5
CVE-2026-69115

OpenIM Server v3.8.3 contains a missing authorization vulnerability that allows any authenticated user to access admin-o

6.5
CVE-2026-69117

NetBox 4.5.8 contains an ORM injection vulnerability that allows authenticated attackers, including those with read-only

6.5
CVE-2026-29035

CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow vulnerability in the read_websocket() function that

6.5
CVE-2026-63133

Malcolm is a network traffic analysis tool suite. Prior to version 26.07.0, `safe-extract.py` extracts uploaded archives

6.5
CVE-2026-66832

When the Mira Android app opens in-app WebView content (e.g., shop redirect flows), the user's live session token is app

6.5
CVE-2026-18710

A MongoDB driver component could write sensitive configuration information, including a credential used for outbound net

6.5
CVE-2026-66098

The Mira hormone monitor device firmware accepts a 0x01 write from any BLE central without authentication, causing the d

6.5
CVE-2026-73245

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0-rc6, Kestra's cli/src/main/resources/appli

6.5
CVE-2026-19587

Uncontrolled Resource Consumption vulnerability in Samsung Open Source rlottie allows Excessive Allocation.

6.5
CVE-2026-19588

Integer Overflow to Buffer Overflow vulnerability in Samsung Open Source rlottie allows Overflow Buffers.

6.5
CVE-2026-12976

The LearnPress WordPress plugin before 4.4.4 does not verify that a user is enrolled in a course before processing AI-a

6.5
CVE-2026-13168

The Eventin WordPress plugin before 4.1.20 does not properly restrict access to stored customer records, allowing users

6.5
CVE-2026-18943

The WPC Admin Columns WordPress plugin before 2.3.4 does not have authorisation checks in one of its AJAX actions, allow

6.5
CVE-2026-18652

Velociraptor allows reading Stacked result sets from the GUI.  Velociraptor's multi-tenant design stores sub orgs within

6.5
CVE-2026-64952

The hunt_delete() VQL function allows deleting hunts.  Velociraptor misapplied the permission check requiring only COLL

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started