Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

4,548 of 57,566 · Page 86/91
CVE-2026-30051

An issue in the CreateUEContextProcedure function (/v1/ue-contexts/{supi}) of free5gc v4.1.0 allows attackers to cause a

CVE-2026-30058

Improper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of

CVE-2026-30059

An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafte

CVE-2026-30060

An issue in free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) when parsing crafted SUCI data during UE

CVE-2026-30063

An issue in the NF Discovery endpoint of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafte

CVE-2026-30064

Improper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cau

CVE-2026-30067

An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to

CVE-2026-30068

Improper input validation in the HandleUpdate function (/sbi/parameter_provision.go) of free5gc v4.0.1 allows attackers

CVE-2026-30069

A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Deni

CVE-2026-30070

An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a

CVE-2026-30071

An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted

CVE-2026-30072

A NULL pointer dereference in the CDR processing path of free5gc v4.0.1 allows attackers to cause a Denial of Service (D

CVE-2026-30073

An issue in the NssaiAvailabilitySubscriptionCreate component of free5gc v4.0.1 allows attackers to cause a Denial of Se

CVE-2026-56651

Dool in versions up to 1.3.8 is vulnerable to symlink following when the "--devel" flag is used, as the application open

CVE-2026-56652

Dool in versions up to 1.3.8 is vulnerable to a CSV injection vulnerability when exporting data to a CSV file, as it fai

CVE-2026-64896

Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functiona

CVE-2026-71401

An integer underflow was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/captu

CVE-2026-75357

An issue in Bilibili Desktop v.1.17.9 allows a remote attacker to execute arbitrary code via the bili-inject.js and bili

CVE-2026-78251

DJI drones contain an FTP service that uses hardcoded credentials shared across affected models and permits authenticate

CVE-2026-79653

In Eclipse SW360 versions 19.0.0, 19.1.0, 19.2.0, 20.0.0, 20.1.0, if the system is configured to use file system storage

CVE-2026-79718

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid

CVE-2026-79719

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid

CVE-2026-79720

Reflected XSS in Netron versions <=9.1.2 on desktop application through unsanitized node names allows an attacker to hid

CVE-2026-79988

The Twig sandbox mechanism in Craft CMS is configured to allow dangerous functionality from the Yii framework, leading t

CVE-2026-81817

Affected versions of Flowintel contain an insecure direct object reference / broken object-level authorization issue acr

CVE-2026-81818

Affected versions of Flowintel contain an authorization flaw in the administrative user-edit API. The existing authori

CVE-2026-81819

Affected versions of Flowintel expose the /my_assignment/user API endpoint to any authenticated API user. The endpoint a

CVE-2026-81820

Affected versions of Flowintel construct timeline HTML using attacker-controllable MISP object fields such as: *

CVE-2026-81826

Affected versions of Flowintel do not revoke existing authenticated sessions when a user’s password is changed. This m

CVE-2026-81827

Affected versions of Flowintel incorrectly attempted to validate login email addresses by calling Email(email). That doe

CVE-2026-18885

ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnera

CVE-2026-18886

ServiceNow has remediated an improper access control vulnerability that was identified in the ServiceNow AI platform. Th

CVE-2026-30612

An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <=

CVE-2026-35868

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link R

CVE-2026-35869

A Command Injection vulnerability exists in the bs_SetLimitCli_info function within the libshare.so library of LB-link R

CVE-2026-36102

An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrat

CVE-2026-37003

Agno up to and including 2.5.8 is vulnerable to Remote Code Execution (RCE) via prompt injection. The PythonTools and Sh

CVE-2026-37004

BerriAI litellm <=1.82.4 is vulnerable to Server-Side Template Injection (SSTI), which allows unauthenticated remote att

CVE-2026-37007

A vulnerability in FileWriterTool in crewai-tools <= 1.10.2rc1 allows a remote attacker to achieve code execution via ma

CVE-2026-37009

A SQL injection vulnerability in NL2SQLTool in crewai-tools v1.10.2rc1 allows a remote attacker to execute arbitrary SQL

CVE-2026-37012

A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to disclose sensitive user te

CVE-2026-37064

User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker

CVE-2026-37065

Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&ac

CVE-2026-37066

Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Man

CVE-2026-37068

Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allow

CVE-2026-37069

Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manag

CVE-2026-37070

Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated

CVE-2026-37071

Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4

CVE-2026-37072

Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-update

CVE-2026-37073

Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated a

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started