Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 860/1152
5.4
CVE-2026-17903

Insufficient policy enforcement in Chromecast in Google Chrome prior to 151.0.7922.72 allowed an attacker on the local n

5.4
CVE-2026-17913

Inappropriate implementation in Chrome for iOS in Google Chrome on iOS prior to 151.0.7922.72 allowed a remote attacker

5.4
CVE-2026-17915

Inappropriate implementation in WebView in Google Chrome on Android prior to 151.0.7922.72 allowed a remote attacker to

5.4
CVE-2026-11870

The WP Ghost (Hide My WP Ghost) WordPress plugin before 7.0.05 does not verify that client IP information comes from a

5.4
CVE-2026-14310

The Tutor LMS WordPress plugin before 4.0.0 does not properly verify that a user has access to the course a Q&A thread

5.4
CVE-2026-15252

The Search Atlas SEO WordPress plugin before 2.6.12 does not perform a capability or nonce check in one of its AJAX han

5.4
CVE-2025-36298

IBM Sterling B2B Integrator 6.1.2.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0

5.4
CVE-2025-36431

IBM Sterling B2B Integrator 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.2.0 through 6.2.2.0_1 is vulnera

5.4
CVE-2026-11383

IBM Tivoli System Automation Application Manager 4.1 and IBM WebSphere Application Server is affected by cross-site scri

5.4
CVE-2026-54522

MessagePack for Ruby is an implementation of the MessagePack binary serialization format. Prior to 1.8.2, MessagePack::B

5.4
CVE-2026-12697

The wpForo Forum WordPress plugin before 3.1.2 does not verify that an AI chat conversation belongs to the requesting us

5.4
CVE-2026-8155

The BuddyPress WordPress plugin before 14.5.0 does not properly enforce authorization on its private messaging endpoints

5.4
CVE-2026-17350

The per-tool permission system (custom roles / role-based tool permissions, introduced in pgAdmin 4 9.3) did not enforce

5.4
CVE-2026-54707

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien

5.4
CVE-2026-34495

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls F

5.4
CVE-2026-34497

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Syste

5.4
CVE-2026-62324

Jodit Editor is a WYSIWYG editor with a built-in file browser & image editor. Prior to 4.12.31, Jodit's sanitizeHTMLElem

5.4
CVE-2026-45086

Decidim is a participatory democracy framework. From 0.31.1 before 0.31.5 and in 0.32.0.rc1 before 0.32.0.rc2, a partici

5.4
CVE-2026-12696

The wpForo Forum WordPress plugin before 3.1.2 does not sanitize and escape a user profile field before outputting it in

5.4
CVE-2026-14292

The Download Manager WordPress plugin before 3.3.66 does not properly escape a package's title before outputting it in t

5.4
CVE-2026-15234

The Codeless Page Builder WordPress plugin through 1.1.4 does not sanitize or validate a shortcode attribute before usin

5.4
CVE-2026-15262

The Admin Columns for ACF Fields WordPress plugin through 0.3.2 does not escape Advanced Custom Fields values before out

5.4
CVE-2026-10773

The DHCPv4 client helper net_dhcpv4_msg_type_name() in subsys/net/lib/dhcpv4/dhcpv4.c indexes a static 8-element const c

5.4
CVE-2026-67306

FreeRDP versions 3.28.0 and earlier contain an out-of-bounds read vulnerability in the RDP6 planar RLE bitmap decoder fu

5.4
CVE-2026-67310

OpenRemote (org.openremote:openremote) versions <= 1.26.2 contain an insecure direct object reference vulnerability in t

5.4
CVE-2026-14864

The JetEngine WordPress plugin before 3.8.12 does not escape a post meta value before outputting it through one of its s

5.4
CVE-2026-15385

The RT Mega Menu WordPress plugin before 1.5.2 does not perform a capability check on the AJAX action that saves mega-m

5.4
CVE-2026-16063

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not sanitise or escape event timeline cont

5.4
CVE-2026-16064

The Event Booking Manager for WooCommerce WordPress plugin before 5.3.7 does not properly verify authorization on the o

5.4
CVE-2026-16292

The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-meta

5.4
CVE-2026-18570

A flaw was found in the full-scope-disabled client-policy executor within the keycloak-services component. This componen

5.4
CVE-2026-68583

luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scripting vulnerability in the blocklist name field th

5.4
CVE-2026-18584

A security vulnerability has been detected in GL.iNet E5800, E750, X2000, X3000, XE3000 and XE300 up to 20260707. Impact

5.4
CVE-2026-28147

Missing Authorization vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templa

5.4
CVE-2026-18651

A flaw was found in 389 Directory Server. During SASL PLAIN authentication, the server installs connection-level bind cr

5.4
CVE-2026-18644

A vulnerability was identified in danpros HTMLy up to 3.1.1. Affected by this issue is the function unlink of the file /

5.4
CVE-2026-18645

A security flaw has been discovered in danpros HTMLy up to 3.1.1. This affects the function add_content of the file /sys

5.4
CVE-2026-49131

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers with fir

5.4
CVE-2026-49132

OPNsense before 26.1.9 contains a stored cross-site scripting vulnerability that allows authenticated attackers to injec

5.4
CVE-2026-52520

Emlog CMS <= 2.6.14 contains a stored cross-site scripting (XSS) vulnerability in the article publishing module (/admin/

5.4
CVE-2026-66316

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a ne

5.4
CVE-2026-66317

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform tampering over a n

5.4
CVE-2026-14848

The Paid Membership Subscriptions WordPress plugin before 3.0.8 does not verify that the subscription being modified th

5.4
CVE-2026-14192

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Bilin Software and

5.4
CVE-2026-14219

URL redirection to untrusted site ('open redirect') vulnerability in Bilin Software and Informatics Consultancy Inc. HUM

5.4
CVE-2026-70367

A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS pr

5.4
CVE-2026-67196

Perspective 5.0.0 contains a cross-site scripting vulnerability in the built-in Debug plugin that allows attackers to in

5.4
CVE-2026-70481

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the stand

5.4
CVE-2026-16942

The WP Custom HTML Page WordPress plugin through 0.6.2 does not sanitise HTML stored through one of its custom page hand

5.4
CVE-2026-71275

OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML r

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started