Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 862/1152
5.4
CVE-2026-47229

Admidio is an open-source user management solution. Prior to version 5.0.10, `modules/sso/clients.php` validates an `adm

5.4
CVE-2026-73262

Prowler is a cloud security platform. Prior to 5.37.0, Prowler's HTML output formatter in prowler/lib/outputs/html/html.

5.4
CVE-2026-73287

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.12, RustFS handles FTPS MKD in FtpsDriv

5.4
CVE-2026-59242

Apache Airflow's XCom `GET /api/v2/{...}/xcomEntries/{key}?deserialize=true` endpoint passed a string-literal payload th

5.4
CVE-2026-68076

Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team'

5.4
CVE-2026-48552

Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable to DOM-based cross-site scripting in jsonquery.js

5.4
CVE-2026-73295

Material for MkDocs is a powerful documentation framework built on top of MkDocs. From 7.2.0 until 9.7.7, the mountSearc

5.4
CVE-2026-19135

A JEXL expression sandbox bypass exists in multiple versions of OpenNMS Meridian and Horizon. A low-privileged authentic

5.4
CVE-2026-72506

VoiceTra provided by National Institute of Information and Communications Technology (NICT) contains an incorrectly spec

5.4
CVE-2026-19088

The ShopEngine Elementor WooCommerce Builder Addon WordPress plugin before 4.9.3 does not protect one of its authentica

5.4
CVE-2026-14332

The Ecwid by Lightspeed Ecommerce Shopping Cart WordPress plugin before 7.0.9 does not perform a capability check or non

5.4
CVE-2026-73621

GitPython before 3.1.56 contains an argument injection vulnerability in the Commit.count() method, which forwards keywor

5.4
CVE-2026-67990

basecamp/upright at commit efe4f2e5254ac6e57e45d2261804cca74dbbca3f disables Rails CSRF protection for its Alertmanager

5.4
CVE-2026-55986

Email Management API Bypasses ManageCredentials Feature Restrictions

5.4
CVE-2026-58435

Gitea LFS Deploy-Key Privilege Escalation

5.4
CVE-2026-73481

phpList before 3.7.0-RC5 fail to enforce CSRF token validation on the bounce rule deletion endpoint (bouncerules.php / b

5.4
CVE-2026-16878

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information due to an out-o

5.4
CVE-2026-72673

Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized deletion of Synthetics private locations via Access

5.4
CVE-2026-17226

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to obtain sensitive information or cause a deni

5.4
CVE-2026-73039

streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated

5.4
CVE-2026-72821

Grav Form plugin versions before 9.1.15 contain a stored cross-site scripting vulnerability in radio and toggle field op

5.4
CVE-2026-72823

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains an API-key scope cap bypass in DemoController. Its

5.4
CVE-2026-72832

Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site scripting vulnerability in the Security::detectXss()

5.4
CVE-2026-17227

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to bypass security restrictions due t

5.4
CVE-2026-18178

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to delete arbitrary files due to path

5.4
CVE-2026-74240

A flaw was found in Red Hat Quay's JWT (JSON Web Token) validation for federated robot accounts and single sign-on (SSO)

5.4
CVE-2026-14230

The ECS WordPress plugin before 4.3.8 does not perform capability or object-ownership checks on its Dynamic Repeater AJ

5.4
CVE-2026-18385

The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – Profile

5.4
CVE-2026-13712

The Divi WordPress theme before 5.9.0 does not properly escape some of its Social Media Follow module settings before ou

5.4
CVE-2026-19966

A vulnerability was identified in CodeCanyon TimeCamp Integration for CRM up to 2.8. This issue affects some unknown pro

5.4
CVE-2026-19969

A security vulnerability has been detected in Open Asset Import Library Assimp 17c12da. The impacted element is the func

5.4
CVE-2026-19986

A weakness has been identified in Adblock for Youtube Extension up to 7.2.1 on Chrome. The impacted element is the funct

5.4
CVE-2026-74999

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to address book" action was subject to stored XSS.

5.4
CVE-2026-75007

In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP search filter was subject to injection via unescaped

5.4
CVE-2026-16044

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to prevent guest users from receiving Board Admin privile

5.4
CVE-2026-75053

In JetBrains IntelliJ IDEA before 2026.2.1 sSRF was possible via the DevKit debug listener endpoint

5.4
CVE-2026-54336

JumpServer is an open source bastion host and an operation and maintenance security audit system. From 4.8.0 until 4.10.

5.4
CVE-2026-75108

Next Terminal fails to enforce per-asset authorization checks on the portal ping and wake-on-LAN endpoints, allowing any

5.4
CVE-2026-64788

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe

5.4
CVE-2026-65341

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.6.1, iOS 18.7.10 and iPadOS 18.7

5.4
CVE-2026-19447

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Fileorbis Informat

5.4
CVE-2026-75107

Grav Form Plugin before 9.1.19 fails to escape field-definition properties including prepend, append, spacer text, secti

5.4
CVE-2026-75834

Grav before 2.0.14 contains a stored cross-site scripting vulnerability in the Security::detectXss() function (system/sr

5.4
CVE-2026-74963

Same-origin policy bypass in the Networking: Cookies component. This vulnerability was fixed in Firefox 154, Firefox ESR

5.4
CVE-2026-74967

Same-origin policy bypass in the Audio/Video: Playback component. This vulnerability was fixed in Firefox 154, Firefox E

5.4
CVE-2026-74968

Site isolation issue in the Graphics: WebRender component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.

5.4
CVE-2026-74970

Site isolation issue in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 153.1, Thunderb

5.4
CVE-2026-74974

Same-origin policy bypass in the Graphics: ImageLib component. This vulnerability was fixed in Firefox 154, Firefox ESR

5.4
CVE-2026-74975

Spoofing issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

5.4
CVE-2026-73995

Subscriber Broken Authentication in User Registration <= 5.2.6 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started