Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 864/1152
5.4
CVE-2026-10618

Hugo's default fenced-code-block renderer writes attribute values taken from the code-fence info string into the rendere

5.4
CVE-2026-78272

Subscriber Broken Access Control in Fluent Support Pro <= 2.3.1 versions.

5.4
CVE-2026-78279

Unauthenticated Cross Site Request Forgery (CSRF) in Fluent Support Pro <= 2.3.1 versions.

5.4
CVE-2026-67204

BookStack before 26.05.4 contains a broken access control vulnerability that allows authenticated API users with image-u

5.4
CVE-2026-34967

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled contain an arbitrary file write vulnerability in th

5.4
CVE-2026-72702

Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, w

5.4
CVE-2026-21754

HCL Hive is affected by multiple infrastructure and network configuration vulnerabilities, which could lead to unauthori

5.4
CVE-2026-78912

UI misrepresentation in Browser in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements v

5.4
CVE-2026-79173

UI misrepresentation in WebAppInstalls in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI ele

5.4
CVE-2026-79180

UI misrepresentation in CustomTabs in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker lever

5.4
CVE-2026-79204

UI misrepresentation in Input in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker to spoof UI el

5.4
CVE-2026-79250

UI misrepresentation in Navigation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof address ba

5.4
CVE-2026-79283

UI misrepresentation in Geometry in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to spoof UI elements

5.4
CVE-2026-55805

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core

5.4
CVE-2026-80195

Kimai before 2.63.0 contains a business logic / improper authorization vulnerability in the team update API endpoint (PA

5.4
CVE-2026-74929

The Project Manager WordPress plugin before 4.0.7 does not restrict several of its REST API routes to the projects a us

5.4
CVE-2026-77757

The Directorist: AI-Powered Business Directory, Listings & Classified Ads WordPress plugin before 8.9.3 does not sanitiz

5.4
CVE-2026-80204

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not apply the API-key scope cap in the injectSecurityTa

5.4
CVE-2026-13481

The IEEE 1588 PTP management-message parser in subsys/net/lib/ptp/tlv.c mishandles the PTP_MGMT_TIME management id. In t

5.4
CVE-2026-54553

Starlette-Admin is a fast, beautiful and extensible administrative interface framework for FastAPI and Starlette applica

5.4
CVE-2026-54256

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th

5.4
CVE-2026-45694

LibreNMS is a network monitoring system. In versions up to and including 26.4.0, the Proxmox application view is vulnera

5.4
CVE-2026-47859

RFC6587SyslogDeserializer, used by the Spring Integration syslog TCP inbound adapter to decode RFC 6587 / RFC 5424 frame

5.4
CVE-2026-47862

An attacker who can set the file_name header on a message reaching a ZipTransformer with ZipResultType.FILE (the default

5.4
CVE-2026-47880

A producer who can publish to a JMS destination consumed by any Spring Integration JMS inbound component can set String

5.4
CVE-2026-81279

Subscriber Broken Access Control in Push Notification for Post and BuddyPress <= 3.20 versions.

5.4
CVE-2026-81668

A flaw was found in Katello where the Content View Filter Rules API does not properly enforce authorization on the paren

5.4
CVE-2026-71402

An out-of-bounds read was found in the DHCPv4 packet capture code of wicked. ni_capture_inspect_udp_header() in src/capt

5.4
CVE-2026-81524

A weakness in the MongoDB C Driver allows special elements in caller-supplied database and collection name components to

5.4
CVE-2026-81528

A MongoDB C# driver document-replacement code path omits the element-name/shape validation that the equivalent write pat

5.4
CVE-2026-81731

Frappe 15.11.0 through 16.32.0 stores and renders the workspace card description without XSS filtering. The description

5.4
CVE-2026-71396

Bendix EC80 Brake ECU uses hard-coded credentials, which could allow an attacker to disable automatic traction control.

5.4
CVE-2026-75548

The affected Ebyte device web management interface does not restrict the interface from being rendered within an extern

5.4
CVE-2026-73827

SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th

5.4
CVE-2026-77838

SOY Calendar contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th

5.4
CVE-2026-78238

SOY Gallery contains a cross-site scripting vulnerability. An arbitrary script may be executed on the web browser of th

5.4
CVE-2026-18393

A flaw was found in FFmpeg. The tdsc_load_cursor() function writes beyond the bounds of a heap-allocated buffer when pro

5.4
CVE-2026-38725

xipblog module v2.0.1 and before for PrestaShop allows unauthenticated remote attackers to inject arbitrary JavaScript v

5.4
CVE-2026-4378

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Akilli Ticaret Sof

5.4
CVE-2026-81759

Contributor Broken Access Control in WpEvently <= 5.5.0 versions.

5.4
CVE-2026-62904

Incorrect authorization in Microsoft Edge (Chromium-based) allows an unauthorized attacker to disclose information over

5.4
CVE-2026-66323

Improper neutralization of parameter/argument delimiters in Microsoft Edge (Chromium-based) allows an unauthorized attac

5.4
CVE-2026-70309

Origin validation error in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature

5.4
CVE-2026-70331

Improper neutralization of input used for llm prompting in Microsoft Edge for iOS allows an unauthorized attacker to per

5.4
CVE-2026-82267

Komodo through 2.3.2 discloses internal resource identifiers and writes audit entries before performing permission check

5.4
CVE-2026-55779

Silverstripe Versioned provides versioning for Silverstripe models. Prior to 3.2.1, RestoreAction::getRestoreMessage() i

5.4
CVE-2026-17522

The Newsletters WordPress plugin before 4.17 does not perform any nonce or capability check when saving one of its setti

5.4
CVE-2026-82469

Rodauth before 2.47.0 contains an authentication bypass vulnerability in the jwt_refresh route that issues new JWT acces

5.4
CVE-2026-82470

Rodauth before 2.47.0 contains a time-based one-time password reuse vulnerability in the otp feature that fails to track

5.4
CVE-2026-82423

A vulnerability has been found in macrozheng mall up to 1.0.3. The affected element is an unknown function of the file /

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started