Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 88/454
8.6
CVE-2026-60293

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: WLS - Web Services). Suppor

8.6
CVE-2026-60327

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp

8.6
CVE-2026-60356

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp

8.6
CVE-2026-60359

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

8.6
CVE-2026-60431

Vulnerability in the Oracle HTTP Server product of Oracle Fusion Middleware (component: mod_proxy). Supported versions

8.6
CVE-2026-60536

Vulnerability in the Oracle Identity Manager Connector product of Oracle Fusion Middleware (component: PeopleSoft Applic

8.6
CVE-2026-60550

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported

8.6
CVE-2026-60556

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported

8.6
CVE-2026-60559

Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supp

8.6
CVE-2026-60671

Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: BI Platform

8.6
CVE-2026-65317

Verba RAG application version 2.1.3 contains a server-side request forgery vulnerability combined with a same-origin mid

8.6
CVE-2026-65318

Verba RAG application version 2.1.3 contains an unauthenticated server-side request forgery vulnerability that allows un

8.6
CVE-2026-13321

The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zon

8.6
CVE-2026-64814

In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session

8.6
CVE-2026-65908

In JetBrains PyCharm before 2026.1.4, 2026.2 arbitrary code execution via malicious Python executable was possible on un

8.6
CVE-2026-65702

Vanna through 2.0.2 contains a path traversal vulnerability in the FileSystemConversationStore persistence integration t

8.6
CVE-2026-28698

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr

8.6
CVE-2026-64400

In the Linux kernel, the following vulnerability has been resolved: ksmbd: prevent path traversal bypass by restricting

8.6
CVE-2025-15662

The Printcart Web to Print Product Designer for WooCommerce WordPress plugin before 2.5.3 does not restrict a user-suppl

8.6
CVE-2026-28973

An integer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10,

8.6
CVE-2026-43760

An access issue was addressed with improved access restrictions. This issue is fixed in macOS Sonoma 14.8.8, macOS Tahoe

8.6
CVE-2026-45293

WordPress Coding Standards is a set of PHP_CodeSniffer rules (sniffs) that enforce WordPress coding conventions. From 0.

8.6
CVE-2026-54603

OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frameworks, including OpenID Connect (OIDC). From 0.4.0

8.6
CVE-2026-54609

QTI Neon is a minimal, game-agnostic, relay-based UDP multiplayer protocol library. In version 1.0.0, the relay's handle

8.6
CVE-2026-48388

Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in

8.6
CVE-2026-14869

The terraform-mcp-server before version 1.1.0 is vulnerable to a server-side request forgery issue in the streamable-HTT

8.6
CVE-2026-48395

Bridge is affected by an Untrusted Search Path vulnerability that could result in arbitrary code execution in the contex

8.6
CVE-2026-48396

Bridge is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the cont

8.6
CVE-2026-54650

openhole exposes localhost to the internet in one command. In 0.1.1 and earlier, openhole-server in internal/server/publ

8.6
CVE-2026-11974

The wp-media-folder-addon WordPress plugin before 4.1.7 does not validate a user-supplied parameter before using it in a

8.6
CVE-2026-58182

The Apache Traffic Server ts_lua plugin mishandles initialization, transform context, and per-instance state. This issu

8.6
CVE-2026-56389

GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of gram

8.6
CVE-2026-16328

In consul-mcp-server, versions 0.1.0 up to 0.1.3 did not restrict how the Consul backend address was supplied, allowing

8.6
CVE-2026-67201

V through 0.5.2, fixed in commit 85859f0, contains a server-side request forgery (SSRF) bypass vulnerability that allows

8.6
CVE-2026-67425

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, llm.chat reads provider keys

8.6
CVE-2026-67427

Flyto2 Core is an execution kernel for automation and AI-agent workflows. Prior to 2.26.6, the workflow engine variable

8.6
CVE-2026-17699

Use after free in Views in Google Chrome prior to 151.0.7922.72 allowed a local attacker to potentially perform a sandbo

8.6
CVE-2026-48448

Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL

8.6
CVE-2026-13395

The Online Scheduling and Appointment Booking System WordPress plugin before 27.8 does not sanitize or properly cast a

8.6
CVE-2026-44094

An unauthenticated remote attacker can enforce the system to fall back to a firmware partition with an insecure configur

8.6
CVE-2026-44098

This vulnerability allows an unauthenticated remote attacker with control over the OCPP backend via firewall-bypass to p

8.6
CVE-2026-22620

Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unau

8.6
CVE-2026-54367

CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, w

8.6
CVE-2026-67346

Swarms through 6.8.1, fixed in commit 8b0fc9e, contains a server-side request forgery vulnerability in the _is_safe_url

8.6
CVE-2026-12721

The Kirki WordPress plugin before 6.0.13 does not properly sanitise and escape a value taken from the request before us

8.6
CVE-2025-71399

Better Auth relies on better-call, which uses the rou3 router library. In affected versions of rou3, paths are normalize

8.6
CVE-2026-12185

In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates from untrusted lengths before integrity check. This i

8.6
CVE-2026-16572

The LogMyTrip WordPress plugin through 1.9 does not sanitize and escape a value taken from a cookie before using it in a

8.6
CVE-2026-68584

SiYuan versions before v3.7.3 contain an authentication bypass vulnerability in publish mode where content-returning end

8.6
CVE-2026-68586

SiYuan before v3.7.3 fails to apply publish-access filters to the getBacklinkDoc and getBackmentionDoc content endpoints

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started