Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 88/436
6.5
CVE-2026-66693

Subscriber Broken Access Control in Motors <= 1.4.113 versions.

6.5
CVE-2026-73340

Contributor Cross Site Scripting (XSS) in Featured Image from URL <= 5.3.3 versions.

6.5
CVE-2026-73357

Donor Cross Site Scripting (XSS) in GiveWP < 4.16.6 versions.

6.5
CVE-2026-53786

rsync before 3.5.0 contains a filter rule bypass vulnerability that allows authenticated clients to override module-leve

6.5
CVE-2026-53788

rsync before 3.5.0 contains a newline injection vulnerability in the name-converter uid/gid mapping interface that allow

6.5
CVE-2026-53789

rsync before 3.5.0 contains an improper path handling vulnerability that allows a malicious sender to expand the scope o

6.5
CVE-2026-53792

rsync before 3.5.0 contains an out-of-bounds read vulnerability in the sender-side block matching logic that allows a ma

6.5
CVE-2026-70457

rsync 3.2.3 before 3.5.0 contains an out-of-bounds write in parse_size_arg() where the return value of snprintf() is use

6.5
CVE-2026-70462

rsync 3.1.0 before 3.5.0 contains a signed integer overflow vulnerability in the I/O timeout implementation that allows

6.5
CVE-2026-73559

vLLM is an inference and serving engine for large language models. From 0.19.0 until 0.26.0, the /v1/completions Complet

6.5
CVE-2026-24059

The GET /api/v1/user/actions/runners/registration-token endpoint (and its owner- and repository-level equivalents) creat

6.5
CVE-2026-42931

Denial of Service via Unbounded io.ReadAll in NPM Package Tag Endpoint

6.5
CVE-2026-57897

Cross-Repo Information Disclosure via Org-Level Actions Run/Job APIs

6.5
CVE-2026-58428

Release attachment extension allowlist bypass via web release edit form (variant of CVE-2025-68939)

6.5
CVE-2026-58442

Repository migration SSRF via multi-answer DNS allow-list bypass

6.5
CVE-2026-12236

The Bluetooth host GATT client function parse_read_std_char_desc() in subsys/bluetooth/host/gatt.c parses an ATT Read By

6.5
CVE-2026-73562

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.10, 7.8.10, 8.

6.5
CVE-2026-16692

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attacker to cause a denial of service due to a stack-bas

6.5
CVE-2026-16853

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information due to an out-of-bounds read.

6.5
CVE-2026-49089

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All

6.5
CVE-2026-72631

Improper Privilege Management (CWE-269) in Kibana Fleet can lead to privilege escalation via Privilege Escalation (CAPEC

6.5
CVE-2026-72636

Uncontrolled Recursion (CWE-674) in the Elasticsearch wildcard matching helper can lead to a denial of service via Exces

6.5
CVE-2026-72638

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Input Data Manipulation (CAPEC-153).

6.5
CVE-2026-72639

Elasticsearch does not enforce an upper bound on a user-supplied count accepted by a search highlighting option, and the

6.5
CVE-2026-72640

The Elastic Cloud on Kubernetes (ECK) operator reads a list of secret references from an annotation on secrets it manage

6.5
CVE-2026-72645

Memory Allocation with Excessive Size Value (CWE-789) in Elasticsearch can lead to denial of service via Excessive Alloc

6.5
CVE-2026-72647

Uncontrolled Recursion (CWE-674) in Elasticsearch can lead to denial of service via Serialized Data with Nested Payloads

6.5
CVE-2026-72648

Cleartext Storage of Sensitive Information in an Environment Variable (CWE-526) in Elastic Cloud on Kubernetes (ECK) can

6.5
CVE-2026-72651

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All

6.5
CVE-2026-72653

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All

6.5
CVE-2026-72656

Memory Allocation with Excessive Size Value (CWE-789) in the ES|QL query processing of Elasticsearch can lead to denial

6.5
CVE-2026-72657

Authorization Bypass Through User-Controlled Key (CWE-639) in Fleet Server can lead to information disclosure via Manipu

6.5
CVE-2026-72659

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to denial of service via Excessive All

6.5
CVE-2026-72660

Uncaught Exception (CWE-248), resulting from Improper Input Validation (CWE-20), in Kibana can lead to denial of service

6.5
CVE-2026-72661

Missing Authorization (CWE-862) in Kibana can lead to information disclosure via Accessing Functionality Not Properly Co

6.5
CVE-2026-72663

Inefficient Algorithmic Complexity (CWE-407) in Kibana can lead to denial of service via Input Data Manipulation (CAPEC-

6.5
CVE-2026-72664

Missing Authorization (CWE-862) in Kibana can lead to unauthorized execution of Elastic Defend response actions on manag

6.5
CVE-2026-72667

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A

6.5
CVE-2026-72674

Allocation of Resources Without Limits or Throttling (CWE-770) in Kibana can lead to a denial of service via Excessive A

6.5
CVE-2026-72676

Improper Control of Generation of Code ('Code Injection') (CWE-94) in Fleet Server can lead to the execution of attacker

6.5
CVE-2026-72678

Elasticsearch does not validate a size value taken from a user-supplied input before that value is used to reserve memor

6.5
CVE-2026-72679

Elasticsearch does not apply its configurable input length restriction to a user-supplied pattern accepted by an interva

6.5
CVE-2026-72680

Kibana Agent Builder A2A JSON-RPC API endpoint derives the identifier of a stored conversation from a user-supplied inpu

6.5
CVE-2026-72681

Kibana Agent Builder does not correctly verify that the requesting user holds the privileges required by a separate Kiba

6.5
CVE-2026-72683

A flaw in Elasticsearch allows an authenticated user with the privileges required to invoke the simulate pipeline API en

6.5
CVE-2026-72684

A flaw in Elasticsearch allows an authenticated user holding only read privileges to submit a small search request conta

6.5
CVE-2026-72686

A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single request containing a crafted user-

6.5
CVE-2026-72687

A flaw in Elasticsearch allows a low-privileged authenticated user to submit a single small request containing a forged

6.5
CVE-2026-17075

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to obtain sensitive information and perform unauthorized oper

6.5
CVE-2026-18671

IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to force a NetServer server thread exception, caused

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started