Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 881/1152
5.3
CVE-2026-33160

Craft CMS is a content management system (CMS). From version 4.0.0-RC1 to before version 4.17.8 and from version 5.0.0-R

5.3
CVE-2026-33323

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version

5.3
CVE-2026-33429

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to version

5.3
CVE-2026-33769

Astro is a web framework. From version 2.10.10 to before version 5.18.1, this issue concerns Astro's remotePatterns path

5.3
CVE-2026-20632

A parsing issue in the handling of directory paths was addressed with improved path validation. This issue is fixed in m

5.3
CVE-2026-20686

This issue was addressed with improved input validation. This issue is fixed in iOS 26.3 and iPadOS 26.3. An app may be

5.3
CVE-2026-20692

A privacy issue was addressed with improved handling of user preferences. This issue is fixed in iOS 26.4 and iPadOS 26.

5.3
CVE-2026-20697

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonom

5.3
CVE-2026-28818

A logging issue was addressed with improved data redaction. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14

5.3
CVE-2026-28820

This issue was addressed with improved checks. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sen

5.3
CVE-2026-28824

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.5, macOS

5.3
CVE-2026-28828

A permissions issue was addressed by removing the vulnerable code. This issue is fixed in macOS Sequoia 15.7.5, macOS So

5.3
CVE-2026-28838

A permissions issue was addressed with additional sandbox restrictions. This issue is fixed in macOS Sequoia 15.7.5, mac

5.3
CVE-2026-28839

The issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Ta

5.3
CVE-2026-28862

A privacy issue was addressed with improved private data redaction for log entries. This issue is fixed in macOS Sequoia

5.3
CVE-2026-2343

The PeproDev Ultimate Invoice WordPress plugin through 2.2.5 has a bulk download invoices action that generates ZIP arch

5.3
CVE-2026-20113

A vulnerability in the web-based Cisco IOx application hosting environment management interface of Cisco IOS XE Software

5.3
CVE-2026-3210

Incorrect Authorization vulnerability in Drupal Material Icons allows Forceful Browsing.This issue affects Material Icon

5.3
CVE-2026-32492

Authentication Bypass by Spoofing vulnerability in Joe Dolson My Tickets my-tickets allows Identity Spoofing.This issue

5.3
CVE-2026-32497

Weak Authentication vulnerability in PickPlugins User Verification user-verification allows Authentication Abuse.This is

5.3
CVE-2026-33722

n8n is an open source workflow automation platform. Prior to versions 2.6.4 and 1.123.23, an authenticated user without

5.3
CVE-2026-33809

A maliciously crafted TIFF file can cause image decoding to attempt to allocate up 4GiB of memory, causing either excess

5.3
CVE-2026-33219

NATS-Server is a High-Performance server for NATS.io, a cloud and edge native messaging system. Prior to versions 2.11.1

5.3
CVE-2026-4281

The FormLift for Infusionsoft Web Forms plugin for WordPress is vulnerable to Missing Authorization in all versions up t

5.3
CVE-2026-1890

The LeadConnector WordPress plugin before 3.0.22 does not have authorization in a REST route, allowing unauthenticated u

5.3
CVE-2026-27813

EVerest is an EV charging software stack. Versions prior to 2026.02.0 have a data race leading to use-after-free. This i

5.3
CVE-2026-33481

Syft is a a CLI tool and Go library for generating a Software Bill of Materials (SBOM) from container images and filesys

5.3
CVE-2026-29055

Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. In versions prior t

5.3
CVE-2026-2100

A flaw was found in p11-kit. A remote attacker could exploit this vulnerability by calling the C_DeriveKey function on a

5.3
CVE-2026-33545

MobSF is a mobile application security testing tool used. Prior to version 4.4.6, MobSF's `read_sqlite()` function in `m

5.3
CVE-2026-33638

Ech0 is an open-source, self-hosted publishing platform for personal idea sharing. Prior to version 4.2.0, `GET /api/all

5.3
CVE-2026-3525

Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects

5.3
CVE-2026-3526

Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects

5.3
CVE-2026-33672

Picomatch is a glob matcher written JavaScript. Versions prior to 4.0.4, 3.0.2, and 2.3.2 are vulnerable to a method inj

5.3
CVE-2026-4900

A weakness has been identified in code-projects Online Food Ordering System 1.0. This affects an unknown part of the fil

5.3
CVE-2026-33721

MapServer is a system for developing web-based GIS applications. Starting in version 4.2 and prior to version 8.6.1, a h

5.3
CVE-2026-33366

Missing authentication for critical function vulnerability in BUFFALO Wi-Fi router products may allow an attacker to for

5.3
CVE-2025-59028

When sending invalid base64 SASL data, login process is disconnected from the auth server, causing all active authentica

5.3
CVE-2026-0394

When dovecot has been configured to use per-domain passwd files, and they are placed one path component above /etc, or s

5.3
CVE-2026-27859

A mail message containing excessive amount of RFC 2231 MIME parameters causes LMTP to use too much CPU. A suitably forma

5.3
CVE-2026-33759

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.ph

5.3
CVE-2026-33761

WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in t

5.3
CVE-2026-33763

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_corre

5.3
CVE-2026-5022

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, a

5.3
CVE-2026-34411

Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticat

5.3
CVE-2026-34364

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint,

5.3
CVE-2026-34368

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `p

5.3
CVE-2026-34369

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_ap

5.3
CVE-2026-31950

LibreChat is a ChatGPT clone with additional features. In versions 0.8.2-rc2 through 0.8.2-rc3, the SSE streaming endpoi

5.3
CVE-2026-33936

The `ecdsa` PyPI package is a pure Python implementation of ECC (Elliptic Curve Cryptography) with support for ECDSA (El

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started