Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 89/454
8.6
CVE-2026-68587

SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHea

8.6
CVE-2026-71255

nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res

8.6
CVE-2026-71259

ESPHome through 2026.7.0-dev contains an operator-precedence bug in the cv.url validator in esphome/config_validation.py

8.6
CVE-2026-71270

Stirling-PDF's POST /api/v1/convert/url/pdf endpoint (ConvertWebsiteToPDF.java) was not updated with the CustomHtmlSanit

8.6
CVE-2026-20263

A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauth

8.6
CVE-2026-20268

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t

8.6
CVE-2026-20269

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t

8.6
CVE-2026-20270

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t

8.6
CVE-2026-20271

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t

8.6
CVE-2026-20273

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t

8.6
CVE-2026-20301

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of

8.6
CVE-2026-18953

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp

8.6
CVE-2026-3430

The Creative Mail WordPress plugin from 1.6.5 to 1.6.9 does not sanitize and escape a parameter before using in an SQL s

8.6
CVE-2026-19143

Insufficient validation of untrusted input in WebAPKs in Google Chrome on Android prior to 151.0.7922.109 allowed a loca

8.6
CVE-2026-53983

Ground Station prior to 0.6.0 contains an unauthenticated blind server-side request forgery vulnerability in the orbital

8.6
CVE-2026-63637

Dgraph is an open source distributed GraphQL database. Prior to 25.3.8, maybeQuoteArg in graphql/resolve/query_rewriter.

8.6
CVE-2026-48120

Kakoune is a code editor. Prior to version 2026.05.21, the bundled, enabled by default, `autorestore.kak` script can be

8.6
CVE-2026-17044

The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it

8.6
CVE-2026-19049

The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries,

8.6
CVE-2026-64940

Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory contains a vulnerability due to a permissive regular exp

8.6
CVE-2026-72581

A server-side request forgery (SSRF) vulnerability in duhow/xiaoai-patch through commit fb07049 allows a remote attacker

8.6
CVE-2026-72535

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mint

8.6
CVE-2026-72536

A missing authentication vulnerability in Chaskiq through commit 46dfdd1 allows unauthenticated remote attackers to mani

8.6
CVE-2026-20349 KEV

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Softwar

8.6
CVE-2026-20776

Improper conditions check for some Intel(R) PROSet/Wireless WiFi Software within Ring 2: Device Drivers may allow a deni

8.6
CVE-2026-48397

Lightroom Classic is affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code e

8.6
CVE-2026-48441

Lightroom Classic is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulne

8.6
CVE-2026-72742

DSPy 3.3.0b1 contains a file exfiltration vulnerability in the Image and Audio output field adapters that allows attacke

8.6
CVE-2026-73247

Kestra is an open-source, event-driven orchestration platform. Prior to 2.0.0, Kestra's core/src/main/java/io/kestra/cor

8.6
CVE-2026-68433

In the Linux kernel, the following vulnerability has been resolved: libceph: bound get_version reply decode to front le

8.6
CVE-2026-18474

The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise and escape a parameter before using it in a SQL sta

8.6
CVE-2026-72789

SiYuan before v3.7.4 fails to properly validate publish access for encrypted notebooks, treating them as publicly access

8.6
CVE-2026-72793

SiYuan versions before v3.7.4 fail to mask sensitive configuration fields in the /api/system/getConf endpoint, allowing

8.6
CVE-2026-72794

siyuan versions before v3.7.4 expose the session cookie signing key through the /api/system/getConf endpoint to unauthen

8.6
CVE-2026-72795

SiYuan versions before v3.7.4 fail to filter embedded block content by publish access in the getBlockDOMWithEmbed and ge

8.6
CVE-2026-72798

SiYuan versions before v3.7.4 fail to properly filter related-database content in renderAttributeView, allowing anonymou

8.6
CVE-2026-72804

SiYuan versions before v3.7.4 fail to validate publish-password tier in getGraph and getLocalGraph endpoints, allowing a

8.6
CVE-2026-59499

: Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Priority Portal Generator addon to Priorit

8.6
CVE-2026-59505

: Improper Access Control vulnerability in Priority Portal Generator addon to Priority ERP (developed by Soft Solutions)

8.6
CVE-2026-73608

SiYuan's development branch (endpoint introduced by commit 9b8e8956f, not present in v3.7.3 or master, patched in v3.7.4

8.6
CVE-2026-72777

Next AI Draw.io through 0.4.16 contains a server-side request forgery vulnerability in the POST /api/parse-url endpoint

8.6
CVE-2026-16815

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service and potentially obtain sensitive

8.6
CVE-2026-17502

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an out-of-bounds write.

8.6
CVE-2026-15205

The Paymob for WooCommerce WordPress plugin before 4.1.9 does not properly sanitise a client-supplied identifier before

8.6
CVE-2026-72810

SiYuan versions before v3.7.4 contain a publish-boundary bypass vulnerability in WebSocket broadcast sessions that allow

8.6
CVE-2026-74791

Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cach

8.6
CVE-2026-56677

9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in src/app/api/auth/o

8.6
CVE-2026-74902

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file upload validation flow that fails to esca

8.6
CVE-2026-75856

CodeWhale before 0.8.64 contains a server-side request forgery bypass vulnerability in DNS pinning logic that fails to p

8.6
CVE-2026-75926

Hugo 0.161.0 placed the Node asset pipelines behind the Node.js permission model so that code running through PostCSS, B

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started