Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

2,090 of 57,566 · Page 9/42
3.7
CVE-2026-54478

In NLnet Labs Unbound 1.18.0 up to and including 1.25.1, when Unbound listens on a 'proxy-protocol-port' interface with

3.7
CVE-2026-52684

If the auth responds very slowly and the records expire in between, the capping of TTLs is not enforced for lack of data

3.7
CVE-2026-52686

The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signat

3.7
CVE-2026-66753

tiny-http through 0.12.0 contains an HTTP header injection vulnerability that allows attackers to inject carriage return

3.7
CVE-2026-55403

datamodel-code-generator generates Python data models from schema definitions. Prior to 0.63.0, src/datamodel_code_gener

3.7
CVE-2026-63235

An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to forcibly terminate the se

3.7
CVE-2026-63236

An improper access control vulnerability in Koollab LMS allowed an unauthenticated attacker to read another user's name,

3.7
CVE-2026-58187

The Apache Traffic Server multiplexer plugin overruns its chunk-decode buffer on upstream input, enabling denial of serv

3.7
CVE-2026-15054

The Bit Form WordPress plugin before 3.1.2 does not enforce a form's active/published status on its public form-submiss

3.7
CVE-2026-14849

The Paid Membership Subscriptions WordPress plugin before 3.0.7 does not protect the member and payment export files it

3.7
CVE-2026-14862

The Support Genix WordPress plugin before 1.4.48 does not properly authorize access to support-ticket attachment downlo

3.7
CVE-2026-14927

The FluentCart A New Era of eCommerce WordPress plugin before 1.5.3 does not perform any authorization or ownership che

3.7
CVE-2026-15381

The WP Go Maps WordPress plugin before 10.1.04 does not properly sanitise and escape a parameter before using it in a S

3.7
CVE-2026-18206

A flaw was found in the keycloak-services component of Keycloak, which provides identity and access management services.

3.7
CVE-2026-56568

HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It inv

3.7
CVE-2026-56570

HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Va

3.7
CVE-2026-56571

HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions

3.7
CVE-2026-25552

Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass rat

3.7
CVE-2026-11882

The Builderall for WordPress plugin before 3.0.2 does not bind the state value of its public OAuth authentication routes

3.7
CVE-2026-56608

HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular acce

3.7
CVE-2026-58044

A flaw in Node.js HTTP client can cause a request desynchronization for Node.js-based forwarding proxies that rebuild ou

3.7
CVE-2026-18569

A flaw was found in the backchannel logout endpoint of the keycloak-services component, which is part of the Red Hat Bui

3.7
CVE-2026-11366

The MonsterInsights WordPress plugin before 11.1.0 does not correctly validate the signature on one of its unauthentica

3.7
CVE-2026-16993

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not protect its shipping-label storage direc

3.7
CVE-2026-70437

Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison

3.7
CVE-2025-13736

When Multi-Attribute Login is enabled, the login interface fails to consistently mask the existence of user accounts. Fo

3.7
CVE-2026-19061

A flaw has been found in Insta InstaKNXServiceApp 1.2.3.1469. Affected by this issue is the function CreateWebClientAndD

3.7
CVE-2026-48082

OpenReception's appointment booking software provides an end-to-end encrypted appointment booking platform. Prior to ver

3.7
CVE-2026-19208

A vulnerability was detected in WonderTrader up to 0.9.9. Impacted is the function TraderDD::queryTrades of the file src

3.7
CVE-2026-71849

Hono is a Web application framework that provides support for any JavaScript runtime. From 4.7.0 to 4.12.33, the Proxy H

3.7
CVE-2026-19361

A flaw has been found in macrozheng mall 0504e86. This vulnerability affects unknown code of the file /sso/getAuthCode o

3.7
CVE-2026-12372

A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk versions 3.9.4 and the current develop branch. Th

3.7
CVE-2026-17016

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not validate the amoun

3.7
CVE-2026-11809

The UpdateHub OTA client in subsys/mgmt/updatehub/updatehub.c contains an out-of-bounds / uninitialized-memory read in z

3.7
CVE-2026-11811

The UpdateHub over-the-air update client's start_coap_client() in subsys/mgmt/updatehub/updatehub.c leaks the CoAP/DTLS

3.7
CVE-2026-44762

SAP Data Services Management Console allows an overly permissive Content Security Policy (CSP) configuration and lacks c

3.7
CVE-2026-58239

SAP Approuter does not sufficiently validate tenant context in inbound requests. An unauthenticated attacker could send

3.7
CVE-2026-66774

SAP Approuter does not consistently handle certain error conditions. An attacker with low privileges could exploit this

3.7
CVE-2026-18044

The Estatik Real Estate Plugin WordPress plugin before 4.3.4 does not validate the same recipient list that it later use

3.7
CVE-2026-73425

Astro is a web framework for content-driven websites. Prior to 8.1.2, the Astro Netlify adapter converts each image.remo

3.7
CVE-2026-14213

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.6 does not verify that an authenticated em

3.7
CVE-2025-62318

HCL AION is affected by a vulnerability where JavaScript responses containing data could be referenced by external pages

3.7
CVE-2026-19748

A security vulnerability has been detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC

3.7
CVE-2026-19749

A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, CP7, TC3B14C, TC3B15C, TC3T14C and TC3T15C up to 20

3.7
CVE-2026-73844

CKAN MCP Server is a tool for querying CKAN open data portals. Prior to 0.4.112, error paths reflect raw upstream respon

3.7
CVE-2026-19891

A vulnerability was determined in TRENDnet TEW-WLC100 2.05b02. This affects an unknown function of the file /etc/racoon.

3.7
CVE-2026-19895

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This affects the function Login::in

3.7
CVE-2026-19896

A flaw has been found in mangroup dtale up to 3.22.0. This vulnerability affects the function build_secret_key of the fi

3.7
CVE-2026-19897

A vulnerability has been found in mangroup dtale up to 3.22.0. This issue affects the function Login of the file dtale/a

3.7
CVE-2026-19898

A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted is the function requestHandler of the file app/vmau

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started