Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 9/436
6.8
CVE-2026-18269

Kenwood DNR1007XR tchdr_bytestream_read Out-Of-Bounds Write Code Execution Vulnerability. This vulnerability allows phys

6.8
CVE-2026-18271

Kenwood DNR1007XR vCardParser Heap-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physica

6.8
CVE-2026-18272

Kenwood DNR1007XR startUpdateProcess Command Injection Vulnerability. This vulnerability allows physically present attac

6.8
CVE-2026-61625

VictoriaMetrics is a scalable solution for monitoring and managing time series data. Prior to 1.122.25, 1.136.12, and 1.

6.8
CVE-2026-14601

The Link Whisper Free WordPress plugin before 0.9.7 does not properly sanitize and escape a parameter before using it in

6.8
CVE-2026-16959

The Media Library Assistant WordPress plugin before 3.40 does not validate a search parameter before concatenating it in

6.8
CVE-2026-16260

The Post Grid, Slider & Carousel Ultimate WordPress plugin before 1.8.1 does not sanitise and escape one of its custom

6.8
CVE-2026-19093

The Tutor LMS WordPress plugin before 4.0.6 does not validate a stored file path before using it to stream media, allow

6.8
CVE-2026-17033

An authenticated attacker with Editor access or alert.instances.external:write can submit an external Alertmanager alert

6.8
CVE-2026-5006

A vulnerability was identified in HashiCorp Vault and Vault Enterprise (“Vault”) such that an authenticated attacker may

6.8
CVE-2026-56706

Adminer before 5.4.3 uses a CSRF token scheme that transmits both the XOR mask and the masked value in every token (form

6.8
CVE-2026-13215

The Zephyr ext2 filesystem driver fails to validate the s_log_block_size field of the on-disk superblock when mounting a

6.8
CVE-2026-55535

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the Jobs API validate_webhook_url() path fails open

6.8
CVE-2026-24167

NVIDIA UFM Enterprise contains a vulnerability in the user management component, where an authenticated administrator co

6.8
CVE-2026-24168

NVIDIA UFM Enterprise contains a vulnerability in the IBDiagnet API where an authenticated attacker with administrative

6.8
CVE-2026-65086

NVIDIA OpenShell for Linux contains a vulnerability in its sandbox exec handler, where an attacker could cause an OS com

6.8
CVE-2026-73180

Insufficient Session Expiration vulnerability in Apache Tomcat meant that if the session ID for an authenticated HTTP se

6.8
CVE-2026-19226

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not validate some widget settings before outputtin

6.8
CVE-2026-32639

Winter CMS is a content management system built on the Laravel PHP framework. In versions up to and including 1.2.12, th

6.8
CVE-2026-47837

Missing Authentication for Critical Function vulnerability in Spring Spring Cloud Config allows Webhook requests to Spri

6.8
CVE-2026-78275

Editor Arbitrary File Deletion in Fluent Boards Pro <= 2.0.11 versions.

6.8
CVE-2026-59272

Any application shipping logs to RabbitMQ over TLS via the Log4j2 appender, relying on the documented default, is expose

6.8
CVE-2026-81092

mcp-go accepted requests on its HTTP transports without checking the Host header. StreamableHTTPServer.ServeHTTP in serv

6.8
CVE-2026-81095

pg-aiguide started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src/httpServ

6.8
CVE-2026-81099

tiger-slack started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. mcp/src/htt

6.8
CVE-2026-81100

tiger-gh-mcp-server started its MCP HTTP transport without enabling the host allow-list the underlying SDK provides. src

6.8
CVE-2026-81706

openssl_encrypt before 1.4.9 fails to prevent namespace collisions between own identities and contacts in IdentityStore,

6.8
CVE-2026-59311

A local unprivileged user on the same host can redirect all Zip/UnZip transformer output into a directory of their choos

6.8
CVE-2026-12513

The Shared Files WordPress plugin before 1.7.67, shared-files-pro WordPress plugin before 1.7.68 do not properly saniti

6.8
CVE-2026-82255

gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerability in the curl-based transport backend where cr

6.8
CVE-2026-82020

Hermes Agent 0.16.0 prior to 0.17.0 contains an improper path restriction vulnerability that allows attackers who can in

6.8
CVE-2026-82262

Logto through 1.42.0 contains a server-side request forgery vulnerability in the POST /api/hooks/:id/test endpoint that

6.8
CVE-2026-82263

Logto through 1.42.0 contains a server-side request forgery vulnerability in the OIDC SSO connector creation endpoint th

6.8
CVE-2026-82264

Duplicacy through 3.2.5 contains a path traversal vulnerability in the restore function that fails to validate entry pat

6.8
CVE-2026-76546

The User Profile Builder WordPress plugin before 4.0.1 does not escape the output of one of its optional shortcodes, al

6.7
CVE-2025-20782

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

6.7
CVE-2025-20783

In display, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation o

6.7
CVE-2025-20784

In display, there is a possible memory corruption due to uninitialized data. This could lead to local escalation of priv

6.7
CVE-2025-20785

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20786

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20787

In display, there is a possible memory corruption due to use after free. This could lead to local escalation of privileg

6.7
CVE-2025-20802

In geniezone, there is a possible memory corruption due to use after free. This could lead to local escalation of privil

6.7
CVE-2025-20803

In dpe, there is a possible memory corruption due to an integer overflow. This could lead to local escalation of privile

6.7
CVE-2025-20804

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if

6.7
CVE-2025-20805

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if

6.7
CVE-2025-20806

In dpe, there is a possible memory corruption due to use after free. This could lead to local escalation of privilege if

6.7
CVE-2025-20807

In dpe, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privi

6.7
CVE-2025-14596

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro Installer (SFX) on Windows allows Search

6.7
CVE-2025-14599

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Standard Installer (SFX) on Windows, Altera Qu

6.7
CVE-2025-14605

Uncontrolled Search Path Element vulnerability in Altera Quartus Prime Pro on Windows (System Console modules) allows Se

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started