Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 90/454
8.6
CVE-2026-60699

Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions t

8.6
CVE-2026-61033

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported

8.6
CVE-2026-61045

Vulnerability in the Oracle WebCenter Sites product of Oracle Fusion Middleware (component: WebCenter Sites). Supported

8.6
CVE-2026-61228

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported

8.6
CVE-2026-61230

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported

8.6
CVE-2026-61286

Vulnerability in the Oracle Enterprise Manager Base Platform product of Oracle Enterprise Manager (component: Event Mana

8.6
CVE-2026-62535

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

8.6
CVE-2026-62586

Vulnerability in the Siebel CRM Administration product of Oracle Siebel CRM (component: Data Archival). Supported versi

8.6
CVE-2026-62599

Vulnerability in the Oracle Trading Community product of Oracle E-Business Suite (component: Third Party Data Integratio

8.6
CVE-2026-62620

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

8.6
CVE-2026-62625

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

8.6
CVE-2026-62628

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

8.6
CVE-2026-62636

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

8.6
CVE-2026-70721

Vulnerability in the Oracle Hyperion Profitability and Cost Management product of Oracle Hyperion (component: Deployment

8.6
CVE-2026-70996

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

8.6
CVE-2026-71131

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

8.6
CVE-2026-73939

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

8.6
CVE-2026-52854

Maps is a MediaWiki extension that enables visualization of geographic data through dynamic embedded maps. Prior to vers

8.6
CVE-2026-12983

The Dinatur WordPress plugin through 1.18 does not sanitize and escape user input before using it in a SQL query, allowi

8.6
CVE-2026-16616

The Simple File List WordPress plugin through 6.3.11 does not validate the source path of a file-move operation reachabl

8.6
CVE-2026-16950

The Product Shortlist WordPress plugin through 1.0.4 does not properly sanitise and escape a parameter before using it i

8.6
CVE-2026-75916

SiYuan through 3.7.3 contains a cross-site scripting vulnerability in the '((' block-reference autocomplete hint popup.

8.6
CVE-2026-75917

SiYuan before v3.7.4 contains a cross-site scripting vulnerability in the file-tree picker's hover-tooltip generation (a

8.6
CVE-2026-66800

Server-side request forgery (ssrf) in Azure Data Factory allows an unauthorized attacker to disclose information over a

8.6
CVE-2026-69519

Observable response discrepancy in Azure Stack HCI allows an unauthorized attacker to disclose information over a networ

8.6
CVE-2026-69558

Authorization bypass through user-controlled key in Microsoft Partner Center allows an unauthorized attacker to disclose

8.6
CVE-2026-72848

SitemapLoader.parse_sitemap in langchain_community/document_loaders/sitemap.py applies the documented restrict_to_same_d

8.6
CVE-2026-77775

Headroom's LLM proxy lets a client choose the upstream destination with the x-headroom-base-url request header. _resolve

8.6
CVE-2026-75932

Jet Admin allows an attacker to create a malicious app and connect it to a target user's custom domain, edit the authent

8.6
CVE-2026-34741

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, authentication bypass allows unauthenticated rem

8.6
CVE-2026-28171

Unauthenticated Arbitrary File Deletion in WooCommerce File Approval <= 10.7 versions.

8.6
CVE-2026-32477

Unauthenticated Arbitrary File Deletion in ShopBuilder Pro – Elementor WooCommerce Builder Addons <= 2.2.0 versions.

8.6
CVE-2026-78284

Unauthenticated Arbitrary File Deletion in MasterStudy LMS <= 3.7.42 versions.

8.6
CVE-2026-63587

The SMS control function of IE-SR-2TX-WL-4G devices can require a password for SMS commands via the 'Enable Password Aut

8.6
CVE-2026-55534

PraisonAI is a multi-agent teams system. From praisonai 4.6.34 until 4.6.58, praisonai serve agents accepts --api-key bu

8.6
CVE-2022-50999

Nokogiri versions before 1.13.5 contain an integer overflow vulnerability in packaged libxml2 buffer handling functions

8.6
CVE-2026-55539

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.51, the Jobs API create_app function mounts /api/v1/runs

8.6
CVE-2026-54511

LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, and 2.1.5, the @logtape/syslog package's escapeStruc

8.6
CVE-2026-27330

Unauthenticated Broken Access Control in Mobile App for WooCommerce <= 0.4.62 versions.

8.6
CVE-2026-81573

If CodeMeter Runtime before 8.41a or 9.10 is configured as a server, the configuration command handler does not enforce

8.6
CVE-2026-81091

The proxy middleware in mcp-use's inspector forwards requests to a destination the caller names. mountMcpProxy in librar

8.6
CVE-2026-81093

The get-html-skeleton tool fetched a URL the caller supplied after checking only its syntax. The handler in src/tools/co

8.6
CVE-2026-80590

In the Linux kernel, the following vulnerability has been resolved: inet: frags: strip GSO state from fragments before

8.6
CVE-2026-82286

gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthent

8.6
CVE-2026-55848

mapfish-print is a component of MapFish for printing templated cartographic maps. Prior to 3.28.30, 3.30.32, 3.31.24, 3.

8.6
CVE-2026-16061

The Rest Routes WordPress plugin through 5.5.5 does not sanitize and validate a value taken from the URL of one of its

8.6
CVE-2026-82641

keploy versions 3.1.0 through 3.6.25 bind the agent control-plane HTTP server to all interfaces without authentication,

8.6
CVE-2026-82645

AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/get

8.5
CVE-2025-69414

Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call wit

8.5
CVE-2025-31044

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in AA-Team Premium SE

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started