Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 90/436
6.5
CVE-2026-65330

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe

6.5
CVE-2026-65347

The issue was addressed with improved checks. This issue is fixed in iOS 26.6.1 and iPadOS 26.6.1, macOS Tahoe 26.6.2. P

6.5
CVE-2026-69146

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. From 3.

6.5
CVE-2026-9859

Mattermost versions 11.7.x <= 11.7.6, 10.11.x <= 10.11.21, 11.8.x <= 11.8.3 fail to enforce PermissionManageBoardRoles o

6.5
CVE-2026-74945

Information disclosure in the Graphics: Text component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39,

6.5
CVE-2026-74948

Information disclosure in the Graphics component. This vulnerability was fixed in Firefox 154, Firefox ESR 115.39, Firef

6.5
CVE-2026-74951

Clickjacking issue in Firefox for Android. This vulnerability was fixed in Firefox 154.

6.5
CVE-2026-74976

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 154, Firefox ESR 140

6.5
CVE-2026-74980

Clickjacking issue in the Downloads component in Firefox for Android. This vulnerability was fixed in Firefox 154.

6.5
CVE-2026-59949

yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JNI-backed XXHash implementations fail to validate t

6.5
CVE-2026-66636

Contributor Cross Site Scripting (XSS) in Wise Chat <= 3.4 versions.

6.5
CVE-2026-66637

Contributor Cross Site Scripting (XSS) in Featured Video Plus <= 2.3.3 versions.

6.5
CVE-2026-66638

Contributor Cross Site Scripting (XSS) in Frontend Admin by DynamiApps <= 3.29.10 versions.

6.5
CVE-2026-66639

Contributor Cross Site Scripting (XSS) in WPZOOM Forms – Contact Form Plugin for Gutenberg <= 2.0.4 versions.

6.5
CVE-2026-66640

Contributor Cross Site Scripting (XSS) in Login With Ajax <= 4.5.1 versions.

6.5
CVE-2026-66641

Contributor Cross Site Scripting (XSS) in Video Conferencing with Zoom <= 4.6.8 versions.

6.5
CVE-2026-66643

Contributor Cross Site Scripting (XSS) in Wufoo Shortcode <= 1.55 versions.

6.5
CVE-2026-66644

Contributor Cross Site Scripting (XSS) in Typing Effect <= 1.3.7 versions.

6.5
CVE-2026-66645

Contributor Cross Site Scripting (XSS) in Table Of Contents Block <= 1.5.0 versions.

6.5
CVE-2026-66646

Contributor Cross Site Scripting (XSS) in WP Tab Widget <= 1.2.11 versions.

6.5
CVE-2026-66651

Unauthenticated Broken Access Control in MultiVendorX <= 5.0.14 versions.

6.5
CVE-2026-66679

Unauthenticated Broken Access Control in Appointment Hour Booking <= 1.5.91 versions.

6.5
CVE-2026-68565

Contributor Cross Site Scripting (XSS) in GeoDirectory <= 2.8.172 versions.

6.5
CVE-2026-73348

Unauthenticated Broken Access Control in GiveWP < 4.16.6 versions.

6.5
CVE-2026-73352

Unauthenticated Broken Access Control in GiveWP <= 4.16.5.1 versions.

6.5
CVE-2026-73359

Subscriber Cross Site Scripting (XSS) in WP Cookie Notice for GDPR, CCPA & ePrivacy Consent <= 4.3.9 versions.

6.5
CVE-2026-73379

Unauthenticated Bypass Vulnerability in Contact Form by Supsystic < 1.10.0 versions.

6.5
CVE-2026-73395

Unauthenticated Insecure Direct Object References (IDOR) in Booking calendar, Appointment Booking System <= 3.2.36 versi

6.5
CVE-2026-73398

Unauthenticated Broken Authentication in Piraeus Bank WooCommerce Payment Gateway 3.2.0 versions.

6.5
CVE-2026-73399

Unauthenticated Broken Authentication in Flutterwave WooCommerce <= 3.3.0 versions.

6.5
CVE-2026-73404

Subscriber Broken Access Control in MasterStudy LMS <= 3.7.41 versions.

6.5
CVE-2026-48744

Saleor is an e-commerce platform. From 3.14.67 until 3.21.67, 3.22.63, and 3.23.22, a broken authorization check in sale

6.5
CVE-2026-66781

A flaw was found in the Submariner operator. The Submariner Custom Resource (CR), used for configuring network connectiv

6.5
CVE-2026-49452

WeasyPrint helps web developers to create PDF documents. Prior to 69.0, WeasyPrint embeds unescaped HTML presentational-

6.5
CVE-2026-52607

A directory traversal vulnerability in reportico-web <= 8.1.0 allows remote attackers to expose or execute arbitrary php

6.5
CVE-2026-68923

MobSF is a mobile application security testing tool used. Prior to 4.5.1, mobsf/MobSF/settings.py places django.middlewa

6.5
CVE-2026-69160

OpenList a file list program that supports multiple storage. Prior to 4.2.4, the share creation and update checks in ser

6.5
CVE-2026-74039

Wazuh 4.0.0 before 4.14.7 and 5.0.0-beta2 contain a denial of service vulnerability that allows authenticated attackers

6.5
CVE-2026-74044

Wazuh 4.0.0 before 4.14.6 contains a path traversal vulnerability that allows authenticated cluster peers to delete arbi

6.5
CVE-2026-47606

NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker could cause an absolute path travers

6.5
CVE-2026-19671

Malcolm's upload-processing pipeline (scripts/safe-extract.py) enforces entry-count, nesting-depth, and total-uncompress

6.5
CVE-2026-52480

An issue in SJRC F11 SJ-GPS-PRO firmware build 2019-09-17 allows a remote attacker to obtain sensitive information via t

6.5
CVE-2026-52731

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, an attacker authenticated to an enabled Zebra RPC endpoi

6.5
CVE-2026-52733

ZEBRA is a Zcash node written entirely in Rust. Prior to 4.5.0, a natural or attacker-influenced chain fork can leave st

6.5
CVE-2026-71317

Lemur manages TLS certificate creation. Prior to 1.9.3, POST /api/1/authorities with type=subca did not require Authorit

6.5
CVE-2026-12631

The Zephyr kernel validates the k_thread_join() and k_thread_abort() system calls (declared __syscall in include/zephyr/

6.5
CVE-2026-12632

Zephyr's Precision Time Protocol receive handler ptp_msg_post_recv() in subsys/net/lib/ptp/msg.c takes the 4-bit message

6.5
CVE-2026-55593

Froxlor is open source server administration software. Prior to 2.3.8, the standalone lib/ajax.php entry point bypasses

6.5
CVE-2026-60682

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Repository). The suppo

6.5
CVE-2026-60830

Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Worklist). Supported versions that

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started