Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 907/1152
5.3
CVE-2026-13057

An issue in the server’s Atlas Search integration allows an authenticated user to bypass per-user access controls. In

5.3
CVE-2026-13070

A MongoDB server initiating an outbound TLS connection may terminate abnormally when processing a malformed OCSP respons

5.3
CVE-2026-13074

An unauthenticated remote client can cause excessive CPU consumption on a MongoDB server by sending a specific combinati

5.3
CVE-2026-16628

A vulnerability was detected in oclif up to 4.23.16. Affected by this vulnerability is the function child_process.exec o

5.3
CVE-2026-16629

A vulnerability was identified in danger danger-js up to 13.0.7. Impacted is the function danger.git.diffForFile of the

5.3
CVE-2026-16630

A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the funct

5.3
CVE-2026-16631

A vulnerability was detected in publint up to 0.1.4. This impacts the function child_process.exec of the file src/node/p

5.3
CVE-2026-16653

A security flaw has been discovered in boazsegev facil.io up to 0.7.58. This affects the function http_sendfile2 of the

5.3
CVE-2026-21723

The alertmanager templates test endpoint (/api/alertmanager/grafana/config/api/v1/templates/test) can execute templates

5.3
CVE-2026-7120

@fastify/static evaluates the allowedPath callback before normalizing dot segments and duplicate path separators in the

5.3
CVE-2026-15827

The GutenKit Blocks plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check

5.3
CVE-2026-25466

Unauthenticated Broken Access Control in WP Go Maps <= 10.1.04 versions.

5.3
CVE-2026-27355

Unauthenticated Broken Access Control in Ditty <= 3.1.66 versions.

5.3
CVE-2026-27399

Unauthenticated Broken Access Control in MarketKing <= 2.1.40 versions.

5.3
CVE-2026-27418

Unauthenticated Broken Access Control in WP Fast Total Search <= 1.81.282 versions.

5.3
CVE-2026-27422

Unauthenticated Broken Access Control in YT Player <= 2.0.9 versions.

5.3
CVE-2026-57716

Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions.

5.3
CVE-2026-61972

Unauthenticated Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

5.3
CVE-2026-65452

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

5.3
CVE-2026-65453

Unauthenticated Broken Access Control in Ebook Store <= 6.19 versions.

5.3
CVE-2026-65468

Unauthenticated Broken Access Control in JetBooking <= 4.1.2 versions.

5.3
CVE-2026-65469

Unauthenticated Broken Access Control in AWP Classifieds <= 4.4.7 versions.

5.3
CVE-2026-65472

Unauthenticated Broken Access Control in Kit (formerly ConvertKit) <= 3.3.5 versions.

5.3
CVE-2026-65474

Unauthenticated Sensitive Data Exposure in Ninja Tables <= 5.2.10 versions.

5.3
CVE-2026-65476

Unauthenticated Broken Access Control in Civi <= 2.2.4 versions.

5.3
CVE-2026-65485

Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions.

5.3
CVE-2026-65486

Unauthenticated Broken Access Control in Event post <= 6.0.1 versions.

5.3
CVE-2026-65487

Unauthenticated Broken Access Control in Photography <= 7.7.6 versions.

5.3
CVE-2026-65489

Unauthenticated Broken Access Control in LA-Studio Element Kit for Elementor <= 1.6.2 versions.

5.3
CVE-2026-65490

Unauthenticated Sensitive Data Exposure in Create by Mediavine <= 2.5.3 versions.

5.3
CVE-2026-65498

Unauthenticated Sensitive Data Exposure in Complianz <= 7.5.0 versions.

5.3
CVE-2026-65501

Unauthenticated Insecure Direct Object References (IDOR) in Shiptastic for WooCommerce <= 5.1.0 versions.

5.3
CVE-2026-65505

Unauthenticated Sensitive Data Exposure in Ultimate Store Kit Elementor Addons <= 3.0.5 versions.

5.3
CVE-2026-65506

Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.

5.3
CVE-2026-65521

Unauthenticated Sensitive Data Exposure in WP Social Ninja <= 4.3.0 versions.

5.3
CVE-2026-65525

Unauthenticated Broken Access Control in Civi Framework <= 2.2.0 versions.

5.3
CVE-2026-65529

Unauthenticated Broken Access Control in Graphina <= 3.1.12 versions.

5.3
CVE-2026-16733

A weakness has been identified in bahmutov find-cypress-specs up to 1.54.12. The impacted element is the function shell.

5.3
CVE-2026-16735

A security vulnerability has been detected in release-it conventional-changelog up to 11.0.1. This affects the function

5.3
CVE-2026-16768

A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO file with pixel values that exceed the defined pale

5.3
CVE-2026-65698

Void through 1.3.4 contains a path traversal vulnerability in the AI agent file-reading tools that allows network-adjace

5.3
CVE-2026-47769

APIFold reads an OpenAPI 3.x or Swagger 2.x specification and generates a live, production-ready MCP server endpoint. Pr

5.3
CVE-2026-12353

An unauthenticated attacker could trigger an Out of Memory condition to crash the Java process for RHCS by repeatedly se

5.3
CVE-2026-64785

SwiftNIO HTTP/2 was missing validation on inbound HEADERS frames that let CR, LF, NUL, SP and other control characters r

5.3
CVE-2026-16763

A vulnerability was identified in localstack serverless-localstack up to 1.4.0. The affected element is an unknown funct

5.3
CVE-2026-44955

Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sensitive system information to an unauthorized contr

5.3
CVE-2026-11354

The Participants Database plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, an

5.3
CVE-2026-13464

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Insecure Direct Ob

5.3
CVE-2026-12654

The Payment Plugins for Stripe WooCommerce plugin for WordPress is vulnerable to authorization bypass in all versions up

5.3
CVE-2026-46452

Improper Input Validation vulnerability in Apache NimBLE in Mesh Proxy SAR reassembly could result in passing broken dat

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started