Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 909/1152
5.3
CVE-2026-14305

The WP Delicious WordPress plugin before 1.10.2 does not perform an authorization check on one of its AJAX actions, all

5.3
CVE-2026-15250

The Appointment Booking Plugin WordPress plugin before 5.6.8 does not restrict which booking fields an unauthenticated

5.3
CVE-2026-15255

The RegistrationMagic WordPress plugin before 6.0.9.4 does not properly validate that a one-time password presented in

5.3
CVE-2026-15257

The RegistrationMagic WordPress plugin before 6.0.9.4 does not perform authorization, ownership or nonce checks on a fr

5.3
CVE-2026-16531

An unauthenticated remote attacker can exploit a path traversal vulnerability in the PCP pmproxy logger servlet using a

5.3
CVE-2026-64635

Improper handling of the returnUrl parameter in the Forgot Password function of Veeam Service Provider Console allows an

5.3
CVE-2026-44102

An unauthenticated remote attacker can trigger a firmware update download via the OCPP backend by supplying an invalid f

5.3
CVE-2026-44103

An unauthenticated remote attacker can inject malicious firmware into the internal charging module because the JupiCore

5.3
CVE-2026-58218

A flaw was found in Samba's internal DNS server where unauthenticated TKEY registration requests were added to the TKEY

5.3
CVE-2026-58216

An out-of-bounds read flaw was found in Samba's Kerberos Key Distribution Center's (KDC) password change (kpasswd) servi

5.3
CVE-2026-11904

IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident

5.3
CVE-2026-43833

Full details and mitigation steps are currently restricted and will be published at a later date.

5.3
CVE-2026-14317

The GiveWP WordPress plugin before 4.16.3 does not restrict the set of available payment gateways to those enabled by t

5.3
CVE-2026-14843

The Events Made Easy WordPress plugin before 3.1.4 does not verify that the requester is authorized to modify the target

5.3
CVE-2026-65311

The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions exposes an undocumented endpoi

5.3
CVE-2026-18436

The MailPress plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 1.5.0 via the

5.3
CVE-2026-18437

The MailerPress – Newsletter, email marketing & AI automation plugin for WordPress is vulnerable to unauthorized access

5.3
CVE-2026-17567

The Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder plugin for WordPress is vulne

5.3
CVE-2026-64607

HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection ma

5.3
CVE-2026-28145

Insufficient Verification of Data Authenticity vulnerability in StylemixThemes MasterStudy LMS allows Manipulating User

5.3
CVE-2026-54909

pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAddress.GetFromAs can panic while parsing a malformed

5.3
CVE-2026-12966

The Direct Payments for WooCommerce WordPress plugin before 2.5.3 does not verify that the requester owns the targeted

5.3
CVE-2026-13604

The Pixelavo WordPress plugin before 1.5.4 registers an unauthenticated AJAX action, gated only by a nonce that it emit

5.3
CVE-2026-14822

The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any authorization check on one of i

5.3
CVE-2026-14840

The YOP Poll WordPress plugin before 7.0.6 does not validate the connection's origin IP address and instead trusts clien

5.3
CVE-2026-15932

The Support Genix WordPress plugin before 1.4.48 does not prevent directory traversal in its ticket-attachment download

5.3
CVE-2025-14073

The WooCommerce PayPal Payments plugin for WordPress is vulnerable to Sensitive Information Disclosure due to an Insecur

5.3
CVE-2026-11995

The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Builder plugin for WordPress

5.3
CVE-2026-15018

The Database Collation Fix plugin for WordPress is vulnerable to time-based SQL Injection via the 'force-collation-algor

5.3
CVE-2026-18059

The PixelYourSite – Your smart PIXEL (TAG) & API Manager plugin for WordPress is vulnerable to Sensitive Information Exp

5.3
CVE-2026-67335

better-auth versions before 1.6.2 fail to validate the OAuth state parameter against the stored nonce when using cookie-

5.3
CVE-2026-67339

guzzlehttp/guzzle versions before 7.14.2 fail to properly isolate Proxy-Authorization headers from origin servers in cUR

5.3
CVE-2026-67353

guzzlehttp/guzzle versions before 7.15.1 contain a denial of service vulnerability in the CookieJar that accepts unlimit

5.3
CVE-2026-59640

In Bouncy Castle for Java before 1.85, OpenPGP CFB quick-check oracle active on symmetric/session-key paths. This issue

5.3
CVE-2026-59641

In Bouncy Castle for Java before 1.85, S/MIME validator trusts signer-asserted signingTime for path validation. This iss

5.3
CVE-2026-59647

In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours unbounded iteration count. This issue also affects

5.3
CVE-2026-59648

In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours attacker-chosen memory and passes. This issue also aff

5.3
CVE-2026-18582

A security flaw has been discovered in mz-automation libiec61850 up to 1.6.1. This vulnerability affects the function Re

5.3
CVE-2026-12860

In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips last two hash bytes in NULL-omitted path. This issu

5.3
CVE-2026-18583

A weakness has been identified in mz-automation libiec61850 up to 1.6.1. This issue affects the function checkDataSetAcc

5.3
CVE-2026-12259

In nltk version 3.9.4, the `nltk.downloader.Downloader._download_package()` function writes downloaded package bytes to

5.3
CVE-2026-60011

Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly authorize requests to directly access certain image

5.3
CVE-2026-62416

Network Scanner Tool and Network Scanner Tool Lite provided by Sharp Corporation, with the initial configuration, requir

5.3
CVE-2026-18604

A vulnerability was identified in textPlus Text Message and Call App up to 8.3.5 on Android. This impacts the function D

5.3
CVE-2026-18610

A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.asp

5.3
CVE-2026-69153

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract

5.3
CVE-2026-18646

A weakness has been identified in danpros HTMLy up to 3.1.1. This vulnerability affects unknown code of the file /system

5.3
CVE-2026-18648

A vulnerability was detected in Blix Email Blue Mail Calendar App 2.2.305. Impacted is the function FileDirectory.getDat

5.3
CVE-2026-58041

A flaw in Node.js node:sqlite allows a stale StatementSyncIterator created through DatabaseSync#createTagStore() to cont

5.3
CVE-2026-18720

A flaw has been found in kalcaddle kodbox 1.67 Build 02. This vulnerability affects unknown code of the file /index.php?

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started