Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 910/1152
5.3
CVE-2026-16536

The Simple Google Calendar Outlook Events Widget WordPress plugin before 3.1.0 does not validate a user-supplied URL bef

5.3
CVE-2026-14202

Observable response discrepancy vulnerability in Bilin Software and Informatics Consultancy Inc. HUMANIST Digital Human

5.3
CVE-2026-15337

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. `django.utils.translation.check_for_language()

5.3
CVE-2026-15830

An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0.8. GeoDjango's `django.contrib.gis.geos.GEOSGeome

5.3
CVE-2026-18784

A vulnerability was found in o6 open62541 up to 1.5.5. This issue affects the function UA_Client_readNodeClassAttribute

5.3
CVE-2026-18785

A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4acd07c1ff07ce242b. Impacted is the function UA_Cli

5.3
CVE-2026-47622

NVIDIA Dynamo for Linux contains a vulnerability where an attacker could cause the generation of error messages that con

5.3
CVE-2026-70487

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline di

5.3
CVE-2026-18853

A security vulnerability has been detected in ZomboDroid Meme Generator App 4.6830 on Android. This issue affects the fu

5.3
CVE-2026-45705

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the fin

5.3
CVE-2026-16981

The DHL Shipping Germany for WooCommerce WordPress plugin before 4.0.1 does not perform any authorization check (no capa

5.3
CVE-2026-55998

The endpoint /v3/import/{token}_{clusterId}.yaml retrieves the cluster object before validating the token. When a valid

5.3
CVE-2026-71203

changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-ke

5.3
CVE-2026-71210

Mealie's AsyncSafeTransport SSRF guard (mealie/pkgs/safehttp/transport.py) resolves a target hostname once, checks the r

5.3
CVE-2026-12762

IBM Cloud Pak For Business Automation 24.0.0, 24.0.1, 25.0.0, and 26.0.0 could allow a remote attacker to obtain sensiti

5.3
CVE-2026-18531

IBM Maximo Application Suite 9.2, 9.1, and 9.0 could allow a remote attacker to tamper with session data due to the use

5.3
CVE-2026-70607

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,

5.3
CVE-2026-18974

A vulnerability was found in heshengtao super-agent-party up to 0.4.1. This affects the function get_file_content of the

5.3
CVE-2026-14240

The tourmaster WordPress plugin before 5.4.9 writes its order/booking export to a fixed, predictable file inside its pub

5.3
CVE-2026-14313

PeproDev WooCommerce Receipt Uploader (PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 slug: pepro-

5.3
CVE-2026-14314

The PeproDev WooCommerce Receipt Uploader WordPress plugin through 2.8.0 does not verify that a requested attachment bel

5.3
CVE-2026-14547

The Estatik Real Estate Plugin WordPress plugin before 4.3.3 does not properly enforce its anti-spam check or restrict t

5.3
CVE-2026-16290

The ProfileGrid WordPress plugin before 6.0.0.0 does not perform authorization checks before returning a group's member

5.3
CVE-2026-19011

A vulnerability was detected in TinyAGI 0.0.20. The affected element is the function buildSystemPrompt of the file packa

5.3
CVE-2026-11983

The Ad Inserter – Ad Manager & AdSense Ads plugin for WordPress is vulnerable to authorization bypass in all versions up

5.3
CVE-2026-0673

The Element Pack Addons for Elementor plugin for WordPress is vulnerable to Email Header Injection in all versions up to

5.3
CVE-2026-19039

A vulnerability was detected in Kino-Kafkaesque ssh-mcp-server up to 8ebbbb99b26f80ff6162fe00957c6dec73fbc5a5. Impacted

5.3
CVE-2026-19044

A flaw has been found in LeeSinLiang godot-mcp 0.1.0. Affected by this vulnerability is the function executeOperation of

5.3
CVE-2026-19045

A weakness has been identified in NocteDefensor LudusMCP up to 1.0.24. The affected element is the function SecretDialog

5.3
CVE-2026-28169

Unauthenticated Sensitive Data Exposure in YITH WooCommerce Zoom Magnifier <= 2.52.0 versions.

5.3
CVE-2026-28180

Unauthenticated Insecure Direct Object References (IDOR) in Mercado Pago payments for WooCommerce <= 8.9.0 versions.

5.3
CVE-2026-32469

Unauthenticated Bypass Vulnerability in CAPTCHA 4WP <= 7.6.0 versions.

5.3
CVE-2026-32548

Unauthenticated Broken Access Control in SureCart <= 4.6.2 versions.

5.3
CVE-2026-65502

Unauthenticated Bypass Vulnerability in Element Pack Elementor Addons <= 8.7.13 versions.

5.3
CVE-2026-66683

Unauthenticated Sensitive Data Exposure in Custom CSS and JavaScript <= 2.0.16 versions.

5.3
CVE-2026-66684

Unauthenticated Sensitive Data Exposure in Export Import Menus <= 1.9.2 versions.

5.3
CVE-2026-66685

Unauthenticated Sensitive Data Exposure in Featured Video Plus <= 2.3.3 versions.

5.3
CVE-2026-66699

Custom role Broken Access Control in Dokan <= 5.0.10 versions.

5.3
CVE-2026-66701

Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.

5.3
CVE-2026-19047

A vulnerability was detected in NocteDefensor LudusMCP up to 1.0.24. This affects the function executeArbitraryCommand/e

5.3
CVE-2026-12501

The WP Travel Engine WordPress plugin before 6.8.2 does not verify that an incoming PayPal payment notification was sent

5.3
CVE-2026-13342

The Security Optimizer WordPress plugin from 1.5.8 to 1.6.4 does not correctly validate requests to its optional IP-base

5.3
CVE-2026-14831

The Easy Booking WordPress plugin before 3.5.0 does not re-enforce a bookable product's configured minimum booking durat

5.3
CVE-2026-14842

The Events Made Easy WordPress plugin before 3.1.2 does not bind the payment authorization token to the payment record b

5.3
CVE-2026-14936

The Simple Membership WordPress plugin before 4.7.7 does not verify that a PayPal payment notification was sent to the s

5.3
CVE-2026-15147

The Five Star Restaurant Reservations WordPress plugin before 2.7.23 does not verify the authenticity of incoming paymen

5.3
CVE-2026-15149

The WP Hotel Booking WordPress plugin before 2.3.3 does not ensure that room quantities and the resulting order total ar

5.3
CVE-2026-15152

The WP Hotel Booking WordPress plugin before 2.3.2 does not verify that a payment notification corresponds to a payment

5.3
CVE-2026-15208

The RegistrationMagic WordPress plugin before 6.0.9.5 does not compare the verified PayPal capture's amount, currency, p

5.3
CVE-2026-16067

The Event Booking Manager for WooCommerce (Pro) WordPress plugin before 5.0.3 does not validate the ticket price on the

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started