Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 912/1152
5.3
CVE-2026-19335

A vulnerability has been found in Jane-xiaoer skill-vision-control up to 1.3.0. This vulnerability affects the function

5.3
CVE-2026-19336

A vulnerability was found in Pimzino spec-workflow-mcp up to 2.2.6. This issue affects the function ApprovalStorage.crea

5.3
CVE-2026-19337

A vulnerability was determined in adenot mcp-google-search up to 0.3.1. Impacted is an unknown function of the file src/

5.3
CVE-2026-19338

A vulnerability was identified in automateyournetwork MCPyATS up to 0.1.4. The affected element is the function processG

5.3
CVE-2026-19356

A vulnerability was identified in MingSoft MCMS up to 3.0.6. This impacts an unknown function of the file /mdiy/form/dat

5.3
CVE-2026-19357

A security flaw has been discovered in MingSoft MCMS up to 3.0.6. Affected is an unknown function of the file /mdiy/form

5.3
CVE-2026-19362

A vulnerability has been found in lmammino oidc-authorizer 0.4.0. This issue affects the function parse_token_from_heade

5.3
CVE-2026-19363

A vulnerability was found in lmammino oidc-authorizer up to 0.4.0. Impacted is an unknown function of the file src/handl

5.3
CVE-2026-19365

A vulnerability was identified in Ichigo3766 image-gen-mcp 0.1.0. The impacted element is an unknown function of the fil

5.3
CVE-2026-19366

A flaw has been found in NocteDefensor LudusMCP up to 1.0.24. Affected is an unknown function of the file src/tools/inse

5.3
CVE-2026-19369

A vulnerability was found in KS-GEN-AI jira-mcp-server 0.2.0. This affects the function axios.get of the file src/index.

5.3
CVE-2026-19370

A vulnerability was determined in bartekke8it56w2 new-mcp 0.1.0. This impacts the function fs.writeFileSync/fs.existsSyn

5.3
CVE-2026-19371

A vulnerability was identified in Nikolaibibo claude-comfyui-mcp 1.0.0. Affected is the function copyFileSync of the fil

5.3
CVE-2026-19372

A security flaw has been discovered in Handwriting-OCR handwriting-ocr-mcp-server 0.1.0. Affected by this vulnerability

5.3
CVE-2026-19373

A weakness has been identified in PhialsBasement KoboldCPP-MCP-Server 1.0.0. Affected by this issue is the function make

5.3
CVE-2026-14860

The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from

5.3
CVE-2026-15229

The Pinpoint Booking System WordPress plugin through 2.9.9.7.1 does not validate the booking price on the server side,

5.3
CVE-2026-15237

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a RES

5.3
CVE-2026-17012

The Accept PayPal & Stripe with Subscriptions for WooCommerce WordPress plugin through 3.1.0 does not verify that the Pa

5.3
CVE-2026-17021

The Salon Booking System WordPress plugin before 10.30.34 does not properly restrict access to some of its booking-modif

5.3
CVE-2026-19074

The Advanced Classifieds & Directory Pro Advanced Classifieds & Directory Pro WordPress plugin before 3.4.3 (<= 3.4.2) i

5.3
CVE-2026-66409

DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords for their Wi-Fi hotspot networks. The password ma

5.3
CVE-2026-66411

DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authentication algorithm in Websocket communications. An unaut

5.3
CVE-2026-72588

A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to d

5.3
CVE-2026-72721

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, Onebox::DomainChec

5.3
CVE-2026-72723

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, SiteSerializer.ano

5.3
CVE-2026-68870

The Azure Key Vault secrets backend in Apache Airflow's Microsoft Azure provider resolved a team-scoped Connection or Va

5.3
CVE-2026-40130

SAP SAPSPrint Service has memory corruption vulnerabilities in the handling of certain commands. An unauthenticated atta

5.3
CVE-2026-58247

SAP ABAP Platform allows an unauthenticated user to send a specially crafted request to an internal component. This coul

5.3
CVE-2026-66778

SAP Approuter does not sufficiently sanitize certain request headers before forwarding traffic to internal components. A

5.3
CVE-2026-8158

The Signed Video Framework contained a  buffer overflow issue which could lead the application using this framework to

5.3
CVE-2026-71218

A flaw was found in iperf3. A remote unauthenticated attacker can exploit a vulnerability in the `JSON_read()` function,

5.3
CVE-2026-72549

An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers

5.3
CVE-2026-14180

A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to han

5.3
CVE-2026-62757

Improper verification of cryptographic signature in Windows Schannel allows an unauthorized attacker to bypass a securit

5.3
CVE-2026-65777

Inadequate encryption strength in Windows Active Directory allows an authorized attacker to bypass a security feature ov

5.3
CVE-2026-20901

Improper input validation for some Intel(R) Xeon(R) processors within firmware may allow an escalation of privilege. Sta

5.3
CVE-2026-73228

Django REST framework is a toolkit for building Web APIs. Prior to 3.17.2, Django REST Framework's request.data parsing

5.3
CVE-2026-71468

A flaw was found in acm-search-v2-api-rhel9. When the `getFederationConfig` function refreshes its cache, it improperly

5.3
CVE-2026-73244

kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /li

5.3
CVE-2026-66340

The Mira cloud authentication endpoints do not enforce per-account rate limiting, per-IP throttling, or account lockout

5.3
CVE-2025-15684

A vulnerability was detected in Open5GS up to 2.7.6. Affected is the function diam_log_func of the file lib/diameter/com

5.3
CVE-2026-16737

The WP Travel Engine WordPress plugin before 6.8.5 does not perform authorization or ownership checks when loading a ca

5.3
CVE-2026-18035

The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allo

5.3
CVE-2026-19073

The Order Sync with Zendesk for WooCommerce WordPress plugin before 2.2.3 does not perform any capability check on one o

5.3
CVE-2026-15213

The Welcart e-Commerce WordPress plugin before 2.11.33 does not verify the authenticity of its convenience-store / bank-

5.3
CVE-2026-16621

The Payment Gateway for PayPal on WooCommerce WordPress plugin before 9.2.1 does not verify that payment actually succee

5.3
CVE-2026-16990

The Payment Button for PayPal WordPress plugin through 1.2.3.44 does not enforce the merchant-configured price server-si

5.3
CVE-2026-17008

The Quick Paypal Payments WordPress plugin through 5.7.50 does not verify the paid amount, receiver, or payment status i

5.3
CVE-2026-70466

A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started