Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 916/1152
5.3
CVE-2026-76390

In Cisco Talos Intelligence for Enterprise Security Cloud versions below 1.0.3, an unauthenticated user could access the

5.3
CVE-2026-76919

ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

5.3
CVE-2022-4996

A flaw has been found in mruby 3.1.0. Affected is the function udiv of the file bigint.c. Executing a manipulation can l

5.3
CVE-2026-76799

A weakness has been identified in code-projects Login Registration System 1.0. This affects an unknown function of the f

5.3
CVE-2026-17153

The AI Agent by SiteGround plugin for WordPress is vulnerable to authorization bypass in all versions up to, and includi

5.3
CVE-2026-77014

A flaw was found in libsoup's SoupServer HTTP Range header processing. The sort_ranges() comparator in soup-message-head

5.3
CVE-2026-28163

Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control S

5.3
CVE-2026-76988

A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This affects the function

5.3
CVE-2026-76989

A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This impacts

5.3
CVE-2026-63016

Uncontrolled Resource Consumption vulnerability in Apache InLong. Users could affect operational configuration or allow

5.3
CVE-2026-43678

An unauthenticated remote peer can crash any NIOWebSocket-based server (including Vapor and Hummingbird) with a single 1

5.3
CVE-2026-53585

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing

5.3
CVE-2026-72854

msgpack_unpacker_expand_buffer in src/unpack.c, reached through the public msgpack_unpacker_reserve_buffer API, computes

5.3
CVE-2026-67445

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit reads SMTP commands through internal/s

5.3
CVE-2026-67446

Mailpit is an email testing tool and API for developers. Prior to 1.30.4, Mailpit decodes attacker-supplied image attach

5.3
CVE-2026-77639

Tor before 0.4.9.9 was prone to a compression bomb bypass where an attacker could concatenate many gzip or zlib sub-stre

5.3
CVE-2026-17120

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a buffer

5.3
CVE-2026-67447

Mailpit is an email testing tool and API for developers. From 1.30.0 until 1.30.5, Mailpit's internal/smtpd/smtpd.go rea

5.3
CVE-2026-76131

Use of hard-coded credentials issue exists in VOCALOID6 , which may allow an attacker to impersonate a legitimate VOCALO

5.3
CVE-2026-13736

The NewPath WildApricotPress Add-on WordPress plugin through 1.0.0 does not enforce its members-only field privacy on a

5.3
CVE-2026-16575

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution WordPress plugin before 5.0.14 does not restrict acc

5.3
CVE-2026-16962

The Tamara Checkout WordPress plugin through 1.9.9.20 does not verify the order key, a nonce, or any capability on its p

5.3
CVE-2026-19441

Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data.

5.3
CVE-2026-59323

An application using Micrometer Tracing with W3C baggage propagation in the Brave bridge is vulnerable to denial of serv

5.3
CVE-2026-15150

The myCred WordPress plugin before 3.2.5 does not verify that the receiver of an incoming payment gateway notification m

5.3
CVE-2026-16650

The Charitable WordPress plugin before 1.8.12 does not verify the authenticity of incoming Square payment webhook events

5.3
CVE-2026-17559

The Passster WordPress plugin before 4.3.9 does not correctly match its own public endpoint paths when deciding which RE

5.3
CVE-2026-75928

The Brushfire platform's video content streaming application (https://online.brushfire.com) exposes database path in req

5.3
CVE-2026-27463

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, the HTML title attribute of the logo in the logi

5.3
CVE-2026-69228

There is a missing authentication vulnerability in Esri Portal for ArcGIS versions 12.0 and prior that may allow a remot

5.3
CVE-2026-53497

CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21, GET /api/app-auth/status is accessible without aut

5.3
CVE-2026-75027

The Themify Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 7.8

5.3
CVE-2026-16612

The FiboSearch WordPress plugin before 1.34.1 does not consistently exclude password-protected products from its unauth

5.3
CVE-2026-16738

The Conekta Payment Gateway WordPress plugin before 6.2.2 does not verify the authenticity of incoming payment gateway w

5.3
CVE-2026-3424

The The kk Star Ratings – Rate Post & Collect User Feedbacks plugin for WordPress is vulnerable to arbitrary shortcode e

5.3
CVE-2026-56380

AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthentica

5.3
CVE-2026-63311

NLTK before 3.10.0 (affected versions <= 3.9.4) contains a server-side request forgery (SSRF) vulnerability in the valid

5.3
CVE-2026-12999

The Infineon Airoc Wi-Fi driver's transmit callback airoc_mgmt_send() in drivers/wifi/infineon/airoc_wifi.c allocates a

5.3
CVE-2026-78051

A vulnerability was determined in alexta69 MeTube up to 2026.06.10. The impacted element is an unknown function of the f

5.3
CVE-2026-75922

Reverse::Proxy versions before 0.04 for Perl allow HTTP request smuggling via a percent-decoded PATH_INFO written unenco

5.3
CVE-2026-78148

A vulnerability was determined in ggml-org llama.cpp bec4772f6. This affects the function rpc_server::graph_compute of t

5.3
CVE-2026-19853

NewSiteServer (NSS) developed by CyberTutor has a Missing Authentication vulnerability. Unauthenticated remote attackers

5.3
CVE-2026-8173

The web GUI of affected Murrelektronik Xelity switches logs MAC addresses from the devices MAC address table when an aut

5.3
CVE-2026-78258

Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.5 versions.

5.3
CVE-2026-78278

Subscriber Insecure Direct Object References (IDOR) in Fluent Boards Pro <= 2.0.11 versions.

5.3
CVE-2026-78291

Unauthenticated Broken Access Control in RepairBuddy <= 4.1223 versions.

5.3
CVE-2025-68833

HCL Hive Keycloak IAM Instance is affected by insufficient granularity of access control which could allow an attacker u

5.3
CVE-2026-21755

HCL Hive is affected by a missing rate limit which could allow an attacker unauthorized access via brute-force or creden

5.3
CVE-2026-13343

The UMP Stream responder library in lib/midi2/ump_stream_responder.c builds reply packets in a 16-byte struct midi_ump (

5.3
CVE-2026-63621

Improper Input Validation, Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Inject

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started