Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 917/1152
5.3
CVE-2026-75099

Unauthenticated REST disclosure of certain content items in Apache Allura. This issue affects Apache Allura: through

5.3
CVE-2026-13213

The Hearing Access Service (HAS) GATT server in subsys/bluetooth/audio/has.c installs a connection-callback set uncondit

5.3
CVE-2026-77310

jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. Prio

5.3
CVE-2026-78430

A vulnerability was detected in sworddut mcp-ffmpeg-helper 0.1.0/0.1.1/0.2.1. This affects the function handleToolCall o

5.3
CVE-2026-16782

A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A m

5.3
CVE-2026-56708

Grav API plugin before 1.0.16 contains a server-side request forgery vulnerability in webhook delivery that allows attac

5.3
CVE-2026-72699

The Grav Login plugin (getgrav/grav-plugin-login) before 3.9.1 is vulnerable to email address enumeration. The register(

5.3
CVE-2026-75575

Rocket.Chat exposes the sendForgotPasswordEmail Meteor method without a DDP rate limit, so an unauthenticated caller may

5.3
CVE-2026-10627

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to authorization bypass i

5.3
CVE-2026-17587

The My Agile Privacy® – CMP, Cookie Consent & Privacy Tools plugin for WordPress is vulnerable to authorization bypass i

5.3
CVE-2026-78684

vLLM before 0.27.0 fails to properly classify DeepStream as a GPU backend and omits pixel-limit enforcement in its decod

5.3
CVE-2026-79660

Ech0 versions before 4.7.3 expose guest commenter email addresses through public API endpoints due to improper JSON seri

5.3
CVE-2026-79668

Ech0 before 4.7.3 contains an authentication bypass vulnerability in the PUT /api/echo/like/:id endpoint that allows una

5.3
CVE-2026-79771

Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Stylesheet transform method when processing Ruby strin

5.3
CVE-2026-79772

Nokogiri versions before 1.19.1 fail to check the return value from xmlC14NExecute in the canonicalize method, returning

5.3
CVE-2026-79776

rclone before 1.75.0 mounts the pprof debug handler as its own router route, bypassing the fail-closed authentication ru

5.3
CVE-2026-79778

rclone before v1.75.0 contains a denial of service vulnerability in the WebDAV TUS creation handler that dereferences a

5.3
CVE-2026-79779

rclone versions before v1.75.0 fail to reject transport downgrades in redirect handling, allowing Basic authorization an

5.3
CVE-2026-79780

rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE-C encryption keys during S3 redirect callbacks, al

5.3
CVE-2026-55419

Reachy Mini is an SDK for controlling Reachy Mini robots. Prior to 1.8.2, the Reachy Mini daemon exposes the /api/media/

5.3
CVE-2026-55619

eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well

5.3
CVE-2026-77585

The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result

5.3
CVE-2026-77680

An algorithmic complexity flaw exists in libsoup's HTTP Range header processing that persists after the CVE-2025-32907 f

5.3
CVE-2026-78991

Race condition in WebProtect in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the r

5.3
CVE-2026-79001

Information leak in Bluetooth in Google Chrome on on Mac prior to 152.0.7977.65 allowed a remote attacker who had compro

5.3
CVE-2026-79028

Observable discrepancy in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive

5.3
CVE-2026-79030

Observable discrepancy in Autofill in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive

5.3
CVE-2026-79044

Missing authorization in WebAppInstalls in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker

5.3
CVE-2026-79074

Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re

5.3
CVE-2026-79089

Race condition in Transactions Platform in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker

5.3
CVE-2026-79104

Missing authorization in Sensor in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised th

5.3
CVE-2026-79147

Information leak in Skia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the rende

5.3
CVE-2026-79181

Observable discrepancy in Glic in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inf

5.3
CVE-2026-79196

Race condition in Editing in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineerin

5.3
CVE-2026-79220

Information leak in Network in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised the re

5.3
CVE-2026-79242

Observable discrepancy in HTML in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inf

5.3
CVE-2026-79265

Incomplete cleanup in GetUserMedia in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromised

5.3
CVE-2026-79287

Observable discrepancy in Forms in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive in

5.3
CVE-2026-73335

Android application "Myna Point" is vulnerable to Improper Authorization in Handler for Custom URL Scheme (CWE-939). A m

5.3
CVE-2026-13172

The Eventin WordPress plugin before 4.1.22 does not restrict access to non-published content by status or ownership in

5.3
CVE-2026-13404

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or ownership check (rel

5.3
CVE-2026-13406

The Royal Addons for Elementor WordPress plugin before 1.7.1066 does not perform any capability or nonce check before r

5.3
CVE-2026-14550

The WPCafe WordPress plugin before 3.0.18 does not perform an authorization check when creating a reservation through i

5.3
CVE-2026-16986

The Booking Package WordPress plugin before 1.7.25 does not validate the payment amount server-side against the stored s

5.3
CVE-2026-19094

The Tutor LMS WordPress plugin before 4.0.6 does not validate values used to build a database query, and does not restr

5.3
CVE-2026-75798

The AI Engine WordPress plugin before 3.7.2 does not perform an authorisation check on one of its administration-only f

5.3
CVE-2026-77694

The Eventin WordPress plugin before 4.1.19 does not properly restrict which changes a guest checkout token is allowed t

5.3
CVE-2026-77754

The Kirki WordPress plugin before 6.0.14 does not perform a capability check on some endpoints of one of its public AJA

5.3
CVE-2026-77758

The Stripe Payment Forms by WP Full Pay WordPress plugin before 8.5.1 does not properly verify that a customer portal s

5.3
CVE-2026-80234

CAYIN CMS-WS and CMS-SE developed by CAYIN Technology have a Missing Authentication vulnerability. Unauthenticated remot

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started