Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 92/436
6.5
CVE-2026-76217

GitPython versions before 3.1.58 fail to validate options passed to git rm and git checkout commands in IndexFile.remove

6.5
CVE-2026-50149

Contour is a Kubernetes ingress controller using Envoy proxy. In versions 1.23.0 through 1.33.4, when an `HTTPProxy` is

6.5
CVE-2026-67268

Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vul

6.5
CVE-2026-61690

Grav is a file-based Web platform. Prior to 2.0.1, Grav ZipArchiver::extract() in system/src/Grav/Common/Filesystem/ZipA

6.5
CVE-2026-61842

Grav is a file-based Web platform. Prior to 2.0.2, the Grav Twig content sandbox permits grav.offsetGet('config') to ret

6.5
CVE-2026-20327

A vulnerability in the web-based management interface of Cisco Unified Intelligence Center could allow an authenticated,

6.5
CVE-2026-19653

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to improper

6.5
CVE-2026-63117

FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.28.0, an authenticated RDP client can advert

6.5
CVE-2026-49976

Snipe-IT is an IT asset/license management system. Prior to 8.6.1, a user with the import permission can use CSV update

6.5
CVE-2026-16846

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to a null p

6.5
CVE-2026-17028

IBM PowerVM Hypervisor FW1120.00, FW1110.00 through FW1110.30, FW1060.00 through FW1060.80, and FW950.00 through FW950.H

6.5
CVE-2026-19509

Improper input validation in `ajaxSet_wireless_network_configuration.jst` in RDK-B WebUI `rdkb-2025q4-kirkstone.04.10.26

6.5
CVE-2026-68559

Wekan is open source kanban built with Meteor. From 9.57 until 9.74, the /api/boards/:boardId/exportExcel route in model

6.5
CVE-2026-68901

Wekan is open source kanban built with Meteor. Prior to 10.38, the /api/boards/:boardId/export, /api/boards/:boardId/att

6.5
CVE-2026-14514

IBM Reliable Scalable Cluster Technology (RSCT) 3.0 could allow a remote attacker to cause a denial of service by sendin

6.5
CVE-2026-54738

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-beta.1, actix-web ConnectionInfo::rea

6.5
CVE-2026-54740

Lemmy is a link aggregator and forum for the fediverse. Prior to 0.19.19 and 1.0.0-alpha.18, a lower-ranked remote moder

6.5
CVE-2026-68555

Coturn is a free open source implementation of TURN and STUN Server. In 4.15.0, an authenticated TURN user can repeatedl

6.5
CVE-2026-63123

Tina is a headless content management system. Prior to 2.5.2, the TinaCMS CLI package's Vite dev server packages/@tinacm

6.5
CVE-2026-69550

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

6.5
CVE-2026-76257

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10

6.5
CVE-2026-76258

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, and Splunk Secure Gateway versions below 3.10.10

6.5
CVE-2026-76260

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user that holds a role with the rest_propertie

6.5
CVE-2026-76343

In Splunk Enterprise versions below 10.4.2, 10.2.6, 10.0.9, and 9.4.14, a user who does not hold the "admin" or "power"

6.5
CVE-2026-76358

In Splunk SOAR versions below 8.6.0, a user with app-install privileges could use path traversal during app installation

6.5
CVE-2026-76359

In Splunk SOAR versions below 8.6.0, a user who holds the Administrator role could use path traversal in the Universal F

6.5
CVE-2026-76363

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" role could run arbitrary Structured Quer

6.5
CVE-2026-76364

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Str

6.5
CVE-2026-76365

In Splunk SOAR versions below 8.6.0, a user who holds the "Automation Engineer" Splunk SOAR role could run arbitrary Str

6.5
CVE-2026-76366

In Splunk SOAR versions below 8.6.0, a user with a valid Splunk SOAR account could use Representational State Transfer (

6.5
CVE-2026-14949

A low privileged remote attacker with a valid session can submit a request to the user creation functionality exposed th

6.5
CVE-2026-73199

A flaw was found in the `ipa-enrollment` SLAPI plugin. A remote authenticated client can exploit a null pointer derefere

6.5
CVE-2025-53999

Unauthenticated Broken Access Control in Altair <= 5.2.2 versions.

6.5
CVE-2026-66601

Subscriber Cross Site Scripting (XSS) in Media LIbrary Assistant <= 3.39 versions.

6.5
CVE-2026-66647

Subscriber Broken Access Control in Homlisti <= 3.1.2 versions.

6.5
CVE-2026-73402

Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.

6.5
CVE-2026-76634

WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows a

6.5
CVE-2026-73255

Mongoose is an embedded web server and network library. Prior to 7.22, an attacker who can control an SSI-enabled file c

6.5
CVE-2026-73258

Mongoose is an embedded web server and network library. Prior to 7.22, a remote attacker can place a lone carriage retur

6.5
CVE-2026-53583

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing

6.5
CVE-2026-53586

libgit2 is a portable C implementation of the Git core methods provided as a linkable library with a solid API, allowing

6.5
CVE-2026-54622

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0

6.5
CVE-2026-54624

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0

6.5
CVE-2026-63003

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. Prior to 5.0

6.5
CVE-2026-75910

Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to

6.5
CVE-2026-77641

tor before 0.4.9.9 was prone to a NULL write after free when sending a CONFLUX_SWITCH cell fails. The return value of re

6.5
CVE-2026-16958

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-o

6.5
CVE-2026-16964

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to intercept messages and forge replies due

6.5
CVE-2026-16972

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to obtain sensitive information due to impro

6.5
CVE-2026-17195

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started