Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 93/454
8.5
CVE-2026-49120

Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authen

8.5
CVE-2026-47201

authentik is an open-source identity provider. Prior to versions 2025.12.5, 2026.2.3, and 2026.5.1, authentik's SAML Sou

8.5
CVE-2026-45549

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ag

8.5
CVE-2026-49824

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic

8.5
CVE-2026-50570

Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applic

8.5
CVE-2026-54420 KEV

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provide

8.5
CVE-2026-24637

Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions.

8.5
CVE-2026-40766

Subscriber SQL Injection in MasterStudy LMS <= 3.7.25 versions.

8.5
CVE-2026-48874

Subscriber SQL Injection in GamiPress <= 7.8.7 versions.

8.5
CVE-2026-48882

Subscriber SQL Injection in WP Time Slots Booking Form <= 1.2.50 versions.

8.5
CVE-2026-48964

Subscriber SQL Injection in ELEX WordPress HelpDesk & Customer Ticketing System <= 3.3.6 versions.

8.5
CVE-2026-52697

Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.

8.5
CVE-2026-52700

Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.

8.5
CVE-2026-39581

Subscriber SQL Injection in WP Sessions Time Monitoring Full Automatic <= 1.1.4 versions.

8.5
CVE-2026-46870

Vulnerability in the MySQL Shell product of Oracle MySQL (component: Shell for VS Code). The supported version that is

8.5
CVE-2026-46915

Vulnerability in the Oracle Complex Maintenance, Repair and Overhaul product of Oracle E-Business Suite (component: Prod

8.5
CVE-2025-69135

Subscriber SQL Injection in Events Schedule - WordPress Events Calendar Plugin <= 2.7.2 versions.

8.5
CVE-2026-22335

Subscriber SQL Injection in WooCommerce Frontend Manager – Ultimate < 6.7.7 versions.

8.5
CVE-2026-48967

Subscriber SQL Injection in Geo Mashup <= 1.13.19 versions.

8.5
CVE-2026-49073

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist

8.5
CVE-2026-49113

Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.

8.5
CVE-2026-54185

Subscriber SQL Injection in Cornerstone < 7.8.8 versions.

8.5
CVE-2026-54813

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Brainstorm Force S

8.5
CVE-2026-54818

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in VeronaLabs Slimsta

8.5
CVE-2026-56012

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in David Lingren Medi

8.5
CVE-2026-54312

n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or

8.5
CVE-2026-49444

n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with pe

8.5
CVE-2026-54008

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backe

8.5
CVE-2026-45687

Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.0, 8.4.1, 8.3.3, 8.2.3,

8.5
CVE-2026-52797

Gogs is an open source self-hosted Git service. Prior to 0.14.0, as an authorized user, an intruder can dictate the valu

8.5
CVE-2026-54822

Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.

8.5
CVE-2026-54838

Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.

8.5
CVE-2026-56049

Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.

8.5
CVE-2026-56769

Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerabili

8.5
CVE-2026-56771

NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows

8.5
CVE-2026-12975

A flaw was found in Apicurio Registry. The ContentTypeUtil.isParsableXml() method creates a SAXParserFactory without ena

8.5
CVE-2026-56064

Subscriber SQL Injection in Tourfic <= 2.22.5 versions.

8.5
CVE-2026-57315

Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.45 versions.

8.5
CVE-2026-57636

Contributor SQL Injection in wpForo Forum <= 3.0.9 versions.

8.5
CVE-2026-57642

Contributor SQL Injection in Gallery <= 4.7.8 versions.

8.5
CVE-2026-57643

Contributor SQL Injection in WP Post Author <= 3.9.1 versions.

8.5
CVE-2026-57644

Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.

8.5
CVE-2026-57653

Contributor SQL Injection in WP Job Portal <= 2.5.2 versions.

8.5
CVE-2026-57662

Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.

8.5
CVE-2026-57663

Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.

8.5
CVE-2026-57667

Sales Representative SQL Injection in Groundhogg <= 4.5 versions.

8.5
CVE-2026-56663

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agent

8.5
CVE-2026-54353

Budibase is an open-source low-code platform. Prior to 3.39.9, authenticated users with automation permissions can bypas

8.5
CVE-2026-57947

Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that al

8.5
CVE-2026-57955

SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary C

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started