Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 93/436
6.5
CVE-2026-19448

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory corruption vulnerability exists in the AIX IPsec ESP decaps

6.5
CVE-2026-54509

TREK is a collaborative travel planner. From 3.0.0 until 3.1.0, the GET /api/journeys/:id/share-link route in server/src

6.5
CVE-2026-67448

Mailpit is an email testing tool and API for developers. From 1.29.0 until 1.30.6, Mailpit's server/server.go origin mid

6.5
CVE-2026-70105

Improper input validation in Microsoft Office Word allows an unauthorized attacker to disclose information over a networ

6.5
CVE-2026-77763

The filestore backend in pkg/object/file.go, used for file:// stores and as a common juicefs sync destination, derived e

6.5
CVE-2026-77768

The report.get procedure in packages/trpc/src/routers/report.ts accepted only a reportId and returned getReportById(repo

6.5
CVE-2026-77769

The report.list procedure in packages/trpc/src/routers/report.ts accepted a projectId and a dashboardId and returned get

6.5
CVE-2026-19848

The ProfilePress WordPress plugin before 4.17.1 does not strip shortcodes from two of its profile fields before renderin

6.5
CVE-2026-59318

In Spring AI's tool calling support, the per-request tool list is advertised to the model as a boundary but is not fully

6.5
CVE-2026-50278

iccDEV provides a set of libraries and tools for working with ICC color management profiles. Versions prior to 2.3.2.1 h

6.5
CVE-2026-77237

Missing queue-set type validation in xQueueAddToSet() in the FreeRTOS-Kernel before 11.3.1 might allow an unprivileged t

6.5
CVE-2026-55168

Runtipi is a personal homeserver orchestrator. In 4.10.0 and earlier, Runtipi accepts symbolic links from an attacker-co

6.5
CVE-2026-77220

PDFio before 1.6.5 contains a dangling pointer vulnerability in the dictionary string-formatting function that stores a

6.5
CVE-2026-34836

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, improper access control in ajax.render.php and a

6.5
CVE-2026-34949

Combodo iTop is a web based IT service management tool.Prior to 3.2.3, an unauthenticated user could delete the .readonl

6.5
CVE-2026-53524

WeeChat (Wee Enhanced Environment for Chat) is a free chat client. In versions 4.3.0 through 4.9.0, the WeeChat relay mo

6.5
CVE-2026-58002

WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in th

6.5
CVE-2026-65915

NLTK versions before 3.10.0 contain a logic bug in FileSystemPathPointer.open() where the sandbox validation check compa

6.5
CVE-2026-18027

The WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels plugin for WordPress is vulnerab

6.5
CVE-2026-78290

Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.6 versions.

6.5
CVE-2026-78323

A flaw was found in JSS (Java Security Services). The JSSTrustManager class does not verify NSS trust flags when validat

6.5
CVE-2026-76845

adm-zip 0.5.9 through 0.6.0 follows symbolic links at the extraction destination. Utils.sanitize in util/utils.js enforc

6.5
CVE-2026-39914

TIM Flow before 26.0.6 contains an improper authorization vulnerability that allows any authenticated user to submit arb

6.5
CVE-2026-59230

Improper input validation vulnerability in Apache Camel. This issue affects Apache Camel: from 2.17.0 before 4.14.9,

6.5
CVE-2026-77914

rConfig Core 8.0.0 before 8.2.13 contains a path traversal vulnerability that allows authenticated users to read arbitra

6.5
CVE-2026-71507

Dolibarr before 24.0.0 contains a broken object-level authorization vulnerability in the REST API company bank account w

6.5
CVE-2026-71508

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the user REST API update endpoint that allows

6.5
CVE-2026-71509

Dolibarr before 24.0.0 contains an improper authorization vulnerability in the expense report REST API update endpoint t

6.5
CVE-2026-75370

An out-of-bounds read/write vulnerability in the MessageParser::parseECSSTCHeader component of SpaceDot AcubeSAT OBC sof

6.5
CVE-2026-71510

Dolibarr before 24.0.0 contains a SQL injection vulnerability in the users REST API that allows authenticated attackers

6.5
CVE-2026-71511

Dolibarr before 24.0.0 contains a sensitive data exposure vulnerability in the Members REST API that allows authenticate

6.5
CVE-2026-75509

joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standar

6.5
CVE-2026-27364

Subscriber Broken Access Control in Style Kits <= 2.6.5 versions.

6.5
CVE-2026-68516

OpenEXR is the reference implementation and specification for the EXR image format, widely used in the motion picture in

6.5
CVE-2026-78266

Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.

6.5
CVE-2026-78434

A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the function FormController::post_ticket_reply of the

6.5
CVE-2026-15023

The Events Manager – Calendar, Bookings, Tickets, and more! plugin for WordPress is vulnerable to generic SQL Injection

6.5
CVE-2026-72697

Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to vali

6.5
CVE-2026-72698

Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing

6.5
CVE-2026-76839

Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and

6.5
CVE-2026-78678

GitPython versions before 3.1.59 contain an incomplete denylist in the unsafe_git_revision_options guard that omits --co

6.5
CVE-2026-78679

GitPython before 3.1.59 contains an arbitrary file read vulnerability in TagReference.create() where a positional refere

6.5
CVE-2026-78470

The WP Project Manager Pro plugin for WordPress is vulnerable to SQL Injection in all versions up to, and including, 4.0

6.5
CVE-2026-78322

A flaw was found in file-roller. When opening or extracting a malicious 7z or RAR archive containing a file entry with a

6.5
CVE-2026-78701

A flaw was found in 389-ds-base. A remote, authenticated attacker could exploit a vulnerability in the Simple Authentica

6.5
CVE-2026-79661

Ech0 through 4.5.6 registers the PUT /api/echo/like/:id endpoint on the public router group without authentication or ra

6.5
CVE-2026-79666

Ech0 before 4.4.3 fails to enforce administrator authorization on dashboard log endpoints, allowing any authenticated us

6.5
CVE-2026-79673

Ech0 before 4.4.3 protects the PUT /user endpoint with the profile:read scope, a read-only scope, but allows write opera

6.5
CVE-2026-55531

PraisonAI is a multi-agent teams system. Prior to praisonai 4.6.58, the MCP HTTP Stream mcp_post handler creates a new _

6.5
CVE-2026-70550

An authorization weakness in JFrog Artifactory Composer repository handling may allow an authenticated user, under speci

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started