Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 932/1152
4.9
CVE-2026-51564

An issue in the redirect parameter in Milk admin <=0.9.8 allows remote attackers to redirect users to arbitrary external

4.9
CVE-2026-16811

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to time-bas

4.9
CVE-2026-15670

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera

4.9
CVE-2026-15671

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera

4.9
CVE-2026-15444

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to generic SQL Injection via the

4.9
CVE-2026-5114

The SpeedyCache plugin for WordPress is vulnerable to Arbitrary File Read via Path Traversal in all versions up to, and

4.9
CVE-2026-1918

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM

4.9
CVE-2026-15344

The WP Photo Album Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'table' parameter in all ver

4.9
CVE-2026-11973

The WP-Lister Lite for eBay plugin for WordPress is vulnerable to generic SQL Injection via the 'orderby' parameter in a

4.9
CVE-2026-58156

Apache Traffic Server mis-parses ports in URLs and userinfo, allowing port-based access-control bypass. This issue affe

4.9
CVE-2026-6089

The WP CTA plugin for WordPress is vulnerable to Server-Side Request Forgery via the 'sticky_s_media' parameter in impor

4.9
CVE-2026-14341

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.0.5, 19.1 before 19.1.3, and 1

4.9
CVE-2026-14227

An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Sessi

4.9
CVE-2026-16105

A flaw was found in the RoleContainerResource component of Keycloak. The issue occurs because certain name-based endpoin

4.9
CVE-2026-45330

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3

4.9
CVE-2026-15403

The Pinpoint Booking System – Version 2 plugin for WordPress is vulnerable to blind SQL Injection via the 'field' parame

4.9
CVE-2026-15601

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Path Traversal (Zi

4.9
CVE-2026-15951

The Icegram Mailer plugin for WordPress is vulnerable to SQL Injection via the 'fields' parameter in versions up to, and

4.9
CVE-2026-16614

The GSheetConnector – CF7 Google Sheets Connector with Real-Time Sync plugin for WordPress is vulnerable to generic SQL

4.9
CVE-2026-17555

The WPvivid Backup & Migration plugin for WordPress is vulnerable to SQL Injection via the export_data parameter in vers

4.9
CVE-2025-15673

The Import and export users and customers WordPress plugin before 2.4.3 does not restrict the path of a file it reads an

4.9
CVE-2026-69090

Admidio before 5.0.11 fails to validate target organization membership in role handlers, allowing authenticated role adm

4.9
CVE-2026-18103

A flaw was found in dhcp-server. A remote attacker with network access to the OMAPI (Open Management Application Program

4.9
CVE-2026-5062

The PrettyLinks – Affiliate Links, Link Branding, Link Tracking, Marketing and Stripe Payments Plugin plugin for WordPre

4.9
CVE-2026-11920

The JoomSport – for Sports: Team & League, Football, Hockey & more plugin for WordPress is vulnerable to time-based SQL

4.9
CVE-2026-11969

The WP TripAdvisor Review Slider plugin for WordPress is vulnerable to generic SQL Injection via 'curselrevs[]' Paramete

4.9
CVE-2026-5651

The Askeet plugin for WordPress is vulnerable to SQL Injection via the 'sql_query' parameter in multiple AJAX actions (a

4.9
CVE-2026-71283

Fledge's backup-restore upload handler, upload_backup (python/fledge/services/core/api/backup_restore.py), calls tarfile

4.9
CVE-2024-8995

Unused authorization codes issued to deleted users are not being properly invalidated or removed from the system. This a

4.9
CVE-2026-17018

The CubeWP Framework WordPress plugin through 1.1.30 does not perform a per-object read authorization check, nor restric

4.9
CVE-2026-24329

A flaw was found in wildfly-core. A remote user authenticated as an administrative user can inject a malformed payload i

4.9
CVE-2026-48384

ColdFusion is affected by an Improper Input Validation vulnerability that could result in an application denial-of-servi

4.9
CVE-2026-58429

Public-Only Personal access tokens scope bypass in Organization and Permission Endpoints

4.9
CVE-2026-67613

CyberPanel before 3.0.0 contains a path traversal vulnerability that allows authenticated administrators to read arbitra

4.9
CVE-2026-73304

Budibase is an open-source low-code platform. Prior to 3.39.25, GET /api/users/metadata and GET /api/users/metadata/:id

4.9
CVE-2026-12743

The affiliate-toolkit – Multi-Network Affiliate & Amazon Product Display plugin for WordPress is vulnerable to time-base

4.9
CVE-2026-72820

Grav versions before 2.0.13 fail to properly validate backup profile root paths, allowing attackers to archive directori

4.9
CVE-2026-19631

A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbit

4.9
CVE-2026-16094

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQ

4.9
CVE-2026-16146

The Invisible Anti-Spam & CAPTCHA — reCAPTCHA Alternative for All Forms plugin for WordPress is vulnerable to generic SQ

4.9
CVE-2026-15602

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injection via the

4.9
CVE-2026-15351

The WC Vendors – WooCommerce Multivendor, WooCommerce Marketplace, Product Vendors plugin for WordPress is vulnerable to

4.9
CVE-2026-17582

The Slider Hero plugin for WordPress is vulnerable to second-order SQL Injection in versions up to, and including, 9.1.7

4.9
CVE-2026-2283

The User Login History plugin for WordPress is vulnerable to SQL Injection via the 'blog_id' parameter in all versions u

4.9
CVE-2026-17604

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to Directory Traversa

4.9
CVE-2026-73383

Shop manager Arbitrary File Download in CTX Feed <= 6.6.47 versions.

4.9
CVE-2026-68924

MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/vie

4.9
CVE-2026-74046

Wazuh 4.4.0 before 4.14.7 contains a denial of service vulnerability in the fdecompress_files() function within cluster.

4.9
CVE-2026-55164

Lemur manages TLS certificate creation. Prior to 1.9.2, lemur.users.service.update assigned a replacement password direc

4.9
CVE-2026-71085

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started