Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 939/1152
4.8
CVE-2026-66139

OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXTRA-SPEC header when a UUID is known.

4.8
CVE-2026-14203

The Smart Manager WordPress plugin before 8.92.0 does not properly encode a post field before rendering it into an HTML

4.8
CVE-2026-63237

A TOTP two-factor authentication bypass vulnerability in Koollab LMS allowed an attacker to supply a client-controlled s

4.8
CVE-2026-65325

Apache Traffic Server reuses multiplexed HTTP/2 origin connections without verifying the server certificate covers the n

4.8
CVE-2026-65100

Apache Traffic Server updates the HTTP/2 HPACK dynamic table before confirming the header block encoded successfully, so

4.8
CVE-2026-66400

Grav Login Plugin versions before 3.8.13 contain an insufficient session expiration vulnerability in TokenStorage.php wh

4.8
CVE-2026-16729

undici's setCookie function does not fully sanitize cookie attributes. In undici before 6.28.0, from 7.0.0 up to before

4.8
CVE-2026-16728

undici's retry interceptor can deliver a response whose body length does not match the Content-Length header exposed to

4.8
CVE-2026-13344

The Essential Addons for Elementor WordPress plugin before 6.6.10 does not validate the HTML tag name of the Pricing Ta

4.8
CVE-2026-63220

CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-For

4.8
CVE-2026-54706

OnionShare is an open source tool that lets you securely and anonymously share files, host websites, and chat with frien

4.8
CVE-2025-15669

The Bit Form WordPress plugin before 3.1.4 does not sanitise one of its conversational-form display settings before ren

4.8
CVE-2025-15675

The Charitable WordPress plugin before 1.8.5.3 does not sanitise and escape one of its campaign image text fields befor

4.8
CVE-2026-56609

HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using

4.8
CVE-2026-67612

OpenEMR through 8.2.0 contains a stored cross-site scripting vulnerability in the patient portal template system that al

4.8
CVE-2026-67617

Microweber CMS through 2.0.20 contains a stored cross-site scripting vulnerability in the content tagging system that al

4.8
CVE-2026-14824

The Quiz and Survey Master (QSM) WordPress plugin before 11.2.2 does not properly escape a question setting before outp

4.8
CVE-2026-15233

The Nested Pages WordPress plugin before 3.2.15 does not properly escape post titles before outputting them into HTML at

4.8
CVE-2026-70589

Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to rede

4.8
CVE-2026-70590

Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed password

4.8
CVE-2026-20198

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an aut

4.8
CVE-2026-71318

Nuxt is an open-source web development framework for Vue.js. From 3.1.0 until 3.21.10 and 4.5.1, an attacker can supply

4.8
CVE-2026-19019

A security flaw has been discovered in poco-ai poco-agent up to 0.5.4. Affected is the function WorkspaceManager._setup_

4.8
CVE-2026-15256

The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate

4.8
CVE-2026-45572

Decidim is a participatory democracy framework. Prior to 0.30.9, from 0.31.0 before 0.31.5, and in 0.32.0.rc1 before 0.3

4.8
CVE-2026-71850

Hono is a Web application framework that provides support for any JavaScript runtime. From 3.8.0 to 4.12.33, memo() from

4.8
CVE-2026-16269

The Newsletters WordPress plugin before 4.16 does not strictly compare its API authentication key, allowing unauthentica

4.8
CVE-2026-16953

The AI Engine WordPress plugin before 3.6.4 does not verify ownership of a guest's uploaded chatbot files before deleti

4.8
CVE-2026-13701

The Advanced Excerpt WordPress plugin before 4.5 does not sanitise and escape one of its settings before outputting it o

4.8
CVE-2026-17023

The Salon Booking System WordPress plugin through 10.30.33 does not perform any capability check or validate an OAuth s

4.8
CVE-2026-66406

DEEBOT PRO M1 and DEEBOT PRO K1VAC use wget command with server certificate validation disabled. A man-in-the-middle at

4.8
CVE-2026-66410

Android and iOS apps ECOVACS PRO App improperly validate server certificates. Communication may be retrieved and/or alt

4.8
CVE-2026-44401

Typemill CMS version 2.x contains a persistent cross-site scripting vulnerability in the Markdown parser extension that

4.8
CVE-2026-73282

In ssh in OpenSSH before 10.5, a use-after-free for realloc data can occur if a certain pair of remote-forwarding operat

4.8
CVE-2026-19503

MongoDB Schema Manager and MongoDB Atlas SQL ODBC Driver do not validate the scheme of the authorization and token endpo

4.8
CVE-2026-17476

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to cause a denial of service due to an improper buffer write.

4.8
CVE-2026-18741

Worksuite SaaS versions prior to 6.0.14 contains a stored cross-site scripting vulnerability in the Asset Management mod

4.8
CVE-2026-74241

A flaw was found in Red Hat Quay's external Lightweight Directory Access Protocol (LDAP) authentication handling. When a

4.8
CVE-2026-73055

Shescape before 2.1.15 (and 3.0.0 before 3.0.2) fails to properly escape tilde (~) characters in assignment contexts on

4.8
CVE-2026-55165

Lemur manages TLS certificate creation. Prior to 1.9.2, the JWT verifier in lemur/auth/service.py:130-137 used fetch_tok

4.8
CVE-2026-62520

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Common Events).

4.8
CVE-2026-70709

Vulnerability in the Oracle Agile Engineering Data Management product of Oracle Supply Chain (component: Engineering Com

4.8
CVE-2026-71088

Vulnerability in the Oracle Agile PLM MCAD Connector product of Oracle Supply Chain (component: CAX Client). The suppo

4.8
CVE-2026-71118

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

4.8
CVE-2026-73901

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

4.8
CVE-2026-16866

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to cause a denial of service due to an out-o

4.8
CVE-2026-21784

HCL IntelliOps Event Management (IEM) is affected by missing or insecure Cross-Origin Security headers. This issue makes

4.8
CVE-2026-54625

django CMS is a content management system powered by Django. Prior to 5.0.8 and in 5.1.0a1, the django CMS page cache in

4.8
CVE-2026-77506

Znuny before LTS 6.5.22 allows AgentTicketEmailResend template XSS.

4.8
CVE-2026-17424

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote attacker to bypass security restrictions due to impro

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started