Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 94/454
8.5
CVE-2026-10129

IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in th

8.5
CVE-2026-11714

IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscover

8.5
CVE-2026-11594

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative

8.5
CVE-2026-24260

NVIDIA Container Toolkit for Linux contains a vulnerability where an attacker could cause a time-of-check time-of-use ra

8.5
CVE-2025-69094

Subscriber SQL Injection in Unicamp <= 2.2.2 versions.

8.5
CVE-2026-57687

Contributor SQL Injection in Custom Field Template <= 2.7.8 versions.

8.5
CVE-2026-57752

Contributor SQL Injection in iNET Webkit 1.2.4 versions.

8.5
CVE-2026-57756

Contributor SQL Injection in nicen-localize-image <= 1.4.9 versions.

8.5
CVE-2026-57765

Contributor SQL Injection in WP EasyCart <= 5.9.0 versions.

8.5
CVE-2026-10055

In Eclipse Theia since version 1.26.0, the backend /services/request-service RPC accepts an attacker-controlled URL from

8.5
CVE-2026-26231

Gitea versions up to and including 1.26.1 allow the Allow edits from maintainers permission path to authorize commits to

8.5
CVE-2025-53828

SharePoint for ownCloud is an application for using SharePoint with the file storage, synchronization, and sharing appli

8.5
CVE-2026-54765

Traefik is an open source HTTP reverse proxy and load balancer. From v3.7.0 prior to v3.7.6, Traefik's Kubernetes Gatewa

8.5
CVE-2026-55999

Local attackers with a X connection able to provide PCX fonts to the X server xorg-server before 21.2.24 and xwayland b

8.5
CVE-2026-56001

A heap buffer overflow in BitmapScaleBitmaps in libXfont2 before 2.0.8 due to an overflowing 32bit size could be used by

8.5
CVE-2026-56002

A heap bufferflow in pcfReadFont() due to missing glyph bounds checking in libXfont2 before 2.0.8  allows attackers auth

8.5
CVE-2026-56003

A heap buffer overflow due to missing size checking in the property buffer when parsing PCF files in libXfont2 ComputeSc

8.5
CVE-2026-56690

Dell PowerFlex Manager, Version prior to 5.1.0.1, contain(s) an Improper Neutralization of Special Elements used in an S

8.5
CVE-2026-54329

Snipe-IT is an IT asset/license management system. Prior to 8.6.2, the Accessories API create path mass-assigns request

8.5
CVE-2026-55789

Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 1.41.0, Logto's self-hosted SAML app

8.5
CVE-2026-61429

PraisonAI versions before 1.6.78 contain a server-side request forgery vulnerability in the Crawl4AI/Chromium backend th

8.5
CVE-2026-57385

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in appsbd Vitepos vit

8.5
CVE-2026-57771

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Milan Petrovic GD

8.5
CVE-2026-57772

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WP Inventory WP In

8.5
CVE-2026-57787

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in CreativeWS CWS SVG

8.5
CVE-2026-57810

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saad Iqbal APIExpe

8.5
CVE-2026-62197

OpenClaw before 2026.6.6 contains a policy bypass vulnerability in browser CDP discovery that accepts blocked WebSocket

8.5
CVE-2026-50340

Use after free in Windows Runtime allows an authorized attacker to elevate privileges over a network.

8.5
CVE-2026-15738

Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2

8.5
CVE-2026-48320

ColdFusion is affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerabi

8.5
CVE-2026-61430

PraisonAI before 1.6.78 contains a server-side request forgery vulnerability in the web_crawl tool that validates hostna

8.5
CVE-2026-55234

Wekan is open source kanban built with Meteor. Prior to 9.37, Wekan DDP update allow rules in server/permissions/cards.j

8.5
CVE-2026-62226

OpenClaw 2026.3.28 before 2026.5.19 contain an authorization bypass vulnerability in the browser act route that fails to

8.5
CVE-2024-58366

SurrealDB before 1.1.1 contains a format string vulnerability in the rquickjs Exception::throw_type function when script

8.5
CVE-2026-47198

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.1, the

8.5
CVE-2026-47033

Vulnerability in the Oracle Contracts Integration product of Oracle E-Business Suite (component: Internal Operations).

8.5
CVE-2026-60193

Vulnerability in the MySQL Connectors product of Oracle MySQL (component: Connector/Net). Supported versions that are a

8.5
CVE-2026-60295

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

8.5
CVE-2026-60330

Vulnerability in the Oracle Identity Manager product of Oracle Fusion Middleware (component: OIM Legacy UI). Supported

8.5
CVE-2026-60420

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

8.5
CVE-2026-60426

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

8.5
CVE-2026-60444

Vulnerability in the Oracle WebCenter Content product of Oracle Fusion Middleware (component: Content Server). Supporte

8.5
CVE-2026-60452

Vulnerability in the WebCenter Content: Imaging product of Oracle Fusion Middleware (component: Core). Supported versio

8.5
CVE-2026-61312

Vulnerability in the Oracle Product Hub product of Oracle E-Business Suite (component: Internal Operations). Supported

8.5
CVE-2026-62513

Vulnerability in the Oracle Process Manufacturing Regulatory Management product of Oracle E-Business Suite (component: I

8.5
CVE-2026-24552

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in John-Michael L'All

8.5
CVE-2026-25405

Contributor SQL Injection in eRoom <= 1.7.1 versions.

8.5
CVE-2026-65450

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

8.5
CVE-2026-65451

Contributor SQL Injection in MapSVG <= 8.14.0 versions.

8.5
CVE-2026-65454

Contributor SQL Injection in Quiz And Survey Master <= 11.2.0 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started