Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 947/1152
4.7
CVE-2026-15173

pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows denial of service

4.7
CVE-2026-57031

An Improper Check for Unusual or Exceptional Conditions vulnerability in the packet forwarding engine (PFE) of Juniper N

4.7
CVE-2026-15494

A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/

4.7
CVE-2026-15518

A vulnerability has been found in AREA 17 Twill CMS up to 3.6.0. The impacted element is the function FileLibraryControl

4.7
CVE-2026-15533

A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of

4.7
CVE-2026-15539

A security vulnerability has been detected in SourceCodester Online Book Store System 1.0. Impacted is an unknown functi

4.7
CVE-2026-44760

Due to a Cross-Site Scripting (XSS) vulnerability, applications based on Business Server Pages framework in SAP NetWeave

4.7
CVE-2026-15700

A security flaw has been discovered in DedeCMS 5.7.118. Affected by this vulnerability is the function ExtractFile of th

4.7
CVE-2026-49167

Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.

4.7
CVE-2026-54432

Roundcube Webmail before 1.6.17 and 1.7.x before 1.7.2 allows Stored Cross-Site Scripting (XSS). The issue occurs becaus

4.7
CVE-2026-50310

Integer overflow or wraparound in Windows Devices Human Interface allows an authorized attacker to disclose information

4.7
CVE-2026-50312

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges loca

4.7
CVE-2026-50657

Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to

4.7
CVE-2026-50183

WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerabilit

4.7
CVE-2026-40106

Wazuh is a free and open source platform used for threat prevention, detection, and response. Versions 4.6.0 and above p

4.7
CVE-2026-54163

secure_headers manages application of security headers with many safe defaults. Prior to 7.3.0, secure_headers builds th

4.7
CVE-2026-16088

A vulnerability was detected in halo-dev halo up to 2.24.2. Affected by this vulnerability is the function Download of t

4.7
CVE-2026-16226

A weakness has been identified in SourceCodester Pizzafy Ecommerce System 1.0. This affects the function save_settings o

4.7
CVE-2026-64823

Home Assistant Core before 2026.5.4 contains a cross-site scripting vulnerability in the Shelly integration's async_get_

4.7
CVE-2026-60337

Vulnerability in the Oracle Project Manufacturing product of Oracle E-Business Suite (component: PJM Command Center).

4.7
CVE-2026-61044

Vulnerability in the Oracle Production Scheduling product of Oracle E-Business Suite (component: Internal Operations).

4.7
CVE-2026-65904

DOMPurify through 3.3.3 fails to sanitize DOM elements passed via IN_PLACE mode when the element originates from a diffe

4.7
CVE-2026-64282

In the Linux kernel, the following vulnerability has been resolved: KVM: arm64: Don't leak PFN when kvm_translate_vncr(

4.7
CVE-2026-14236

The Contact Form 7 WordPress plugin before 2.5 does not validate the host of a user-supplied return URL before using it

4.7
CVE-2026-43770

A race condition was addressed with additional validation. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.

4.7
CVE-2026-43781

A race condition was addressed with improved state handling. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 1

4.7
CVE-2026-43811

A race condition was addressed with improved checks. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 26.6 and

4.7
CVE-2026-3093

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 14.0 before 19.0.5, 19.1 before 19.1.3, and 1

4.7
CVE-2026-62343

ImageMagick is free and open-source software used for editing and manipulating digital images. In versions prior to 6.9.

4.7
CVE-2026-62845

Kamaji is the Hosted Control Plane Manager for Kubernetes. Prior to 26.7.4-edge, the PostgreSQL and MySQL datastore driv

4.7
CVE-2026-18321

Buffer overflow in NTPsec's Zyfer refclock allows local attacker to crash ntpd

4.7
CVE-2026-18592

A security flaw has been discovered in osCommerce 4.14.63493. Affected by this issue is the function EmailController of

4.7
CVE-2026-18738

Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vulnerability that allows unauthenticated remote att

4.7
CVE-2026-16296

The Clearfy Cache WordPress plugin before 2.4.3 does not validate the redirect target in its Cyrlitera old-URL redirect

4.7
CVE-2026-18856

A vulnerability was determined in Poesis Rhymix CMS up to 2.1.33. This impacts the function procImporterAdminCheckXmlFil

4.7
CVE-2026-15452

The Smash Balloon Social Photo Feed – Easy Social Feeds Plugin plugin for WordPress is vulnerable to Reflected Cross-Sit

4.7
CVE-2026-13477

IBM QRadar 7.6.0.0 through 7.6.0.1, and 7.5.0 through 7.5.0 UP 15 Interim Fix 005 could allow an authenticated privilege

4.7
CVE-2026-18909

A stack-based buffer overflow vulnerability exists in ELAN Microelectronics Corp. ELAN Smart-Pad on Windows (ETD.sys and

4.7
CVE-2026-71497

jsoup is a Java library for working with real-world HTML. From 1.14.3 until 1.23.1, jsoup's HTML parser could incorrectl

4.7
CVE-2026-19244

A vulnerability was detected in HKUDS nanobot up to 0.2.1. The affected element is the function connect_mcp_servers of t

4.7
CVE-2026-19359

A security vulnerability has been detected in nxp-auto-goldvip gvip up to 1.4.0. Affected by this issue is the function

4.7
CVE-2026-19360

A vulnerability was detected in wongcyrus ExcelLexBot up to 0.0.3. This affects the function ExcelLexBotS3TriggerFunctio

4.7
CVE-2026-19383

A security vulnerability has been detected in saithink/saigroup SaiAdmin up to 5.0.1. This impacts the function shell_ex

4.7
CVE-2026-15060

When systemd-machined >= v259 (or v258 with a custom `polkit` policy that allows `register-machine` access) is running o

4.7
CVE-2026-47922

CAI Content Credentials is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege

4.7
CVE-2026-73490

Loofah is a general library for manipulating and transforming HTML/XML documents and fragments, built on top of Nokogiri

4.7
CVE-2026-18622

Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations

4.7
CVE-2026-19694

TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of service

4.7
CVE-2026-19695

Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of service

4.7
CVE-2025-52640

HCL AION is affected by a vulnerability where the shared storage used by product components is architected without suffi

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started