Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 948/1152
4.7
CVE-2026-14256

ELAN reported a potential out-of-bounds write vulnerability in the ELAN TrackPoint driver that, under certain circumstan

4.7
CVE-2026-49820

Probo is a self-hostable governance, risk, and compliance (GRC) platform built for engineering and security teams. Probo

4.7
CVE-2026-53797

rsync before 3.5.0 contains a symlink race condition vulnerability in the sender's source tree traversal that allows an

4.7
CVE-2026-53800

rsync before 3.5.0 contains a symlink race condition vulnerability in the --remove-source-files feature that allows atta

4.7
CVE-2026-73563

Backstage is an open framework for building developer portals. Prior to 0.29.2, the experimental dynamic client registra

4.7
CVE-2026-19761

A vulnerability has been found in DTStack Taier 1.4.0. Affected is the function MultipartFile.getOriginalFilename of the

4.7
CVE-2026-19787

A vulnerability was determined in SourceCodester Air Cargo Management System 1.0. Impacted is an unknown function of the

4.7
CVE-2026-19834

A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected is an unknown function of the file /admin/custome

4.7
CVE-2026-19839

A vulnerability was detected in SourceCodester Simple Doctors Appointment System 1.0. This issue affects the function sa

4.7
CVE-2026-19925

A vulnerability was detected in SourceCodester Stock Management System 1.0. This issue affects some unknown processing o

4.7
CVE-2026-19971

A flaw has been found in LB-Link WR1210M 1.0.3. This impacts the function main of the file /www/cgi-bin/backup.cgi of th

4.7
CVE-2026-19997

A security flaw has been discovered in Webkul Bagisto up to 2.4.4. This issue affects some unknown processing of the fil

4.7
CVE-2026-62575

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Installation and C

4.7
CVE-2026-70794

Vulnerability in the Oracle Hyperion Financial Reporting product of Oracle Hyperion (component: Server). The supported

4.7
CVE-2026-71105

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

4.7
CVE-2026-14287

The 10Web Booster WordPress plugin before 2.33.5 does not correctly validate an access token on an unauthenticated requ

4.7
CVE-2026-76572

A vulnerability was detected in pkp pkp-lib up to 3.3.0-22/3.4.0-10/3.5.0-4. The affected element is the function _trans

4.7
CVE-2026-76881

CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

4.7
CVE-2026-76882

Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

4.7
CVE-2026-76883

Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

4.7
CVE-2026-76889

UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

4.7
CVE-2026-76920

3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

4.7
CVE-2026-76927

H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

4.7
CVE-2026-76929

Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of service

4.7
CVE-2026-76995

A vulnerability was identified in SourceCodester Simple Online Food Ordering System 1.0. This issue affects some unknown

4.7
CVE-2026-68921

DiceBear is an avatar library for designers and developers. Prior to 9.4.3, @dicebear/core interpolates the rotate optio

4.7
CVE-2026-17009

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to a NULL po

4.7
CVE-2026-73537

Cross-site scripting vulnerability exists in Miraikan Assist App. If this vulnerability is exploited, an arbitrary scrip

4.7
CVE-2026-78140

A flaw has been found in Dromara UJCMS up to 10.1.3. The impacted element is the function update of the file src/main/ja

4.7
CVE-2026-56136

In NTFS-3G through 2026.2.25, an out-of-bounds read exists in ntfs_ir_nill() in libntfs-3g/index.c that allows an attack

4.7
CVE-2026-34959

Adminer 4.6.0 before 5.5.0 prepends the client-supplied X-Forwarded-Prefix header to $_SERVER["REQUEST_URI"] with no tru

4.7
CVE-2026-15917

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core

4.7
CVE-2026-80200

Kimai before 2.53.0 contains an open redirect vulnerability in the SAML authentication success handler that accepts unva

4.7
CVE-2026-14212

The Booking for Appointments and Events Calendar WordPress plugin before 9.8 does not verify that an authenticated empl

4.7
CVE-2026-81893

A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG image containing chunked ICC profile markers, an e

4.7
CVE-2026-82274

Twenty through 2.35.0 contains an open redirect vulnerability in the OAuthPropagatorController.propagateOAuthCallback en

4.7
CVE-2026-81342

The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.43 does not validate a redirect parameter supplied dur

4.7
CVE-2026-82467

Rodauth before 2.47.0 fails to validate protocol-relative return-to paths in confirm_password, login_return_to_requested

4.7
CVE-2026-82468

Rodauth before 2.47.0 contains a cross-site request forgery protection bypass vulnerability in the JSON request content

4.6
CVE-2026-20974

Improper input validation in data related to network restrictions prior to SMR Jan-2026 Release 1 allows physical attack

4.6
CVE-2026-20828

Out-of-bounds read in Windows Internet Connection Sharing (ICS) allows an unauthorized attacker to disclose information

4.6
CVE-2026-20834

Absolute path traversal in Windows Shell allows an unauthorized attacker to perform spoofing with a physical attack.

4.6
CVE-2026-20959

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2025-67399

An issue in AIRTH SMART HOME AQI MONITOR Bootloader v.1.005 allows a physically proximate attacker to obtain sensitive i

4.6
CVE-2025-13453

A potential vulnerability was reported in some ThinkPlus USB drives that could allow a user with physical access to read

4.6
CVE-2026-21981

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that a

4.6
CVE-2025-68132

EVerest is an EV charging software stack. Prior to version 2025.12.0, `is_message_crc_correct` in the DZG_GSH01 powermet

4.6
CVE-2025-66488

Discourse is an open source discussion platform. A vulnerability present in versions prior to 3.5.4, 2025.11.2, 2025.12.

4.6
CVE-2025-67723

Discourse is an open source discussion platform. Versions prior to 3.5.4, 2025.11.2, 2025.12.1, and 2026.1.0 have a cont

4.6
CVE-2025-15543

Improper link resolution in USB HTTP access path in VX800v v1.0 allows a crafted USB device to expose root filesystem co

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started