Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 95/436
6.5
CVE-2026-79239

Out of bounds read in Tint in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to potentiall

6.5
CVE-2026-79241

Out of bounds read in GPU in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to read memory

6.5
CVE-2026-79243

Improper input validation in ReadingList in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker

6.5
CVE-2026-79246

Information leak in DataTransfer in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive i

6.5
CVE-2026-79249

Code injection in Bisection in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive inform

6.5
CVE-2026-79253

Improper input validation in Network in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker lev

6.5
CVE-2026-79258

Incorrect authorization in WebXR in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social eng

6.5
CVE-2026-79260

Improper input validation in Cookies in Google Chrome prior to 152.0.7977.65 allowed a remote attacker who had compromis

6.5
CVE-2026-79270

Uninitialized resource in ANGLE in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to read memory outside

6.5
CVE-2026-79271

Information leak in DOM in Google Chrome prior to 152.0.7977.65 allowed a remote attacker leveraging social engineering

6.5
CVE-2026-79285

Uninitialized resource in ANGLE in Google Chrome on on Windows prior to 152.0.7977.65 allowed a remote attacker to obtai

6.5
CVE-2026-79288

Improper input validation in Autofill in Google Chrome on on Android prior to 152.0.7977.65 allowed a remote attacker to

6.5
CVE-2026-79291

Information leak in CSS in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive informatio

6.5
CVE-2026-79293

Information leak in Animation in Google Chrome prior to 152.0.7977.65 allowed a remote attacker to obtain sensitive info

6.5
CVE-2026-80189

LeafWiki extracts an uploaded ZIP archive without limiting how much data it will write. ZipExtractor.ExtractToDir in int

6.5
CVE-2026-14216

The Booking for Appointments and Events Calendar WordPress plugin before 2.4.7 does not require authentication before p

6.5
CVE-2026-16984

The Privacy Policy Generator, Terms & Conditions, GDPR, CCPA, Cookie Policy & Disclaimer Templates WordPress plugin bef

6.5
CVE-2026-77695

The Return Refund and Exchange For WooCommerce WordPress plugin before 4.6.4 does not correctly verify the ownership of

6.5
CVE-2026-78146

The Simple Newsletter Plugin WordPress plugin before 4.3.3 does not verify that the requester is the subscriber named i

6.5
CVE-2025-10903

GitLab has remediated an issue in GitLab EE affecting all versions from 11.10 before 19.1.7, 19.2 before 19.2.5, and 19.

6.5
CVE-2026-77801

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.8 before 19.1.7, 19.2 before 19.2.5, and 1

6.5
CVE-2026-48548

Nagios Core before 4.5.12 contains a cross-site request forgery vulnerability in cmd.cgi where the CSRF protection mecha

6.5
CVE-2026-48549

Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSRF vulnerability in cmd.cgi. When no Cookie header

6.5
CVE-2026-81030

Mage AI does not confine the paths accepted by its browser-items API to the project directory. BrowserItemResource in ma

6.5
CVE-2026-81034

Netmaker disables certificate verification on the connection to the configured mail server. The sender in pro/email/smtp

6.5
CVE-2026-48786

Fleet is an open-source device management platform built on osquery. In versions prior to 4.87.0, the target search endp

6.5
CVE-2026-75466

libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability in the PNG loader. When processing a valid indexe

6.5
CVE-2026-46370

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the labels

6.5
CVE-2026-46371

Fleet is an open-source device management platform built on osquery. In versions up to and including 4.84.1, the Apple M

6.5
CVE-2026-47842

Applications using AesBytesEncryptor with the two-argument constructor or when passing a null IV generator and CBC as th

6.5
CVE-2026-49809

Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used i

6.5
CVE-2026-71054

Vulnerability in Oracle Java SE (component: 2D). Supported versions that are affected are Oracle Java SE: 7u511. Easily

6.5
CVE-2026-74771

Dell PowerProtect One, versions 20.1.0.0 and below, contain an Authorization Bypass Through User-Controlled Key vulnerab

6.5
CVE-2026-62326

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

6.5
CVE-2026-47860

An attacker who can publish to a queue consumed by an application that has enabled message decompression can crash the c

6.5
CVE-2026-59274

The UnZipTransformer does not limit decompressed entry size or entry count when processing archives. Consequently, an at

6.5
CVE-2026-59278

JsonKafkaHeaderMapper and DefaultKafkaHeaderMapper include java.net in their default trusted packages list. When these m

6.5
CVE-2026-78273

Subscriber Cross Site Scripting (XSS) in Fluent Boards Pro <= 2.0.11 versions.

6.5
CVE-2026-17562

Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Fu

6.5
CVE-2026-81658

A flaw was found in Foreman. The template revision endpoint does not enforce object-level authorization when retrieving

6.5
CVE-2026-40526

Volmarg Personal Management System contains a path traversal vulnerability that allows authenticated attackers to read a

6.5
CVE-2026-80210

FrontAccounting through 2.4.20 generates a CSRF token in end_form() in includes/ui/ui_controls.inc and embeds it as the

6.5
CVE-2026-81101

The configure command accepted any endpoint URL and stored it beside the user's access token. ConfigureCommand.execute i

6.5
CVE-2026-54732

libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js u

6.5
CVE-2026-59317

DeadLetterPublishingRecovererFactory reads the retry_topic-original-timestamp header from an inbound ConsumerRecord and

6.5
CVE-2026-59320

When a container-level ErrorHandler is configured (the mitigation for finding 221000), each delivery whose processing th

6.5
CVE-2026-81521

The MongoDB Go Driver's client-level bulk write operation may accept a caller-supplied database name containing a reserv

6.5
CVE-2026-81526

The MongoDB Rust Driver does not neutralize special characters in a caller-supplied target identifier before embedding i

6.5
CVE-2026-81527

A NoSQL/expression injection weakness exists in the LINQ-to-aggregation query translation layer of the MongoDB C# Driver

6.5
CVE-2026-81729

Dolibarr before 23.0.4 authorizes REST API document deletion against the wrong permission. Documents::delete() in htdocs

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started