Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 950/1152
4.6
CVE-2026-7429

SSCMS v7.4.0 contains a reflected cross-site scripting vulnerability in the STL processing endpoint that allows attacker

4.6
CVE-2026-42078

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable t

4.6
CVE-2026-42080

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, there is an arbitrary fi

4.6
CVE-2026-42086

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems.

4.6
CVE-2025-31978

HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) befo

4.6
CVE-2025-52613

HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated

4.6
CVE-2026-8233

A vulnerability was determined in Dotouch XproUPF 2.0.0-release-088aa7c4. Affected is an unknown function of the compone

4.6
CVE-2026-42857

Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_ht

4.6
CVE-2026-28961

This issue was addressed with improved checks. This issue is fixed in macOS Sequoia 15.7.8, macOS Sonoma 14.8.8, macOS T

4.6
CVE-2026-28963

A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attac

4.6
CVE-2026-44259

efw4.X is an Enterprise Framework for Web. Prior to 4.08.010, the previewServlet serves files with their detected MIME t

4.6
CVE-2026-45317

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, an ap

4.6
CVE-2026-21789

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certai

4.6
CVE-2026-47090

Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd

4.6
CVE-2025-40900

An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an

4.6
CVE-2025-15645

Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due t

4.6
CVE-2026-35007

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single_unit.php that allows a

4.6
CVE-2026-35008

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in single.php that allows authen

4.6
CVE-2026-35009

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_note.php that allows auth

4.6
CVE-2026-35010

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in patient_JF.php that allows au

4.6
CVE-2026-35011

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in opena.php that allows authent

4.6
CVE-2026-35012

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_facnote.php that allows a

4.6
CVE-2026-35013

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in street_view.php that allows a

4.6
CVE-2026-35014

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in routes_nm.php that allows aut

4.6
CVE-2026-35015

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in do_unit_mail.php that allows

4.6
CVE-2026-35016

Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in search.php that allows authen

4.6
CVE-2026-41073

RT is an open source, enterprise-grade issue and ticket tracking system. Versions prior to 5.0.10 and 6.0.0 through 6.0.

4.6
CVE-2026-3314

Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hi

4.6
CVE-2026-44710

pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, src/device.c passed t

4.6
CVE-2026-33462

A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with

4.6
CVE-2026-49324

Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025

4.6
CVE-2026-49316

Expected behavior violation in the in-vehicle network of the Indian Motorcycle Scout Bobber + Tech 2025 model year allow

4.6
CVE-2026-49325

Improper handling of physical conditions in the bike-shutdown control of the Indian Motorcycle Scout Bobber + Tech 2025

4.6
CVE-2026-45153

Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlockin

4.6
CVE-2026-45284

Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper chec

4.6
CVE-2026-36174

GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations t

4.6
CVE-2026-36178

The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configu

4.6
CVE-2026-36180

A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only pr

4.6
CVE-2026-45462

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-45467

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-45468

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-45479

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-45483

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server

4.6
CVE-2026-47637

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-47638

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-47640

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-47641

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a networ

4.6
CVE-2026-48562

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-46532

ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0

4.6
CVE-2026-46609

Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML int

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started