Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 951/1152
4.6
CVE-2026-45106

Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and

4.6
CVE-2022-44630

Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Reque

4.6
CVE-2026-50099

During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in clearte

4.6
CVE-2026-11443

Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote at

4.6
CVE-2026-56269

Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' fo

4.6
CVE-2026-10642

The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable()

4.6
CVE-2026-9799

A flaw was found in org.keycloak.authorization. An authenticated user with a granted User-Managed Access (UMA) permissio

4.6
CVE-2026-38571

Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands,

4.6
CVE-2026-13808

Insufficient data validation in Chrome for iOS in Google Chrome on iOS prior to 150.0.7871.47 allowed a local attacker t

4.6
CVE-2026-6683

FatFs R0.16 and earlier contains a divide-by-zero in exFAT sync logic bug when crafted metadata causes n_fatent - 2 to b

4.6
CVE-2026-6684

FatFs prior to R0.16 that use GPT scanning with 'FF_LBA64 = 1' contains an issue where an unbounded loop count derived f

4.6
CVE-2026-6686

FatFs R0.16 and earlier contains an uninitialized cluster exposure when f_lseek() extends files beyond EOF without zero-

4.6
CVE-2026-34096

Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribut

4.6
CVE-2026-34097

Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attri

4.6
CVE-2026-34098

Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action att

4.6
CVE-2026-4770

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in TR7 Cyber ​​Defens

4.6
CVE-2026-10656

The MAX32xxx USB device controller driver (drivers/usb/udc/udc_max32.c, compatible adi_max32_usbhs) dereferenced an endp

4.6
CVE-2026-10834

The WP Travel Engine WordPress plugin before 6.8.1 does not properly validate the source of a user-supplied profile ima

4.6
CVE-2026-46672

Actual is a local-first personal finance app. Prior to 26.6.0, @actual-app/cli ships a hand-rolled CSV serializer in pac

4.6
CVE-2026-61456

The Grav API plugin (getgrav/grav-plugin-api) before 1.0.3 fails to sanitize SVG files uploaded through the POST /api/v1

4.6
CVE-2025-30008

HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users

4.6
CVE-2026-49794

Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose informat

4.6
CVE-2026-55016

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-55019

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-55020

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-55030

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-55135

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-62826

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-21760

HCL DevOps Loop is affected by an Unauthorized Access to Admin Functionality (Forced Browsing) vulnerability. Improper a

4.6
CVE-2026-53592

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. A Prototype Pollution condition in th

4.6
CVE-2026-47689

FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.

4.6
CVE-2026-46948

Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Sec

4.6
CVE-2026-60684

Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Upload Attachments).

4.6
CVE-2026-7007

The Zephyr ext2 file system validates the on-disk superblock in ext2_verify_disk_superblock() (subsys/fs/ext2/ext2_impl.

4.6
CVE-2026-43753

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.6 and iPadOS 26.6, macO

4.6
CVE-2026-43766

An authorization issue was addressed with improved state management. This issue is fixed in macOS Sequoia 15.7.8, macOS

4.6
CVE-2026-64732

This issue was addressed through improved state management. This issue is fixed in iOS 18.7.10 and iPadOS 18.7.10, iOS 2

4.6
CVE-2026-16273

The Narrative Publisher WordPress plugin through 1.0.7 does not restrict write access to a REST-exposed post meta field

4.6
CVE-2026-20471

In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of service

4.6
CVE-2026-69093

Admidio before 5.0.11 does not validate the adm_csrf_token in modules/category-report/preferences.php, which performs pe

4.6
CVE-2026-67673

A stack-based buffer overflow vulnerability exists in the cmd_edl function of OreSat Firmware v1.0. The vulnerability is

4.6
CVE-2026-47362

In versions of the Datadog Android application prior to v554-5.9.4, two Room-backed SQLite databases store sensitive con

4.6
CVE-2026-21060

Improper input validation in Samsung Contacts prior to SMR Aug-2026 Release 1 allows physical attackers to access data a

4.6
CVE-2026-21070

Improper input validation in Samsung Message prior to SMR Aug-2026 Release 1 allows physical attackers to access sensiti

4.6
CVE-2026-66408

The root accounts of DEEBOT PRO M1 and DEEBOT PRO K1VAC are configured with weak passwords. Physical access to an affec

4.6
CVE-2026-12051

The USB DFU class implementation in Zephyr's new (experimental) device_next USB device stack contains a NULL pointer der

4.6
CVE-2026-21269

is affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to in

4.6
CVE-2026-61350

Buffer over-read in Windows NTFS allows an unauthorized attacker to disclose information with a physical attack.

4.6
CVE-2026-62829

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allo

4.6
CVE-2026-62917

Improper input validation in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a networ

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started