Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 959/1152
4.4
CVE-2026-15786

The WP Encryption – One Click Free SSL Certificate & SSL / HTTPS Redirect, Security & SSL Scan plugin for WordPress is v

4.4
CVE-2026-24639

Author Server Side Request Forgery (SSRF) in Photo Block <= 1.7.1 versions.

4.4
CVE-2026-65496

Author Server Side Request Forgery (SSRF) in Complianz <= 7.5.0 versions.

4.4
CVE-2026-15673

The SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress is vulnera

4.4
CVE-2026-56850

A flaw in Node.js HTTPS Agent connection reuse can cause PFX object-array key collisions, allowing mutual TLS (mTLS) cli

4.4
CVE-2026-59327

Spring Tools for Eclipse stores the Spring Boot DevTools remote secret (spring.devtools.remote.secret) as a plain string

4.4
CVE-2026-20472

In TFA, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servic

4.4
CVE-2026-20484

In TFA, there is a possible information disclosure due to a missing permission check. This could lead to local informati

4.4
CVE-2026-20488

In display, there is a possible information disclosure due to a missing bounds check. This could lead to local informati

4.4
CVE-2026-20489

In display, there is a possible information disclosure due to an integer overflow. This could lead to local information

4.4
CVE-2026-20490

In ccci, there is a possible out of bounds read due to a missing bounds check. This could lead to local denial of servic

4.4
CVE-2026-20493

In wifi, there is a possible out of bounds write due to a missing bounds check. This could lead to local denial of servi

4.4
CVE-2026-20496

In geniezone, there is a possible out of bounds read due to a missing bounds check. This could lead to local information

4.4
CVE-2026-18508

A flaw was found in GNU tar. When extracting an archive with the --one-top-level option, hardlink targets are not confin

4.4
CVE-2026-18477

A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's incremental dumpdir 'X' rename handling allows a local a

4.4
CVE-2026-17614

A path traversal flaw was found in WildFly's domain mode implementation. The LocalFileRepository.getFile() and getCo

4.4
CVE-2026-47487

NVIDIA Triton Inference Server for Linux contains a vulnerability where a user could cause files outside the model repos

4.4
CVE-2026-5108

The Super Progressive Web Apps plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `superpwa_setti

4.4
CVE-2026-5116

The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all ver

4.4
CVE-2026-71212

xidown (a yt-dlp/ffmpeg GUI wrapper) builds its yt-dlp command-line invocation (xidown/core/scanner.py and downloader.py

4.4
CVE-2026-0637

When an Event Publisher output adapter is configured with irrelevant properties, the affected products log these propert

4.4
CVE-2026-19079

A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was found in the fixfiles script in policycoreutils. W

4.4
CVE-2026-11425

Domoticz versions prior to 2026.3 contains a stored cross-site scripting vulnerability in the mobile dashboard that allo

4.4
CVE-2026-19326

A vulnerability was detected in Jevon-Zhong Ai-doctor 0.0.1. This vulnerability affects the function deleteImage of the

4.4
CVE-2026-6426

A type mismatch vulnerability was found in QEMU's vhost inflight migration VMState handling. The destination buffer size

4.4
CVE-2026-20752

Improper authentication for some Intel(R) PROSet/Wireless WiFi Software within Ring 0: Kernel may allow an information d

4.4
CVE-2026-73036

Bash-it 3.2.0 contains a terminal escape sequence injection vulnerability in the barbuk theme's Python virtualenv prompt

4.4
CVE-2026-47234

Admidio is an open-source user management solution. Prior to version 5.0.10, when debug logging is enabled, `Session::se

4.4
CVE-2026-58420

Local File Inclusion via file:// URI in Migration Restore

4.4
CVE-2026-17438

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a local attacker to obtain sensitive information or modify data due to improper

4.4
CVE-2026-13002

A flow has been identified into dnssec.c library, causing an infinite loop to dnsmasq service. An attacker who controls

4.4
CVE-2026-2487

The Admin Custom Login plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versi

4.4
CVE-2026-12477

The Gravity Booster – Styles & Layouts for Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripti

4.4
CVE-2026-75059

In JetBrains PyCharm before 2026.2.1 code execution via Quick Documentation was possible

4.4
CVE-2026-60884

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Panel Processor). Suppo

4.4
CVE-2026-71060

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

4.4
CVE-2026-71139

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version th

4.4
CVE-2026-71145

Vulnerability in the Oracle Hyperion Financial Management product of Oracle Hyperion (component: Security). The suppor

4.4
CVE-2026-73880

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

4.4
CVE-2026-16897

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to an out-of

4.4
CVE-2026-75526

django CMS is an easy-to-use and developer-friendly enterprise content management system powered by Django. From 5.0.8 u

4.4
CVE-2026-18822

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to cause a denial of service due to uncontrol

4.4
CVE-2026-77643

A cross-site scripting vulnerability in queryparser/termgenerator_internal.cc in Xapian xapian-core before 2.1.0 and be

4.4
CVE-2026-78196

A security flaw has been discovered in achorein expo-share-intent up to 8.0.0. This affects the function getDataColumn o

4.4
CVE-2026-75982

The LearnPress plugin for WordPress is vulnerable to unauthorized modification of arbitrary WordPress options in version

4.4
CVE-2026-80101

A flaw was found in the file-xwd plugin in GIMP. When processing a specially crafted XWD image file, the plugin validate

4.4
CVE-2026-76149

CorvusSKK contains an integer overflow vulnerability, which may allow malicious data to be written to a dictionary file.

4.4
CVE-2026-61790

Weblate is a web-based continuous localization platform used to manage software translations. In versions prior to 2026.

4.4
CVE-2026-21810

HCL BigFix Quantum Risk Analyzer is affected by a hardcoded external resource reference and a lack of binary integrity w

4.4
CVE-2026-19454

The JetBackup WordPress plugin before 3.1.23.5 does not perform its multisite authorisation check before serving backup

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started