Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

22,671 of 57,566 · Page 96/454
8.5
CVE-2026-17179

IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a remote authenticated attacker to cause a denial of service due to c

8.5
CVE-2026-57485

Stirling-PDF is a locally hosted web application that facilitates various operations on PDF files. Prior to 2.9.0, the /

8.5
CVE-2026-73410

Budibase is an open-source low-code platform. Prior to 3.40.0, packages/backend-core/src/utils/outboundFetch.ts pinned a

8.5
CVE-2026-32466

Subscriber SQL Injection in Gravity Forms Bookings premium <= 2.1 versions.

8.5
CVE-2026-75898

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (age

8.5
CVE-2026-60758

Vulnerability in the Siebel Artificial Intelligence product of Oracle Siebel CRM (component: AI). Supported versions th

8.5
CVE-2026-60798

Vulnerability in the Siebel CRM Deployment product of Oracle Siebel CRM (component: Migration). Supported versions that

8.5
CVE-2026-60841

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

8.5
CVE-2026-60849

Vulnerability in the Oracle Unified Directory product of Oracle Fusion Middleware (component: OUD Core). Supported vers

8.5
CVE-2026-61212

Vulnerability in the Oracle WebCenter Portal product of Oracle Fusion Middleware (component: Runtime Tools). Supported

8.5
CVE-2026-61326

Vulnerability in the Siebel CRM Cloud Applications product of Oracle Siebel CRM (component: Siebel Cloud Manager). Supp

8.5
CVE-2026-62590

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versi

8.5
CVE-2026-62596

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: Open Integration). Supported versi

8.5
CVE-2026-62615

Vulnerability in the Oracle Reports Developer product of Oracle Fusion Middleware (component: Security and Authenticatio

8.5
CVE-2026-70718

Vulnerability in the Oracle Bills of Material product of Oracle E-Business Suite (component: Internal Operations). Supp

8.5
CVE-2026-70728

Vulnerability in Oracle Autonomous Health Framework (component: Trace File Analyzer). Supported versions that are affec

8.5
CVE-2026-70807

Vulnerability in the Oracle Call Center Technology product of Oracle E-Business Suite (component: Internal Operations).

8.5
CVE-2026-70859

Vulnerability in the Siebel CRM Integration product of Oracle Siebel CRM (component: REST). Supported versions that are

8.5
CVE-2026-70885

Vulnerability in the Oracle Hyperion Data Relationship Management product of Oracle Hyperion (component: Access and secu

8.5
CVE-2026-71002

Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager product of Oracle Commerce (comp

8.5
CVE-2026-71049

Vulnerability in the Oracle Product Lifecycle Analytics product of Oracle Supply Chain (component: Installation Issues).

8.5
CVE-2026-71057

Vulnerability in the Oracle BI Publisher product of Oracle Analytics (component: BI Platform Security). Supported versi

8.5
CVE-2026-71062

Vulnerability in the RDBMS component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.3

8.5
CVE-2026-71155

Vulnerability in the Helidon product of Oracle Fusion Middleware (component: Imperative Web Server). Supported versions

8.5
CVE-2026-11565

The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file mana

8.5
CVE-2026-32552

Subscriber SQL Injection in YITH WooCommerce Membership Premium <= 2.33.0 versions.

8.5
CVE-2026-66668

Subscriber SQL Injection in Community by PeepSo <= 9.0.5.2 versions.

8.5
CVE-2026-68558

Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in m

8.5
CVE-2026-66594

Subscriber SQL Injection in WordPress Persistent Login <= 3.1.0 versions.

8.5
CVE-2026-73998

Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.

8.5
CVE-2026-74013

Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.

8.5
CVE-2026-17168

IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a remote authenticated attacker to execute arbitrary code due

8.5
CVE-2026-46682

BigBlueButton is an open-source virtual classroom. Prior to 3.0.23, BigBlueButton allowed authenticated moderators to in

8.5
CVE-2026-55765

CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.28.4 and

8.5
CVE-2026-69419

Integer overflow or wraparound in Azure Data Manager for Energy allows an authorized attacker to execute code over a net

8.5
CVE-2026-69543

Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a

8.5
CVE-2026-72860

The POST /api/provider-nodes/validate route in 9router takes a caller-supplied baseUrl and issues server-side HTTP reque

8.5
CVE-2026-22681

OpenViking before 0.3.4 contains a server-side request forgery vulnerability that allows authenticated low-privilege att

8.5
CVE-2026-10053

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.8 before 19.0.6, 19.1 before 19.1.4, and 1

8.5
CVE-2026-32471

Subscriber SQL Injection in ProLancer Element <= 1.4.8 versions.

8.5
CVE-2026-32478

Subscriber SQL Injection in WP Project Manager Pro <= 4.0.1 versions.

8.5
CVE-2026-76838

Hi.Events validates a webhook destination only when it is registered, never when it is used. NoInternalUrlRule in backen

8.5
CVE-2026-68062

SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an

8.5
CVE-2026-68959

SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an

8.5
CVE-2026-68960

A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is

8.5
CVE-2026-55526

PraisonAI is a multi-agent teams system. Prior to praisonaiagents 1.6.58, spider_tools._host_is_blocked() does not resol

8.5
CVE-2026-70551

A user who can read an existing remote VCS repository can replace its configured origin or supply an absolute VCS data U

8.5
CVE-2026-65092

NVIDIA OpenShell Sandbox for Linux contains a vulnerability where an attacker could cause a path traversal bypass of L7

8.5
CVE-2026-81027

one-api gates one of its two channel-pinning paths and not the other. middleware/auth.go permits a request to name a spe

8.5
CVE-2026-32550

Subscriber SQL Injection in Kadence Shop Kit <= 3.0.6 versions.

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started