Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

21,780 of 57,566 · Page 96/436
6.5
CVE-2026-68967

Bendix EC80 Brake ECU is vulnerable to an out-of-bounds write, which could allow an attacker to deliver a payload that

6.5
CVE-2026-61802

Wazuh is an open-source security platform providing unified XDR and SIEM protection for endpoints and cloud workloads. I

6.5
CVE-2026-16759

The Tutor LMS – eLearning and online course solution plugin for WordPress is vulnerable to Remote Code Execution limited

6.5
CVE-2026-82123

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tangible Loops & L

6.5
CVE-2026-9548

An improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in extract domain

6.5
CVE-2026-40014

An attacker that can send mail to a user can craft a message header that makes the IMAP THREAD command consume CPU dispr

6.5
CVE-2026-40017

An attacker that can send mail to a user can craft a message header whose values are chosen to collide in an internal ha

6.5
CVE-2026-52687

An attacker that has valid credentials can select a compression algorithm for the IMAP connection whose decompression st

6.5
CVE-2026-73209

An attacker that has valid credentials can send crafted compressed data that causes the affected process to exhaust its

6.5
CVE-2026-82250

gitoxide gix-packetline versions before 0.21.5 contain a panic vulnerability in the TextRef implementation that occurs w

6.5
CVE-2026-81341

wolfEngine before 1.4.1 sources the explicit AES-CCM nonce for TLS 1.2 and DTLS 1.2 records from the record input buffer

6.5
CVE-2026-55545

Yamcs is a mission control framework. Prior to 5.12.8 and 5.13.2, Yamcs WebSocket subscription handlers fail to enforce

6.5
CVE-2026-55549

Yamcs is a mission control framework. Prior to 5.9.4, Yamcs reflects an attacker-controlled redirect_uri parameter from

6.5
CVE-2026-66324

External control of file name or path in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoo

6.5
CVE-2026-77939

Flextype CMS through v1.0.0-dev contains an expression language injection vulnerability that allows authenticated attack

6.5
CVE-2026-82265

Zipkin through 3.6.1 exposes Spring Boot Actuator endpoints on the tracing API port without authentication, allowing una

6.5
CVE-2026-82271

R2R through 3.6.5 fails to properly validate user ownership in conversation update and message handlers, allowing authen

6.5
CVE-2026-82272

Immich through 3.1.0 fails to properly enforce locked asset visibility when assets are locked through the single-asset e

6.5
CVE-2026-82273

Mastra through 1.63.0 contains an authentication bypass vulnerability in the memory API thread ownership validation when

6.5
CVE-2026-82306

StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfi

6.5
CVE-2026-13734

Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c vali

6.5
CVE-2026-55855

MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to

6.5
CVE-2026-18233

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by one of its delivery endpoints

6.5
CVE-2026-18234

The MStore API WordPress plugin before 4.21.1 does not verify that the order targeted by its wallet payment handling be

6.5
CVE-2026-77008

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not have any authorisation or

6.5
CVE-2026-77010

The HEL Online Classroom: AI-powered Online Classrooms WordPress plugin through 1.0.3 does not perform authorisation che

6.5
CVE-2026-82462

pac4j-oidc before 6.5.6 accepts OIDC callbacks carrying only an access token without authorization code or ID token vali

6.5
CVE-2026-82634

Frappe Framework development builds contain an authorization flaw in the render_jinja_template endpoint that allows low-

6.5
CVE-2026-82547

A vulnerability was found in Linux Foundation Magma 1.9.0. The affected element is an unknown function of the file tasks

6.5
CVE-2026-82643

WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php tha

6.4
CVE-2025-14627

The WP Import – Ultimate CSV XML Importer for WordPress plugin for WordPress is vulnerable to Server-Side Request Forger

6.4
CVE-2025-13746

The ForumWP – Forum & Discussion Board plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the User's

6.4
CVE-2025-14120

The URL Image Importer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all ver

6.4
CVE-2025-14438

The Xagio SEO – AI Powered SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to,

6.4
CVE-2025-4776

The Phlox theme for WordPress is vulnerable to Stored Cross-Site Scripting via the `data-caption` HTML attribute in all

6.4
CVE-2025-12067

The Table Field Add-on for ACF and SCF plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Table C

6.4
CVE-2025-14552

The MediaPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's mpp-uploader shortcode

6.4
CVE-2025-46696

Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application, version(s) versions 5.26 to 5.30, contain(s) an Executi

6.4
CVE-2025-0980

Nokia SR Linux is vulnerable to an authentication vulnerability allowing unauthorized access to the JSON-RPC service. W

6.4
CVE-2025-13418

The Responsive Pricing Table plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'plan_icons' para

6.4
CVE-2025-13497

The Recras WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'recrasname' shortcode at

6.4
CVE-2025-13531

The Stylish Order Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'product_name'

6.4
CVE-2025-13667

The WP Recipe Manager plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Skill Level' input fiel

6.4
CVE-2025-13841

The Smart App Banners plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'size' and 'verticalalig

6.4
CVE-2025-13847

The PhotoFade plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'time' parameter in all versions

6.4
CVE-2025-13848

The STM Gallery 1.9 plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'composicion' parameter in

6.4
CVE-2025-13849

The Cool YT Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'videoid' parameter in all

6.4
CVE-2025-13887

The AI BotKit – AI Chatbot & Live Support for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scriptin

6.4
CVE-2025-14053

The Wish To Go plugin for WordPress is vulnerable to Stored Cross-Site Scripting via shortcode attributes in all version

6.4
CVE-2025-14109

The AH Shortcodes plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'column' shortcode attribute

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started