Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 998/1152
4.3
CVE-2026-16254

A flaw was found in claircore's apk package scanner. Malformed package-database data in a container layer can cause an o

4.3
CVE-2026-63733

SurrealDB versions before 3.2.0 contain a permissions bypass vulnerability where data-modifying statements within PERMIS

4.3
CVE-2026-63738

SurrealDB versions 3.1.0 before 3.1.5 fail to enforce field-level SELECT permissions when records are accessed through g

4.3
CVE-2026-63742

SurrealDB versions before 3.1.0 contain a field-level SELECT permission bypass vulnerability in indexed COUNT fast paths

4.3
CVE-2026-63748

SurrealDB versions before 3.1.0 contain an information disclosure vulnerability where authenticated users with UPDATE ac

4.3
CVE-2026-63749

SurrealDB versions before 3.1.0 contain an authentication bypass vulnerability in LIVE SELECT subscriptions where permis

4.3
CVE-2026-63751

SurrealDB versions before 3.1.0 contain a field-level permission bypass vulnerability in JSON Patch operations that allo

4.3
CVE-2026-63752

SurrealDB before 3.1.0 contains an authorization bypass vulnerability in the RELATE statement that allows authenticated

4.3
CVE-2026-63753

SurrealDB before 3.1.0 fails to refresh authentication state in LIVE SELECT subscriptions when session state changes. At

4.3
CVE-2026-63761

SurrealDB before 3.1.0 silently substitutes the ES384 algorithm when a JWT access method is configured with ALGORITHM ES

4.3
CVE-2026-13724

Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry an

4.3
CVE-2026-32819

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

4.3
CVE-2026-32823

dataCycle is a data management system for centrally storing, managing, searching, finding, and distributing data. In dat

4.3
CVE-2026-63768

cal.diy through 6.2.0 contains an open redirect vulnerability in the conferencing OAuth callback endpoint that allows at

4.3
CVE-2026-44584

Paymenter is a free and open-source webshop solution for management of hosting services. In versions prior to 1.5.0, the

4.3
CVE-2026-16336

A vulnerability was found in trinodb trino 481. Affected is an unknown function of the file core/trino-main/src/main/jav

4.3
CVE-2026-3182

Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive

4.3
CVE-2026-14183

The Classified Listing WordPress plugin before 5.3.9 does not verify that the order targeted by its payment-receipt han

4.3
CVE-2026-14185

The WPBot WordPress plugin before 8.2.0 does not perform a capability or nonce check in one of its retrieval-augmented-

4.3
CVE-2026-1372

The Tutor LMS Elementor Addons plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and in

4.3
CVE-2026-65009

OpenRemote versions before 1.26.2 contain an information disclosure vulnerability in the SyslogResource REST endpoint th

4.3
CVE-2026-8285

Improper restriction of excessive authentication attempts vulnerability in Universal Software Inc. FlexCity allows Exces

4.3
CVE-2026-59850

A flaw was found in libssh. If data packets are processed after a channel is closed, channel data callbacks can be invok

4.3
CVE-2026-16450

A vulnerability was identified in zsadmin2025 ZS-Admin up to b52e14536d59fda11e56e2536a1c32e82a38cead. This affects the

4.3
CVE-2026-16454

In Eclipse hawkBit versions 1.0.3 and prior, a privilege escalation vulnerability (CWE-284 / CWE-862) has been identifie

4.3
CVE-2026-24232

NVIDIA Tranformers4Rec contains a vulnerability where an attacker could cause improper deserialization of untrusted data

4.3
CVE-2026-49092

Unintended Proxy or Intermediary ('Confused Deputy') (CWE-441) in Kibana can lead to unauthorized information exposure v

4.3
CVE-2026-63092

kirby-modules through 5.5.7, fixed in commit 315417e, contains an information disclosure vulnerability that allows any a

4.3
CVE-2026-64821

djangoSIGE through 1.10 (commit a6fe7e8) contains a cross-site request forgery vulnerability that allows unauthenticated

4.3
CVE-2026-10675

In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bluetooth/mesh/pb_adv.c), prov_msg_recv() rescheduled the

4.3
CVE-2026-21954

Vulnerability in the Oracle Retail Xstore Point of Service product of Oracle Retail Applications (component: Xstore Mobi

4.3
CVE-2026-46980

Vulnerability in the Oracle Utilities Network Management System product of Oracle Utilities Applications (component: Mob

4.3
CVE-2026-60233

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). The supported version tha

4.3
CVE-2026-60303

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

4.3
CVE-2026-60307

Vulnerability in the Oracle Coherence product of Oracle Fusion Middleware (component: Core). Supported versions that ar

4.3
CVE-2026-60395

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1

4.3
CVE-2026-60397

Vulnerability in Oracle GoldenGate (component: Admin Server Executable). Supported versions that are affected are 19.1.

4.3
CVE-2026-60408

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op

4.3
CVE-2026-60410

Vulnerability in the TimesTen In-Memory Database product of Oracle TimesTen In-Memory Database (component: Kubernetes Op

4.3
CVE-2026-60434

Vulnerability in the Oracle Transportation Management product of Oracle Supply Chain (component: Authentication). The

4.3
CVE-2026-61292

Vulnerability in the Oracle U.S. Federal Financials product of Oracle E-Business Suite (component: Internal Operations).

4.3
CVE-2026-61315

Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that ar

4.3
CVE-2026-61316

Vulnerability in the Oracle EDI Gateway product of Oracle E-Business Suite (component: EDI). Supported versions that ar

4.3
CVE-2026-62483

Vulnerability in the Oracle Project Contracts product of Oracle E-Business Suite (component: Internal Operations). Supp

4.3
CVE-2026-65314

Electric Postgres Sync versions below 1.6.10 contains an information disclosure vulnerability that allows attackers to i

4.3
CVE-2026-16485

A vulnerability has been found in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some u

4.3
CVE-2026-16486

A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the f

4.3
CVE-2026-63143

Missing Authorization (CWE-862) in Kibana can lead to unauthorized information disclosure via Privilege Abuse (CAPEC-122

4.3
CVE-2026-63145

Incorrect Authorization (CWE-863) in Kibana can lead to integrity compromise of Machine Learning audit and notification

4.3
CVE-2026-63259

Authorization Bypass Through User-Controlled Key (CWE-639) in Kibana can lead to information disclosure via user-supplie

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started