Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 999/1152
4.3
CVE-2026-63262

Missing Authorization (CWE-862) in Kibana can lead to unauthorized cross-space information disclosure via user-supplied

4.3
CVE-2026-16473

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted aud

4.3
CVE-2026-65011

Graylog2 Server before commit 46a2eeb contains a missing per-entity permission check in the POST /events/definitions/{de

4.3
CVE-2026-65650

Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload.

4.3
CVE-2026-13061

An authenticated user may be able to view session metadata belonging to other users on the system through the $listSessi

4.3
CVE-2026-13063

An authenticated user with standard read/write privileges can cause the mongod process to terminate due to an out-of-mem

4.3
CVE-2026-13073

An authenticated user with read-only privileges can cause the mongod process to terminate abnormally by issuing a crafte

4.3
CVE-2026-24537

Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility Helper (WAH) <= 0.6.6 versions.

4.3
CVE-2026-25424

Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions.

4.3
CVE-2026-27392

Contributor Broken Access Control in uListing <= 2.2.0 versions.

4.3
CVE-2026-27423

Subscriber Broken Access Control in Participants Database <= 2.7.8.4 versions.

4.3
CVE-2026-61973

Subscriber Broken Access Control in ShopLentor Pro <= 2.8.5 versions.

4.3
CVE-2026-64810

In JetBrains IntelliJ IDEA before 2026.2 hTML injection was possible in an IDE notification, allowing silent user activi

4.3
CVE-2026-65456

Contributor Insecure Direct Object References (IDOR) in Product Slider for WooCommerce <= 1.13.62 versions.

4.3
CVE-2026-65457

Subscriber Broken Access Control in ЮKassa для WooCommerce <= 2.16.1 versions.

4.3
CVE-2026-65458

Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Chouby Polylang and Chouby P

4.3
CVE-2026-65460

Unauthenticated Cross Site Request Forgery (CSRF) in Zarinpal Gateway <= 5.1.0 versions.

4.3
CVE-2026-65491

Subscriber Broken Access Control in Query Wrangler <= 1.5.57 versions.

4.3
CVE-2026-65524

Contributor Broken Access Control in Avada Custom Branding <= 1.2 versions.

4.3
CVE-2026-65530

Subscriber Broken Access Control in TemplateSpare <= 4.2.2 versions.

4.3
CVE-2026-65535

Contributor Sensitive Data Exposure in TinyMCE Templates <= 4.8.1 versions.

4.3
CVE-2026-65537

Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.

4.3
CVE-2026-8287

Allocation of resources without limits or throttling vulnerability in BizimHesap Information Systems Industry and Trade

4.3
CVE-2026-65920

Diffusers through 0.39.0, fixed in commit cee298c, contains a path traversal vulnerability in the _get_checkpoint_shard_

4.3
CVE-2026-48012

Shopware is an open commerce platform. Versions 6.7.3.0 through 6.7.10.0 have an open redirect in Shopware's public SSO

4.3
CVE-2026-15420

The Nexter Blocks – Gutenberg Blocks, Page Builder & AI Website Builder plugin for WordPress is vulnerable to Directory

4.3
CVE-2026-55985

The web management interface in  Tycon Systems TPDIN-Monitor-WEB2 stores and displays system credentials in cleartext o

4.3
CVE-2026-17457

A vulnerability has been found in mf-yang openclaw-cn up to 0.2.1. Affected by this issue is the function assertBrowserN

4.3
CVE-2026-17459

A vulnerability was determined in perwendel spark up to 2.9.4. This vulnerability affects the function staticFiles.exter

4.3
CVE-2026-10600

Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6.5, 10.11.x <= 10.11.20 fail to bound the time and

4.3
CVE-2026-66428

Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review Slider <= 18.4 versions.

4.3
CVE-2026-66474

Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers and Footers Code – HT Script <= 1.1.8 versions.

4.3
CVE-2026-17569

Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only per

4.3
CVE-2026-17570

Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileg

4.3
CVE-2026-59728

Astro is a web framework for content-driven websites. In versions 1.0.0 through 4.0.18, the source.title and enclosure.t

4.3
CVE-2026-15136

The Cookie Banner for GDPR / CCPA – WPLP Cookie Consent plugin for WordPress is vulnerable to Cross-Site Request Forgery

4.3
CVE-2026-16587

The Advanced Form Integration — Connect Forms to 200+ Apps plugin for WordPress is vulnerable to authorization bypass in

4.3
CVE-2026-16797

The ShopLentor – All-in-One WooCommerce Growth & Store Enhancement Plugin plugin for WordPress is vulnerable to Insecure

4.3
CVE-2026-58246

SAP NetWeaver Application Server for ABAP and ABAP Platform writes sensitive session identifier information into a diagn

4.3
CVE-2026-18038

A flaw has been found in nextlevelbuilder GoClaw up to 3.13.2. Affected by this vulnerability is the function ExecTool.E

4.3
CVE-2026-66750

Let's Chat 0.3.0 through 0.4.8 contains a broken access control vulnerability that allows authenticated attackers to dow

4.3
CVE-2026-7362

IBM Sterling B2B Integrator 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM Sterling File Gateway 6.2.1

4.3
CVE-2026-3157

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM

4.3
CVE-2026-3158

IBM Sterling B2B Integrator 6.2.0.0 through 6.2.0.5_2, 6.2.1.0 through 6.2.1.1_2, and 6.2.2.0 through 6.2.2.0_1 and IBM

4.3
CVE-2026-17166

The Event Booking Manager for WooCommerce – Sell Tickets, Event Registration, RSVP & Event Calendar plugin for WordPress

4.3
CVE-2026-5626

The Survey Form Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability chec

4.3
CVE-2026-63240

An information disclosure vulnerability in Koollab LMS allowed an authenticated learner to obtain correct quiz answers f

4.3
CVE-2026-63242

A business logic vulnerability in Koollab LMS allowed an authenticated learner to set their lesson completion status to

4.3
CVE-2026-9720

The Facturación Electrónica Costa Rica plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions

4.3
CVE-2026-14351

GitLab has remediated an issue in GitLab CE/EE affecting all versions from 8.8 before 19.0.5, 19.1 before 19.1.3, and 19

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started