Total CVEs

132,176

Critical Severity

2,835

High Severity

10,141

Last 7 Days

1,644
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,761 - 2,780 of 28,581 CVEs

n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n Has a Source Control Pull SQL Injection

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n Has an XML Node Prototype Pollution Patch Bypass

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n Has an Arbitrary File Read via Git Node

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n: HTTP Request Node Pagination Prototype Pollution to RCE

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub
CVE-2026-44722 MEDIUM - 6.2

pyzipper has an encryption bypass for small files encrypted using it

Vendor: pip
Product: pyzipper
Published: May 14, 2026
Source: GitHub
CVE-2026-43978 HIGH - 8.1

wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager

Vendor: pip
Product: wger
Published: May 14, 2026
Source: GitHub
CVE-2026-44501 MEDIUM - 4.3

DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This is a Deserialization...

Vendor: datahub-project
Product: datahub
Published: May 14, 2026
Source: NVD
CVE-2026-43977 HIGH - 7.5

wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API

Vendor: pip
Product: wger
Published: May 14, 2026
Source: GitHub
CVE-2026-42159 MEDIUM - 5.4

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of...

Vendor: reconurge
Product: flowsint
Published: May 14, 2026
Source: NVD
CVE-2026-42853 MEDIUM - 6.5

@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input

Vendor: npm
Product: @apostrophecms/cli
Published: May 14, 2026
Source: GitHub
CVE-2026-44482 CRITICAL - 9.6

soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an HTML payload executed locally in the Electron app. This means attacker-controlled SoundCloud track metadata can lead to local command execution on the...

Vendor: richardhbtz
Product: soundcloud-rpc
Published: May 14, 2026
Source: NVD

Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted filenames can execute javascript in the file browser This vulnerability is fixed in 4.0.11, 4.1.5, and 4.2.2.

Vendor: OSC
Product: ondemand
Published: May 14, 2026
Source: NVD

STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve local code execution (LCE) with the privileges of the user running STIGQter. This requires user interaction: the victim must open the malicious .stigqter file and explicitly ru...

Vendor: squinky86
Product: STIGQter
Published: May 14, 2026
Source: NVD
CVE-2026-42457 CRITICAL - 9.0

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name field of a templateRef. This can lead to the execution of arbitrary external scr...

Vendor: loft-sh
Product: loft
Published: May 14, 2026
Source: NVD
CVE-2026-41937 HIGH - 7.2

Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_admin users to execute arbitrary PHP code by uploading a malicious plugin ZIP file. Attackers can craft a ZIP containing a plugin.php with a valid Slug header and a public/index.ph...

Vendor: givanz
Product: Vvveb
Published: May 14, 2026
Source: NVD
CVE-2026-41935 HIGH - 7.1

Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where Base::init() repeatedly invokes permission() on error handlers, causing infinite recursion until PHP memory limits are exhausted. Attackers can send sustained requests to forbidden admi...

Vendor: givanz
Product: Vvveb
Published: May 14, 2026
Source: NVD
CVE-2026-41933 MEDIUM - 5.3

Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attackers to enumerate files and directories by accessing multiple paths lacking proper index directives in .htaccess files. Attackers can access directories such as admin asset paths, ...

Vendor: givanz
Product: Vvveb
Published: May 14, 2026
Source: NVD
CVE-2026-41932 MEDIUM - 6.1

Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::addUser() controller copies raw POST username values into the display_name field before sanitization occurs. Attackers can submit HTML and script markup in the username field durin...

Vendor: givanz
Product: Vvveb
Published: May 14, 2026
Source: NVD
CVE-2026-24712 HIGH - 7.3

Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.

Vendor: northern.tech
Product: cfengine
Published: May 14, 2026
Source: NVD