Total CVEs

138,728

Critical Severity

3,597

High Severity

12,893

Last 7 Days

1,623
Quick preset (or use dates below)
Clear Filters
Showing 2,921 - 2,940 of 3,597 CVEs
CVE-2026-25538 CRITICAL - 8.8

Devtron is an open source tool integration platform for Kubernetes. In version 2.0.0 and prior, a vulnerability exists in Devtron's Attributes API interface, allowing any authenticated user (including low-privileged CI/CD Developers) to obtain the global API Token signing key by accessing the /...

Vendor: go
Product: github.com/devtron-labs/devtron
Published: Feb 04, 2026
Source: GitHub
CVE-2026-25160 CRITICAL - 9.1

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certificate verification by default for all outgoing storage driver communications, making the system vulnerable to Man-in-the-Middle (MitM) attacks. This e...

Vendor: go
Product: github.com/alist-org/alist/v3
Published: Feb 04, 2026
Source: GitHub

n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8nโ€™s community package installation functionality. The issue allowed authenticated users with administrative permissions to execute arbitrary system comman...

Vendor: n8n-io
Product: n8n
Published: Feb 04, 2026
Source: NVD
CVE-2026-25115 CRITICAL - 9.9

n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environment and execute code outside the intended security boundary. This issue has been patched in version 2.4.8.

Vendor: n8n-io
Product: n8n
Published: Feb 04, 2026
Source: NVD
CVE-2026-25056 CRITICAL - 8.8

n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to create or modify workflows to write arbitrary files to the n8n server's filesystem potentially leading ...

Vendor: n8n-io
Product: n8n
Published: Feb 04, 2026
Source: NVD
CVE-2026-25053 CRITICAL - 9.9

n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to execute arbitrary system commands or read arbitrary files on the n8n host. This issue has been patche...

Vendor: n8n-io
Product: n8n
Published: Feb 04, 2026
Source: NVD
CVE-2026-25052 CRITICAL - 9.9

n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenticated users with permission to create or modify workflows to read sensitive files from the n8n host system. This can be exploited to obtain critical co...

Vendor: n8n-io
Product: n8n
Published: Feb 04, 2026
Source: NVD
CVE-2026-25049 CRITICAL - 9.9

n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended system command execution on the host running n8n. This issue has ...

Vendor: n8n-io
Product: n8n
Published: Feb 04, 2026
Source: NVD
CVE-2025-5329 CRITICAL - 9.8

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation allows SQL Injection.This issue affects Delta Course Automation: through 04022026. NOTE: The vendor was contacted early about this disclosur...

Published: Feb 04, 2026
Source: NVD
CVE-2025-59818 CRITICAL - 10.0

This vulnerability allows authenticated attackers to execute arbitrary commands on the underlying system using the file name of an uploaded file.

Vendor: Zenitel
Product: TCIS-3+
Published: Feb 04, 2026
Source: NVD
CVE-2026-1633 CRITICAL - 10.0

The Synectix LAN 232 TRIO 3-Port serial to ethernet adapter exposes its web management interface without requiring authentication, allowing unauthenticated users to modify critical device settings or factory reset the device.

Published: Feb 04, 2026
Source: NVD

Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users can crash the Navidrome server by supplying an excessively large size parameter to /rest/getCoverArt or to a shared-image URL (/share/img/<token>). When processing such requ...

Vendor: go
Product: github.com/navidrome/navidrome
Published: Feb 04, 2026
Source: GitHub
CVE-2026-1632 CRITICAL - 9.1

MOMA Seismic Station Version v2.4.2520 and prior exposes its web management interface without requiring authentication, which could allow an unauthenticated attacker to modify configuration settings, acquire device data or remotely reset the device.

Published: Feb 03, 2026
Source: NVD
CVE-2026-25150 CRITICAL - 9.3

Qwik is a performance focused javascript framework. Prior to version 1.19.0, a prototype pollution vulnerability exists in the formToObj() function within @builder.io/qwik-city middleware. The function processes form field names with dot notation (e.g., user.name) to create nested objects, but fails...

Vendor: QwikDev
Product: qwik
Published: Feb 03, 2026
Source: NVD
CVE-2020-37094 CRITICAL - 9.8

EspoCRM 5.8.5 contains an authentication vulnerability that allows attackers to access other user accounts by manipulating authorization headers. Attackers can decode and modify Basic Authorization and Espo-Authorization tokens to gain unauthorized access to administrative user information and privi...

Vendor: EspoCRM
Product: EspoCRM
Published: Feb 03, 2026
Source: NVD
CVE-2020-37090 CRITICAL - 9.8

School ERP Pro 1.0 contains a file upload vulnerability that allows students to upload arbitrary PHP files to the messaging system. Attackers can upload malicious PHP scripts through the message attachment feature, enabling remote code execution on the server.

Vendor: Arox
Product: School ERP Pro
Published: Feb 03, 2026
Source: NVD
CVE-2020-37082 CRITICAL - 9.8

webERP 4.15.1 contains an unauthenticated file access vulnerability that allows remote attackers to download database backup files without authentication. Attackers can directly access generated backup files in the companies/weberp/ directory by requesting the Backup_[timestamp].sql.gz file.

Vendor: Weberp
Product: webERP
Published: Feb 03, 2026
Source: NVD
CVE-2020-37080 CRITICAL - 9.8

webTareas 2.0.p8 contains a file deletion vulnerability in the print_layout.php administration component that allows authenticated attackers to delete arbitrary files. Attackers can exploit the vulnerability by manipulating the 'atttmp1' parameter to specify and delete files on the server ...

Vendor: luiswang
Product: webTareas
Published: Feb 03, 2026
Source: NVD
CVE-2020-37075 CRITICAL - 9.8

LanSend 3.2 contains a buffer overflow vulnerability in the Add Computers Wizard file import functionality that allows remote attackers to execute arbitrary code. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) overwrite and execute shellcode when importi...

Vendor: LizardSystems
Product: LanSend
Published: Feb 03, 2026
Source: NVD
CVE-2020-37074 CRITICAL - 9.8

Remote Desktop Audit 2.3.0.157 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code during the Add Computers Wizard file import process. Attackers can craft a malicious payload file to trigger a structured exception handler (SEH) bypass and execute shellcode when ...

Vendor: LizardSystems
Product: Remote Desktop Audit
Published: Feb 03, 2026
Source: NVD