Total CVEs

133,082

Critical Severity

2,916

High Severity

10,594

Last 7 Days

2,044
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 3,661 - 3,680 of 29,487 CVEs

FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: Vector Store No Permission Checks

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full history to paginating clients. Clients could therefore fail to display room history. This vulnerabilit...

Vendor: pip
Product: matrix-synapse
Published: May 14, 2026
Source: GitHub

Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing other users to be denied service. This vulnerability is fixed in 1.152.1.

Vendor: pip
Product: matrix-synapse
Published: May 14, 2026
Source: GitHub

n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n Has a Source Control Pull SQL Injection

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n Has an XML Node Prototype Pollution Patch Bypass

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n Has an Arbitrary File Read via Git Node

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n: HTTP Request Node Pagination Prototype Pollution to RCE

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub
CVE-2026-44722 MEDIUM - 6.2

pyzipper has an encryption bypass for small files encrypted using it

Vendor: pip
Product: pyzipper
Published: May 14, 2026
Source: GitHub
CVE-2026-43978 HIGH - 8.1

wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager

Vendor: pip
Product: wger
Published: May 14, 2026
Source: GitHub
CVE-2026-44501 MEDIUM - 4.3

DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This is a Deserialization...

Vendor: datahub-project
Product: datahub
Published: May 14, 2026
Source: NVD
CVE-2026-43977 HIGH - 7.5

wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API

Vendor: pip
Product: wger
Published: May 14, 2026
Source: GitHub
CVE-2026-42159 MEDIUM - 5.4

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of...

Vendor: reconurge
Product: flowsint
Published: May 14, 2026
Source: NVD
CVE-2026-42853 MEDIUM - 6.5

@apostrophecms/cli: Command Injection in apos create via Unsanitized Password Input

Vendor: npm
Product: @apostrophecms/cli
Published: May 14, 2026
Source: GitHub
CVE-2026-44482 CRITICAL - 9.6

soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an HTML payload executed locally in the Electron app. This means attacker-controlled SoundCloud track metadata can lead to local command execution on the...

Vendor: richardhbtz
Product: soundcloud-rpc
Published: May 14, 2026
Source: NVD

Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted filenames can execute javascript in the file browser This vulnerability is fixed in 4.0.11, 4.1.5, and 4.2.2.

Vendor: OSC
Product: ondemand
Published: May 14, 2026
Source: NVD

STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve local code execution (LCE) with the privileges of the user running STIGQter. This requires user interaction: the victim must open the malicious .stigqter file and explicitly ru...

Vendor: squinky86
Product: STIGQter
Published: May 14, 2026
Source: NVD