Total CVEs

125,674

Critical Severity

2,261

High Severity

7,825

Last 7 Days

1,174
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 21 - 40 of 22,079 CVEs
CVE-2026-41671 MEDIUM - 6.8

Admidio: OIDC Token Introspection Endpoint Returns Active for All Tokens Without Validation

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41670 HIGH - 8.2

Admidio Sends SAML Response to Unvalidated Assertion Consumer Service URL from AuthnRequest

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41669 HIGH - 8.2

Admidio Ignores SAML Signature Validation Result, Processes Forged AuthnRequests and LogoutRequests

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub

Admidio has CSRF on Admin Preferences that Triggers Unauthorized Backup, .htaccess Write, and Email Send

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41662 MEDIUM - 5.2

Admidio Missing Minimum Administrator Check in Role Membership Removal

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41661 MEDIUM - 6.1

Admidio vulnerable to reflected XSS in msg_window.php via Square Bracket to HTML Tag Conversion

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41660 HIGH - 7.1

Admidio has Inverted 2FA Reset Authorization Check that Lets Group Leaders Strip Admin TOTP

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub

Admidio Leaks Hidden Profile Field Values via Blind Search Oracle in Member Assignment

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41658 MEDIUM - 6.5

Admidio's Missing Authorization on Inventory Module Destructive Endpoints Allows Any Authenticated User to Delete Items

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41657 MEDIUM - 4.9

Admidio Exposes Cross-Organization Member Data via Permission Check Mismatch in contacts_data.php

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41656 MEDIUM - 4.5

Admidio has Path Traversal via Unvalidated `name` Parameter in Document Add Mode that Enables Arbitrary Server File Read

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41655 MEDIUM - 6.5

Admidio has Path Traversal in ECard Preview that Allows Reading Arbitrary Server Files Including Database Credentials

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42232 CRITICAL - 10.0

n8n has XML Node Prototype Pollution that to RCE

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42231 CRITICAL - 10.0

n8n has Prototype Pollution in XML Webhook Body Parser that Leads to RCE

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42235 HIGH - 8.2

n8n Vulnerable to XSS via MCP OAuth client

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42226 HIGH - 8.5

n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42234 HIGH - 7.5

n8n has a Python Task Runner Sandbox Escape Vulnerability

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42227 MEDIUM - 7.7

n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub

n8n Vulnerable to Unauthenticated Denial of Service via MCP Client Registration

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42228 MEDIUM - 5.4

n8n Vulnerable to Hijacking of Unauthenticated Chat Execution

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub