Total CVEs

140,356

Critical Severity

3,747

High Severity

13,524

Last 7 Days

1,771
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 10,941 - 10,960 of 36,761 CVEs
CVE-2026-45732 HIGH - 8.1

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints authorized access using credential:read rather than credential:update. An authenticated user with read-only access to a shared credential could initiate an ...

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub
CVE-2026-44792 HIGH - 9.0

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator perfor...

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub
CVE-2026-44791 CRITICAL - 9.9

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the patch for CVE-2026-42232 in the XML node. When combined with other nodes, this could lead to RCE on the n8n host. This vulne...

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub
CVE-2026-44790 CRITICAL - 8.8

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation allowing an attacker to read arbitrary files from the n8n server potentially lea...

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub
CVE-2026-44789 CRITICAL - 9.9

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node. Combined with other techniques thi...

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub
CVE-2026-44722 MEDIUM - 6.2

pyzipper has an encryption bypass for small files encrypted using it

Vendor: pip
Product: pyzipper
Published: May 14, 2026
Source: GitHub
CVE-2026-43978 HIGH - 8.1

wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager

Vendor: pip
Product: wger
Published: May 14, 2026
Source: GitHub
CVE-2026-44501 MEDIUM - 4.3

DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the OIDC callback flow, with no integrity protection (no HMAC, no encryption). This is a Deserialization...

Vendor: datahub-project
Product: datahub
Published: May 14, 2026
Source: NVD
CVE-2026-43977 HIGH - 7.5

wger Vulnerable to IDOR: Authenticated Users Can Read Any User's Private Workout Session Data via Template Routine API

Vendor: pip
Product: wger
Published: May 14, 2026
Source: GitHub
CVE-2026-42159 MEDIUM - 5.4

Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of...

Vendor: reconurge
Product: flowsint
Published: May 14, 2026
Source: NVD
CVE-2026-42853 MEDIUM - 6.5

ApostropheCMS is an open-source Node.js content management system. Versions of the @apostrophecms/cli package up to and including 3.6.0 contain a command injection vulnerability in the apos create command. User-supplied input from the password prompt is embedded directly into a shell command without...

Vendor: npm
Product: @apostrophecms/cli
Published: May 14, 2026
Source: GitHub
CVE-2026-44482 CRITICAL - 9.6

soundcloud-rpc is a SoundCloud Client with Discord Rich Presence, Dark Mode, Last.fm and AdBlock support. Prior to 0.1.8, a track title containing an HTML payload executed locally in the Electron app. This means attacker-controlled SoundCloud track metadata can lead to local command execution on the...

Vendor: richardhbtz
Product: soundcloud-rpc
Published: May 14, 2026
Source: NVD

Open OnDemand is an open-source high-performance computing portal. Prior to 4.0.11, 4.1.5, and 4.2.2, specially crafted filenames can execute javascript in the file browser This vulnerability is fixed in 4.0.11, 4.1.5, and 4.2.2.

Vendor: OSC
Product: ondemand
Published: May 14, 2026
Source: NVD

STIGQter is an open-source reimplementation of DISA's STIG Viewer. From 0.1.2 to before 1.2.7, an attacker can achieve local code execution (LCE) with the privileges of the user running STIGQter. This requires user interaction: the victim must open the malicious .stigqter file and explicitly ru...

Vendor: squinky86
Product: STIGQter
Published: May 14, 2026
Source: NVD
CVE-2026-42457 CRITICAL - 9.0

vCluster Platform provides a Kubernetes platform for managing virtual clusters, multi-tenancy, and cluster sharing. Prior to 4.4.3, 4.5.5, 4.6.2, 4.7.1, and 4.8.0, there is a Stored XSS attack vulnerability via the name field of a templateRef. This can lead to the execution of arbitrary external scr...

Vendor: loft-sh
Product: loft
Published: May 14, 2026
Source: NVD
CVE-2026-41937 HIGH - 7.2

Vvveb before 1.0.8.3 contains an unrestricted file upload vulnerability in the plugin upload endpoint that allows super_admin users to execute arbitrary PHP code by uploading a malicious plugin ZIP file. Attackers can craft a ZIP containing a plugin.php with a valid Slug header and a public/index.ph...

Vendor: givanz
Product: Vvveb
Published: May 14, 2026
Source: NVD
CVE-2026-41935 HIGH - 7.1

Vvveb before 1.0.8.3 contains an uncontrolled recursion vulnerability in the admin controller dispatch cycle where Base::init() repeatedly invokes permission() on error handlers, causing infinite recursion until PHP memory limits are exhausted. Attackers can send sustained requests to forbidden admi...

Vendor: givanz
Product: Vvveb
Published: May 14, 2026
Source: NVD
CVE-2026-41933 MEDIUM - 5.3

Vvveb before 1.0.8.3 contains a directory listing information disclosure vulnerability that allows unauthenticated attackers to enumerate files and directories by accessing multiple paths lacking proper index directives in .htaccess files. Attackers can access directories such as admin asset paths, ...

Vendor: givanz
Product: Vvveb
Published: May 14, 2026
Source: NVD
CVE-2026-41932 MEDIUM - 6.1

Vvveb before 1.0.8.3 contains a stored cross-site scripting vulnerability in the customer signup flow where the Signup::addUser() controller copies raw POST username values into the display_name field before sanitization occurs. Attackers can submit HTML and script markup in the username field durin...

Vendor: givanz
Product: Vvveb
Published: May 14, 2026
Source: NVD
CVE-2026-24712 HIGH - 7.3

Northern.tech CFEngine Enterprise and Community before 3.21.8, 3.24.3, and 3.27.0 allows Command injection.

Vendor: northern.tech
Product: cfengine
Published: May 14, 2026
Source: NVD