Total CVEs

125,872

Critical Severity

2,276

High Severity

7,883

Last 7 Days

1,165
Quick preset (or use dates below)
Clear Filters
Showing 101 - 120 of 8,730 CVEs
CVE-2026-41658 MEDIUM - 6.5

Admidio's Missing Authorization on Inventory Module Destructive Endpoints Allows Any Authenticated User to Delete Items

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41657 MEDIUM - 4.9

Admidio Exposes Cross-Organization Member Data via Permission Check Mismatch in contacts_data.php

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41656 MEDIUM - 4.5

Admidio has Path Traversal via Unvalidated `name` Parameter in Document Add Mode that Enables Arbitrary Server File Read

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41655 MEDIUM - 6.5

Admidio has Path Traversal in ECard Preview that Allows Reading Arbitrary Server Files Including Database Credentials

Vendor: composer
Product: admidio/admidio
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42227 MEDIUM - 7.7

n8n has Public API Variables IDOR that Allows Cross-Project Secret Disclosure

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42228 MEDIUM - 5.4

n8n Vulnerable to Hijacking of Unauthenticated Chat Execution

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7408 MEDIUM - 4.7

A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this issue is the function save_menu of the file /admin/ajax.php?action=save_menu. Performing a manipulation results in sql injection. The attack can be initiated remotely. The exploit is now public and may be u...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7407 MEDIUM - 4.7

A security vulnerability has been detected in SourceCodester Pizzafy Ecommerce System 1.0. Affected by this vulnerability is the function save_settings of the file /pizzafy/admin/ajax.php?action=save_settings of the component Setting Handler. Such manipulation leads to sql injection. It is possible ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7403 MEDIUM - 5.3

A security flaw has been discovered in geldata gel-mcp 0.1.0. This impacts the function list_rules/fetch_rule of the file src/gel_mcp/server.py. The manipulation of the argument rule_name results in path traversal. The attack may be performed from remote. The exploit has been released to the public ...

Published: Apr 29, 2026
Source: NVD
CVE-2026-1858 MEDIUM - 4.8

wget2 accepts a server certificate with incorrect Key Usage (KU) or Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be able to reuse it for TLS server authentication.

Published: Apr 29, 2026
Source: NVD
CVE-2026-42229 MEDIUM - 6.8

n8n has SQL Injection in SeaTable Node

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42230 MEDIUM - 4.7

n8n has Open Redirect in MCP OAuth Consent Flow

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub

n8n has SQL Injection in Oracle Database Node via Limit Field

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42237 MEDIUM - 8.2

n8n has SQL Injection in Snowflake and MySQL Nodes

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub

OpenID Connect nonce generated but never validated โ€” ID token replay attack

Vendor: composer
Product: roadiz/openid
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41255 MEDIUM - 6.1

CKAN has CSRF exemption primed by anonymous requests

Vendor: pip
Product: ckan
Published: Apr 29, 2026
Source: GitHub

CKAN has no certificate validation on STMP connection

Vendor: pip
Product: ckan
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41484 MEDIUM - 5.3

OneCollector exporter reads unbounded HTTP response bodies

Vendor: nuget
Product: OpenTelemetry.Exporter.OneCollector
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7425 MEDIUM - 6.5

Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash) by sending a crafted Router Advertisement with a truncated PREFIX_INFORMATION option that is smalle...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7401 MEDIUM - 4.3

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the component Registration. The manipulation of the argument student_id/full_name/section/username results i...

Published: Apr 29, 2026
Source: NVD