Total CVEs

142,027

Critical Severity

3,943

High Severity

14,108

Last 7 Days

1,693
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 16,401 - 16,420 of 38,432 CVEs
CVE-2026-42230 MEDIUM - 4.7

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /mcp-oauth/register endpoint accepted OAuth client registrations without authentication, allowing arbitrary redirect_uri values to be registered. When a user denies the MCP OAuth consent dialog, t...

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42233 MEDIUM - 9.8

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the Limit field via expressions to be interpolated directly into the SQL query without sanitization...

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42237 MEDIUM - 8.2

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the fix for GHSA-f3f2-mcxc-pwjx did not cover the Snowflake node or the legacy MySQL v1 node. Both nodes construct SQL queries by directly interpolating user-controlled table names, column names, and ...

Vendor: npm
Product: n8n
Published: Apr 29, 2026
Source: GitHub
CVE-2026-42224 HIGH - 7.7

ipl/web is a set of common web components for php projects. Prior to version 0.13.1, the vulnerability allows an attacker to inject malicious Javascript into a victim's browser to run it in the context of Icinga Web. The victim needs to visit a specifically prepared website and may have no imme...

Vendor: composer
Product: ipl/web
Published: Apr 29, 2026
Source: GitHub

Roadiz is a polymorphic content management system based on a node system. Prior to versions 2.3.43, 2.5.45, 2.6.31, and 2.7.18, the roadiz/openid package generates an OIDC nonce in OAuth2LinkGenerator::generate() and includes it in the authorization request sent to the identity provider, but never s...

Vendor: composer
Product: roadiz/openid
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41643 HIGH - 7.5

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. Prior to version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP where a malformed BGP UPDATE message can trigger a runtime error: index out of range panic. This occurs during t...

Vendor: go
Product: github.com/osrg/gobgp/v4
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41642 HIGH - 7.5

GoBGP is an open source Border Gateway Protocol (BGP) implementation in the Go Programming Language. In version 4.3.0, a remote Denial of Service (DoS) vulnerability exists in GoBGP due to a nil pointer dereference. When a malformed BGP UPDATE message contains an unrecognized Path Attribute marked a...

Vendor: go
Product: github.com/osrg/gobgp/v4
Published: Apr 29, 2026
Source: GitHub

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0.0 to before version 0.31.7.0, a theme upload feature allows any authenticated backend user with theme-upload permission to achieve remote ...

Vendor: composer
Product: ci4-cms-erp/ci4ms
Published: Apr 29, 2026
Source: GitHub

Hyperledger Fabric is an enterprise-grade permissioned distributed ledger framework for developing solutions and applications. From versions 1.0.0 to 2.2.26, Channel.java implements readObject() and exposes deSerializeChannel() which call ObjectInputStream.readObject() on untrusted byte arrays witho...

Vendor: maven
Product: org.hyperledger.fabric-sdk-java:fabric-sdk-java
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41255 MEDIUM - 6.1

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, Access to the views via tokens or unauthenticated requests marked the endpoint as not requiring CSRF protection. The marking was a member variable in flask-wtf.csrf.CSRFProtect()...

Vendor: pip
Product: ckan
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41132 MEDIUM - 7.4

CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, the configured SMTP server may be spoofed with any certificate (e.g. self-signed), leaving credentials and all emails sent open to MITM attacks. This vulnerability is fixed in 2....

Vendor: pip
Product: ckan
Published: Apr 29, 2026
Source: GitHub
CVE-2026-40902 HIGH - 7.5

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the XLSX reader's ColumnAndRowAttributes::readRowAttributes() method reads row numbers from XML attributes without validating them against the spreadsheet maximum r...

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub
CVE-2026-40863 HIGH - 7.5

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML XML reader (Reader\Xml) does not validate the ss:Index row attribute against the maximum allowed row count (AddressRange::MAX_ROW = 1,048,576). An atta...

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub
CVE-2026-34084 HIGH - 9.8

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when the filename argument to IOFactory::load() is user-controlled, an attacker can supply a PHP stream wra...

Vendor: composer
Product: phpoffice/phpspreadsheet
Published: Apr 29, 2026
Source: GitHub
CVE-2026-41484 MEDIUM - 5.3

OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In versions 1.15.0 and earlier, when a request to the configured back-end or collector results in an unsuccessful HTTP 4xx or 5xx response, the HttpJsonPostTransport class reads the enti...

Vendor: nuget
Product: OpenTelemetry.Exporter.OneCollector
Published: Apr 29, 2026
Source: GitHub
CVE-2026-7426 HIGH - 8.1

Insufficient validation of the prefix length field in IPv6 Router Advertisement processing in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause memory corruption by sending a crafted Router Advertisement with a prefix length value exceeding the maximum valid length...

Vendor: amazon
Product: freertos-plus-tcp
Published: Apr 29, 2026
Source: NVD
CVE-2026-7425 MEDIUM - 6.5

Insufficient option length validation in the IPv6 Router Advertisement parser in FreeRTOS-Plus-TCP before V4.2.6 and V4.4.1 allows an adjacent network actor to cause a denial of service (device crash) by sending a crafted Router Advertisement with a truncated PREFIX_INFORMATION option that is smalle...

Vendor: amazon
Product: freertos-plus-tcp
Published: Apr 29, 2026
Source: NVD
CVE-2026-7401 MEDIUM - 4.3

A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This vulnerability affects unknown code of the file /index.php?action=register of the component Registration. The manipulation of the argument student_id/full_name/section/username results i...

Published: Apr 29, 2026
Source: NVD
CVE-2026-7400 HIGH - 7.3

A security vulnerability has been detected in geekgod382 filesystem-mcp-server 1.0.0. This issue affects the function is_path_allowed of the file server.py of the component read_file_tool/write_file_tool. Such manipulation leads to path traversal. The attack can be launched remotely. The exploit has...

Published: Apr 29, 2026
Source: NVD
CVE-2026-34965 HIGH - 8.8

Cockpit CMS contains an authenticated remote code execution vulnerability in the /cockpit/collections/save_collection endpoint that allows authenticated attackers with collection management privileges to inject arbitrary PHP code into collection rules parameters. Attackers can inject malicious PHP c...

Vendor: Cockpit
Product: Cockpit CMS
Published: Apr 29, 2026
Source: NVD