Total CVEs

131,269

Critical Severity

2,778

High Severity

9,907

Last 7 Days

1,030
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,841 - 1,860 of 27,674 CVEs

Portainer Has an Arbitrary File Read via Git Symlink Injection in Stack Auto-Update

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub
CVE-2026-44850 HIGH - 8.5

Portainer has a bind-mount restriction bypass via HostConfig.Mounts

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub
CVE-2026-44885 MEDIUM - 5.5

Portainer has a path traversal in backup archive extraction that allows arbitrary file write

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub

Portainer missing authorization on Docker plugin endpoints, which allows host RCE

Vendor: go
Product: github.com/portainer/portainer
Published: May 14, 2026
Source: GitHub

FlowiseAI: Evaluator create+update mass-assignment allows cross-workspace evaluator takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: Evaluation create+update mass-assignment allows cross-workspace evaluation takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: DatasetRow create+update mass-assignment allows cross-workspace row takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: Dataset create+update mass-assignment allows cross-workspace dataset takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: CustomTemplate create+update mass-assignment allows cross-workspace template takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: Assistant create+update mass-assignment allows cross-workspace assistant takeover

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

FlowiseAI: Vector Store No Permission Checks

Vendor: npm
Product: flowise
Published: May 14, 2026
Source: GitHub

Synapse pagination Denial of Service

Vendor: pip
Product: matrix-synapse
Published: May 14, 2026
Source: GitHub

Synapse CPU starvation (Denial of Service)

Vendor: pip
Product: matrix-synapse
Published: May 14, 2026
Source: GitHub

n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n Has a Source Control Pull SQL Injection

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n Has an XML Node Prototype Pollution Patch Bypass

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n Has an Arbitrary File Read via Git Node

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub

n8n: HTTP Request Node Pagination Prototype Pollution to RCE

Vendor: npm
Product: n8n
Published: May 14, 2026
Source: GitHub
CVE-2026-44722 MEDIUM - 6.2

pyzipper has an encryption bypass for small files encrypted using it

Vendor: pip
Product: pyzipper
Published: May 14, 2026
Source: GitHub
CVE-2026-43978 HIGH - 8.1

wger: Privilege escalation via trainer-login session chaining allows gym trainer to impersonate gym manager

Vendor: pip
Product: wger
Published: May 14, 2026
Source: GitHub