Vulnerability index

Browse CVEs

6,044 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Filtering by weakness Code InjectionCWE-94 × clear
N8n HIGH 8.8
CVE-2026-27497

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or…

Fix: 1.123.22 / 2.9.3+
Fix from $1,950 2026-02-25
N8n HIGH 8.8
CVE-2026-27498

n8n is an open source workflow automation platform. Prior to versions 2.2.0 and 1.123.8, an authenticated user with permission to create or modify wo…

Fix: 1.123.8 / 2.2.0+
Fix from $1,950 2026-02-25
N8n CRITICAL 9.9
CVE-2026-27577EPSS 9%

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation o…

Fix: 1.123.22 / 2.9.3+
Fix from $2,300 2026-02-25
N8n CRITICAL 9.0
CVE-2026-27493

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, a second-order expression injection vulnerability …

Fix: 1.123.22 / 2.9.3+
Fix from $2,300 2026-02-25
N8n CRITICAL 9.9
CVE-2026-27495

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or…

Fix: 1.123.22 / 2.9.3+
Fix from $2,300 2026-02-25
Unclassified HIGH 8.8
CVE-2026-27701

LiveCode is an open-source, client-side code playground. Prior to commit e151c64c2bd80d2d53ac1333f1df9429fe6a1a11, LiveCode's `i18n-update-pull` GitH…

Patch available
Fix from $1,950 2026-02-25
Budibase CRITICAL 9.0
CVE-2026-27702

Budibase is a low code platform for creating internal tools, workflows, and admin panels. Prior to version 3.30.4, an unsafe `eval()` vulnerability i…

Fix: 3.30.4+
Fix from $2,300 2026-02-25
Unclassified HIGH 8.8
CVE-2026-1929

The Advanced Woo Labels plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.37. This is due to the us…

Mitigation only
Fix from $1,950 2026-02-25
Patients Waiting Area Queue Management System MEDIUM 5.4
CVE-2026-3171

A flaw has been found in SourceCodester/Patrick Mvuma Patients Waiting Area Queue Management System 1.0. Affected by this vulnerability is an unknown…

No fix yet
Fix from $1,600 2026-02-25
Interface Traduction Objets HIGH 8.8
CVE-2026-27745

The SPIP interface_traduction_objets plugin versions prior to 2.2.2 contain an authenticated remote code execution vulnerability in the translation i…

Fix: 2.2.2+
Fix from $1,950 2026-02-25
Tickets CRITICAL 9.8
CVE-2026-27744

The SPIP tickets plugin versions prior to 4.3.3 contain an unauthenticated remote code execution vulnerability in the forum preview handling for publ…

Fix: 4.3.3+
Fix from $2,300 2026-02-25
Enclave CRITICAL 10.0
CVE-2026-27597

Enclave is a secure JavaScript sandbox designed for safe AI agent code execution. Prior to version 2.11.1, it is possible to escape the security boun…

Fix: 2.11.1+
Fix from $2,300 2026-02-25
Airflow HIGH 8.4
CVE-2024-56373

DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server…

Fix: 2.11.1+
Fix from $1,950 2026-02-24
Modern Image Gallery App MEDIUM 6.1
CVE-2026-3070

A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknown functionality of the file u…

No fix yet
Fix from $1,600 2026-02-24
Sogo MEDIUM 6.1
CVE-2026-3054

A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross s…

Mitigation only
Fix from $1,600 2026-02-24
Horilla MEDIUM 5.4
CVE-2026-3050

A flaw has been found in horilla-opensource horilla up to 1.0.2. Impacted is an unknown function of the file static/assets/js/global.js of the compon…

Fix: 1.0.3+
Fix from $1,600 2026-02-24
Imagemagick MEDIUM 5.3
CVE-2026-25797

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-15 and 6.9.13-40, the ps coder…

Fix: 6.9.13-40 / 7.1.2-15+
Fix from $1,600 2026-02-24
Unclassified HIGH 8.6
CVE-2025-9120

Improper Control of Generation of Code ('Code Injection') vulnerability in OpenText™ Carbonite Safe Server Backup allows Code Injection.  The vulner…

Mitigation only
Fix from $1,950 2026-02-24
Event Management System MEDIUM 6.1
CVE-2026-3043

A flaw has been found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/navbar.php. Executi…

No fix yet
Fix from $1,600 2026-02-24
Jeewms MEDIUM 6.1
CVE-2026-3028

A vulnerability was determined in erzhongxmu JEEWMS up to 3.7. This vulnerability affects the function doAdd of the file src/main/java/com/jeecg/demo…

Fix: after 3.7
Fix from $1,600 2026-02-23
Jeewms MEDIUM 6.1
CVE-2026-3027

A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-in/ueditor/jsp/getContent.jsp…

Fix: after 3.7
Fix from $1,600 2026-02-23
X6000r Firmware HIGH 8.8
CVE-2025-70328

TOTOLINK X6000R v9.4.0cu.1498_B20250826 contains an OS command injection vulnerability in the NTPSyncWithHost handler of the /usr/sbin/shttpd executa…

No fix yet
Fix from $1,950 2026-02-23
Smart Sso MEDIUM 5.4
CVE-2026-2972

A vulnerability was determined in a466350665 Smart-SSO up to 2.1.1. This affects the function Save of the file smart-sso-server/src/main/java/openjoe…

Fix: after 2.1.1
Fix from $1,600 2026-02-23
Smart Sso MEDIUM 6.1
CVE-2026-2971

A vulnerability was found in a466350665 Smart-SSO up to 2.1.1. Affected by this issue is some unknown functionality of the file smart-sso-server/src/…

Fix: after 2.1.1
Fix from $1,600 2026-02-23
Webaudiorecorder.js CRITICAL 9.8
CVE-2026-2964

A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library lib/WebAudioRecorder.js of t…

Mitigation only
Fix from $2,300 2026-02-23
Forest MEDIUM 5.4
CVE-2026-2947

A vulnerability was detected in rymcu forest up to 0.0.5. This affects the function updateUserInfo of the file - src/main/java/com/rymcu/forest/web/a…

Fix: after 0.0.5
Fix from $1,600 2026-02-22
Forest MEDIUM 5.4
CVE-2026-2946

A security vulnerability has been detected in rymcu forest up to 0.0.5. Affected by this issue is the function XssUtils.replaceHtmlCode of the file s…

Fix: after 0.0.5
Fix from $1,600 2026-02-22
Oneuptime CRITICAL 9.9
CVE-2026-27574

OneUptime is a solution for monitoring and managing online services. In versions 9.5.13 and below, custom JavaScript monitor feature uses Node.js's n…

Fix: 10.0.5+
Fix from $2,300 2026-02-21
Metabase MEDIUM 6.5
CVE-2026-27464

Metabase is an open-source data analytics platform. In versions prior to 0.57.13 and versions 0.58.x through 0.58.6, authenticated users are able to …

Fix: 0.57.13 / 0.58.7+
Fix from $1,600 2026-02-21
Moodle HIGH 7.2
CVE-2026-26045

A flaw was identified in Moodle’s backup restore functionality where specially crafted backup files were not properly validated during processing. If…

Fix: 4.5.9 / 5.0.5+
Fix from $1,950 2026-02-21