Vulnerability index

Browse CVEs

2,888 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.3 CVE-2026-64964 ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account confirmation functionality. Due … No fix yet Fix from $4,0002026-08-20 MEDIUM 5.1 CVE-2026-64962 ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malicious website which, when visi… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.3 CVE-2026-64961 ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functionality, the values required for… No fix yet Fix from $4,0002026-08-20 HIGH 8.7 CVE-2026-64960 ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handling of file uploads, files are … No fix yet Fix from $4,9002026-08-20 CRITICAL 9.8 CVE-2026-15706 Missing authentication for critical function vulnerability in Baylan Measuring Instruments Industry and Trade Inc. Baylan Smart Meter Management Appl… No fix yet Fix from $5,7502026-08-20 HIGH 8.4 CVE-2026-77118 A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the Huffman delta loop advances i… No fix yet Fix from $4,9002026-08-20 MEDIUM 5.3 CVE-2026-76989 A security vulnerability has been detected in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This impacts an unknown function of the fi… Patch available Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-76988 A weakness has been identified in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. This affects the function CipConnMgrClass::forward_ope… Patch available Fix from $4,0002026-08-20 HIGH 7.3 CVE-2026-76987 A security flaw has been discovered in liftoff-sr CIPster 1802525be27d33e19a9a83c163e331a1d13b1892. The impacted element is the function CipAttribute… Patch available Fix from $4,9002026-08-20 HIGH 7.6 CVE-2026-74011 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Inje… No fix yet Fix from $4,9002026-08-20 CRITICAL 9.6 CVE-2026-28164 Cross-Site Request Forgery (CSRF) vulnerability in HashThemes Easy Elementor Addons allows Cross Site Request Forgery. This issue affects Easy Eleme… No fix yet Fix from $5,7502026-08-20 MEDIUM 5.3 CVE-2026-28163 Missing Authorization vulnerability in myCred New User Approve allows Exploiting Incorrectly Configured Access Control Security Levels. This issue a… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.0 CVE-2025-62306 HCL IntelliOps Event Management (IEM) is affected by information omission. The lack of information breaks auditability and observability of a workflo… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.9 CVE-2025-62300 HCL IntelliOps Event Management (IEM) is affected by a race condition. A "timing window" can occur where an attacker can modify the resource causing … No fix yet Fix from $4,0002026-08-20 MEDIUM 6.6 CVE-2025-62299 HCL IntelliOps Event Management (IEM) is affected by a least privileges violation which could allow an attacker to access the resource with the eleva… No fix yet Fix from $4,0002026-08-20 MEDIUM 6.3 CVE-2026-77085 n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent requests to the user-supplied … No fix yet Fix from $4,0002026-08-20 HIGH 7.7 CVE-2026-77084 n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repositor… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.0 CVE-2026-77083 n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM sandbox did not freeze the sa… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-77082 n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS) vulnerability in the Filter … No fix yet Fix from $4,0002026-08-20 MEDIUM 5.1 CVE-2026-77081 n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication p… No fix yet Fix from $4,0002026-08-20 HIGH 8.7 CVE-2026-77080 n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which … No fix yet Fix from $4,9002026-08-20 HIGH 7.4 CVE-2026-77079 n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project… No fix yet Fix from $4,9002026-08-20 HIGH 7.2 CVE-2026-77077 n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's prototype-freezing routine covers g… No fix yet Fix from $4,9002026-08-20 HIGH 7.1 CVE-2026-77076 n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. When a GraphQL request fails at… No fix yet Fix from $4,9002026-08-20 HIGH 8.4 CVE-2026-77075 n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in resource-locator field link preview… No fix yet Fix from $4,9002026-08-20 MEDIUM 6.0 CVE-2026-77074 n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticat… No fix yet Fix from $4,0002026-08-20 MEDIUM 5.3 CVE-2026-77073 n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an exp… No fix yet Fix from $4,0002026-08-20 HIGH 8.4 CVE-2026-77072 n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the Form node's completion page. The completion page … No fix yet Fix from $4,9002026-08-20 HIGH 7.1 CVE-2026-77071 n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update o… No fix yet Fix from $4,9002026-08-20 HIGH 7.1 CVE-2026-77070 n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which … No fix yet Fix from $4,9002026-08-20