Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified MEDIUM 5.1
CVE-2026-19434

Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the app…

Patch available
Fix from $1,600 2026-08-11
Unclassified MEDIUM 5.4
CVE-2026-72784

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 6.2
CVE-2026-72783

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContain…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-72782

Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 8.8
CVE-2026-72781

Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechan…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 6.5
CVE-2026-72780

Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 8.8
CVE-2026-72778

Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the …

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 5.8
CVE-2026-72775

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifi…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 7.1
CVE-2026-72774

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 8.9
CVE-2026-72772

n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming to…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 7.1
CVE-2026-72771

n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoin…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 7.1
CVE-2026-72770

n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operations that allows authenticated…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 6.1
CVE-2026-72769

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to creat…

No fix yet
Fix from $1,600 2026-08-11
Unclassified MEDIUM 6.4
CVE-2026-72768

n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated use…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 8.7
CVE-2026-72767

n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users w…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 8.2
CVE-2026-72766

n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforc…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 8.7
CVE-2026-72765

n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create …

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 5.8
CVE-2026-72764

n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and …

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 7.2
CVE-2026-72763

n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for credentials referenced inside…

No fix yet
Fix from $1,950 2026-08-11
Unclassified HIGH 7.7
CVE-2026-72762

n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 5.3
CVE-2026-72750

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates ex…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 7.1
CVE-2026-72749

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The node assigns output fields vi…

No fix yet
Fix from $1,950 2026-08-11
Unclassified CRITICAL 9.1
CVE-2026-72748

AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to wri…

Patch available
Fix from $2,300 2026-08-11
Unclassified HIGH 7.2
CVE-2026-72747

AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in…

Patch available
Fix from $1,950 2026-08-11
Unclassified HIGH 7.5
CVE-2026-72746

FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, t…

Patch available
Fix from $1,950 2026-08-11
Unclassified HIGH 7.5
CVE-2026-72745

FreeRDP before 3.30.0 contains an out-of-bounds vulnerability in kerberos_DecryptMessage() (winpr/libwinpr/sspi/Kerberos/kerberos.c). The 16-bit EC (…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 6.2
CVE-2026-72744

Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the development server's Chrome D…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 7.5
CVE-2026-69109

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal…

No fix yet
Fix from $1,950 2026-08-11
Unclassified MEDIUM 6.0
CVE-2026-69108

A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privileg…

No fix yet
Fix from $1,600 2026-08-11
Unclassified HIGH 7.8
CVE-2026-64629

A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applicati…

No fix yet
Fix from $1,950 2026-08-11