Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

MEDIUM 5.1 CVE-2026-19434 Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the app… Patch available Fix from $1,6002026-08-11 MEDIUM 5.4 CVE-2026-72784 Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<… No fix yet Fix from $1,6002026-08-11 MEDIUM 6.2 CVE-2026-72783 Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContain… No fix yet Fix from $1,6002026-08-11 MEDIUM 6.5 CVE-2026-72782 Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in… No fix yet Fix from $1,6002026-08-11 HIGH 8.8 CVE-2026-72781 Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechan… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.5 CVE-2026-72780 Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can… No fix yet Fix from $1,6002026-08-11 HIGH 8.8 CVE-2026-72778 Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the … No fix yet Fix from $1,9502026-08-11 MEDIUM 5.8 CVE-2026-72775 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifi… No fix yet Fix from $1,6002026-08-11 HIGH 7.1 CVE-2026-72774 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access… No fix yet Fix from $1,9502026-08-11 HIGH 8.9 CVE-2026-72772 n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming to… No fix yet Fix from $1,9502026-08-11 HIGH 7.1 CVE-2026-72771 n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoin… No fix yet Fix from $1,9502026-08-11 HIGH 7.1 CVE-2026-72770 n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operations that allows authenticated… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.1 CVE-2026-72769 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to creat… No fix yet Fix from $1,6002026-08-11 MEDIUM 6.4 CVE-2026-72768 n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated use… No fix yet Fix from $1,6002026-08-11 HIGH 8.7 CVE-2026-72767 n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users w… No fix yet Fix from $1,9502026-08-11 HIGH 8.2 CVE-2026-72766 n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforc… No fix yet Fix from $1,9502026-08-11 HIGH 8.7 CVE-2026-72765 n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create … No fix yet Fix from $1,9502026-08-11 MEDIUM 5.8 CVE-2026-72764 n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and … No fix yet Fix from $1,6002026-08-11 HIGH 7.2 CVE-2026-72763 n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for credentials referenced inside… No fix yet Fix from $1,9502026-08-11 HIGH 7.7 CVE-2026-72762 n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format… No fix yet Fix from $1,9502026-08-11 MEDIUM 5.3 CVE-2026-72750 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the Snowflake node's Execute Query operation, which interpolates ex… No fix yet Fix from $1,6002026-08-11 HIGH 7.1 CVE-2026-72749 n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The node assigns output fields vi… No fix yet Fix from $1,9502026-08-11 CRITICAL 9.1 CVE-2026-72748 AVideo contains an unauthenticated arbitrary file write vulnerability in the aVideoEncoderChunk.json.php endpoint that allows remote attackers to wri… Patch available Fix from $2,3002026-08-11 HIGH 7.2 CVE-2026-72747 AVideo fails to sanitize the phone field during user registration, allowing unauthenticated attackers to inject malicious JavaScript that persists in… Patch available Fix from $1,9502026-08-11 HIGH 7.5 CVE-2026-72746 FreeRDP before 3.30.0 contains a server-side authentication bypass in the RDSTLS handshake. When a server is configured with RdstlsSecurity = TRUE, t… Patch available Fix from $1,9502026-08-11 HIGH 7.5 CVE-2026-72745 FreeRDP before 3.30.0 contains an out-of-bounds vulnerability in kerberos_DecryptMessage() (winpr/libwinpr/sspi/Kerberos/kerberos.c). The 16-bit EC (… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.2 CVE-2026-72744 Nuxt versions >= 4.4.7 and < 4.5.1, and >= 3.21.7 and < 3.21.10, contain an information disclosure vulnerability in the development server's Chrome D… No fix yet Fix from $1,6002026-08-11 HIGH 7.5 CVE-2026-69109 A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.3). The affected application is vulnerable to a path traversal… No fix yet Fix from $1,9502026-08-11 MEDIUM 6.0 CVE-2026-69108 A vulnerability has been identified in Siemens License Server (SLS) (All versions < V5.1). The affected application is vulnerable to a local privileg… No fix yet Fix from $1,6002026-08-11 HIGH 7.8 CVE-2026-64629 A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applicati… No fix yet Fix from $1,9502026-08-11