Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

57,566 results · Page 1137/1152
CVE-2026-14163

In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed

CVE-2025-14601

An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execu

CVE-2026-75948

Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event"

CVE-2026-76564

Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7

CVE-2026-76565

Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7

CVE-2026-76569

Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4

CVE-2026-76610

Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint la

CVE-2026-77026

Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Su

CVE-2026-77068

n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-s

CVE-2026-77069

n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorization-code-t

CVE-2026-77070

n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and

CVE-2026-77071

n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row G

CVE-2026-77072

n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the Form node's completi

CVE-2026-77073

n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authent

CVE-2026-77074

n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text oper

CVE-2026-77075

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in resour

CVE-2026-77076

n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. Wh

CVE-2026-77077

n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's protot

CVE-2026-77079

n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. W

CVE-2026-77080

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability

CVE-2026-77081

n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. Whe

CVE-2026-77082

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS)

CVE-2026-77083

n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM

CVE-2026-77084

n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git no

CVE-2026-77085

n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent r

CVE-2026-77118

A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the

CVE-2026-7485

Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allo

CVE-2026-64960

ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handlin

CVE-2026-64961

ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functiona

CVE-2026-64962

ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malic

CVE-2026-64963

A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when

CVE-2026-64964

ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account con

CVE-2026-64965

ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints.  A low-privileged authenticat

CVE-2026-64966

ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor priv

CVE-2026-64967

A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access

CVE-2026-64968

ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make t

CVE-2026-64969

ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authent

CVE-2026-64970

ATutor is vulnerable to Stored Cross Site Scripting in registration functionality.  An attacker can register a new accou

CVE-2026-64971

ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, wh

CVE-2026-64972

ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double

CVE-2026-70383

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information Sys

CVE-2026-73220

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the au

CVE-2026-40345

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the

CVE-2026-54136

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.71

CVE-2026-55095

OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an authenticated non-a

CVE-2026-63481

Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier,

CVE-2026-71492

Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry

CVE-2026-2334

An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-s

CVE-2026-53424

Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject

CVE-2026-53425

Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authent

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started