57,566 vulnerabilities published in 2026
In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed
An OS command injection vulnerability in vsDesk allows an authenticated attacker with administrative privileges to execu
Joomla Extension - icagenda.com - Authenticated Stored XSS in iCagenda 4.0.8 to 4.0.12 - The frontend "Submit an Event"
Joomla Extension - phoca.cz - Stored XSS via User-Agent header in Admin Order View in Phoca Cart 5.0.0-6.1.7
Joomla Extension - phoca.cz - Reflected XSS via price_from & price_to filter parameters in Phoca Cart 5.0.0-6.1.7
Joomla Extension - phoca.cz - Reflected XSS via the search GET parameter in Phoca Download 5.0.0-6.1.4
Joomla Extension - yootheme.com - Unauthenticated tag modifications in Zoo < 4.1.65 - The comment controller endpoint la
Joomla Extension - tassos.gr - Client-controlled validation bypass in Convert Forms extension < 5.2.5 - The front-end Su
n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-s
n8n before 1.123.69, 2.33.4, and 2.34.1 contains an SSRF protection bypass in the OAuth2 credential authorization-code-t
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row G
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the Form node's completi
n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authent
n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text oper
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in resour
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. Wh
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's protot
n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. W
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability
n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. Whe
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS)
n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM
n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git no
n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent r
A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the
Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allo
ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handlin
ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functiona
ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malic
A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when
ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account con
ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints. A low-privileged authenticat
ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor priv
A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access
ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make t
ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authent
ATutor is vulnerable to Stored Cross Site Scripting in registration functionality. An attacker can register a new accou
ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, wh
ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information Sys
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the au
deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.71
OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an authenticated non-a
Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier,
Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry
An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-s
Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject
Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authent
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started