57,566 vulnerabilities published in 2026
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. Wh
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's protot
n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. W
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability
n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. Whe
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS)
n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM
n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git no
n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent r
A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the
Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allo
ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handlin
ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functiona
ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malic
A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when
ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account con
ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints. A low-privileged authenticat
ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor priv
A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access
ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make t
ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authent
ATutor is vulnerable to Stored Cross Site Scripting in registration functionality. An attacker can register a new accou
ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, wh
ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information Sys
CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the au
deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the
Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.71
OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an authenticated non-a
Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier,
Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry
An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-s
Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject
Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authent
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in
Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c wh
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsi
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuff
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion
Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in
Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server t
Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildca
A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as a
A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a th
Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/c
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_a
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/clie
Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.
Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in
Scan for 2026 Vulnerabilities
CyberStrike detects these CVEs across your infrastructure automatically.
Get Started