Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

4,548 of 57,566 · Page 77/91
CVE-2026-77076

n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. Wh

CVE-2026-77077

n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's protot

CVE-2026-77079

n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. W

CVE-2026-77080

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability

CVE-2026-77081

n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. Whe

CVE-2026-77082

n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS)

CVE-2026-77083

n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM

CVE-2026-77084

n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git no

CVE-2026-77085

n8n before 2.34.1 and 2.33.x before 2.33.4 contains an SSRF protection bypass in the SearXNG Agent tool. The tool sent r

CVE-2026-77118

A heap out-of-bounds write exists in the Photo CD (PCD) decoder of GraphicsMagick. In DecodeImage() (coders/pcd.c), the

CVE-2026-7485

Incorrect authorization in frozen BI aggregations in Checkmk <2.5.0p2, <2.4.0p29, <2.3.0p47, and all 2.2.0 versions allo

CVE-2026-64960

ATutor Gameme module allows users to upload files of any type and extension without restriction. Due to improper handlin

CVE-2026-64961

ATutor is vulnerable to authentication bypass . Although a token validation check is present in the auto-login functiona

CVE-2026-64962

ATutor is vulnerable to Cross-Site Request Forgery (CSRF) in profile update functionality. An attacker can craft a malic

CVE-2026-64963

A path traversal vulnerability in ATutor allows an authenticated user to access files from other course directories when

CVE-2026-64964

ATutor generates predictable email confirmation tokens due to the use of insufficiently random values in the account con

CVE-2026-64965

ATutor is vulnerable to Missing Authorization Check on Test and Question Import endpoints.  A low-privileged authenticat

CVE-2026-64966

ATutor is vulnerable to a Path Traversal vulnerability in ZIP extraction functionality. An attacker with instructor priv

CVE-2026-64967

A path traversal vulnerability in ATutor's error log viewer allows an attacker with administrative privileges to access

CVE-2026-64968

ATutor is vulnerable to Server-Side request forgery in import functionalities. An authenticated administrator can make t

CVE-2026-64969

ATutor is vulnerable to Insecure Direct Object Reference (IDOR) attack in profile picture related endpoints. Any authent

CVE-2026-64970

ATutor is vulnerable to Stored Cross Site Scripting in registration functionality.  An attacker can register a new accou

CVE-2026-64971

ATutor is vulnerable to Reflected XSS in restore functionality. An attacker can provide a specially crafted URL that, wh

CVE-2026-64972

ATutor is vulnerable to Reflected XSS via popup parameter in preview.php. An authenticated attacker can inject a double

CVE-2026-70383

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Estonian Information Sys

CVE-2026-73220

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.68.0 until 2.70.0, the au

CVE-2026-40345

deepmerge-ts is a typescript library providing functionality to deep merging of javascript objects. Prior to 8.0.0, the

CVE-2026-54136

Windmill is an open-source developer platform for internal code: APIs, background jobs, workflows and UIs. Prior to 1.71

CVE-2026-55095

OpenProject is open-source, web-based project management software. In version 17.5.1 and earlier, an authenticated non-a

CVE-2026-63481

Hurl is a command line tool that runs and tests HTTP requests defined in plain text files. In version 8.0.1 and earlier,

CVE-2026-71492

Banks generates meaningful LLM prompts using a simple template language. Prior to version 2.4.5, DirectoryPromptRegistry

CVE-2026-2334

An issue was discovered in vsDesk v14.0101. An authenticated attacker with administrative privileges can bypass client-s

CVE-2026-53424

Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject

CVE-2026-53425

Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authent

CVE-2026-63379

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent processes chunked HTTP trailers in

CVE-2026-63380

Libevent is an event notification library. Prior to 2.2.2-alpha, libevent can dereference invalid list pointers in ws.c

CVE-2026-63381

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has a use-after-free in buffer.c wh

CVE-2026-63382

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, the libevent evhttp parser in http.c inconsi

CVE-2026-63383

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent can read beyond a contiguous evbuff

CVE-2026-63384

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has an incorrect integer conversion

CVE-2026-63385

Libevent is an event notification library. Prior to 2.1.13 and 2.2.2-alpha, libevent has two HTTP parsing weaknesses in

CVE-2026-73251

Mongoose is an embedded web server and network library. Prior to 7.23, a network attacker can impersonate a TLS server t

CVE-2026-73253

Mongoose is an embedded web server and network library. Prior to version 7.22, an on-path network attacker with a wildca

CVE-2026-19586

A pre-authentication OS command injection vulnerability has been identified in Omada gateways configured to operate as a

CVE-2026-19683

A vulnerability exists in the Dynamic DNS (DDNS) functionality of TP-Link Omada Gateways. During communication with a th

CVE-2026-50190

Shaarli is a personal bookmarking service. Versions prior to 0.16.3 are vulnerable to stored XSS in `application/front/c

CVE-2026-53569

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted toggle_like and mark_a

CVE-2026-62315

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, frappe.client.set_value in frappe/clie

CVE-2026-63654

Frappe is a full-stack web application framework. In version 16.31.0 and earlier, the whitelisted frappe.model.workflow.

CVE-2026-66001

Frappe is a full-stack web application framework. Prior to 15.114.0 and 16.26.0, the approve and authorize functions in

Scan for 2026 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started