CVE Vulnerability Database
Search and browse 390,041 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-56778 | MEDIUM | 6.4 | — | Jul 8, 2026 | n8n before 2.25.7 and 2.26.x before 2.26.2 contains an authorization bypass in the Public API execution retry endpoint, ... |
| CVE-2026-56776 | HIGH | 7.4 | 0.2% | Jul 8, 2026 | n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization bypass in the POST /workflows/{workflowId}/test-runs/n... |
| CVE-2026-56775 | MEDIUM | 5.4 | — | Jul 8, 2026 | n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authorization vulnerability in three mutating evaluation test-run en... |
| CVE-2026-56401 | — | — | 0.3% | Jul 8, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-56374 | HIGH | 7.1 | 0.1% | Jul 8, 2026 | ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerability in the FTXT encoder due to missing boundary ch... |
| CVE-2026-56362 | MEDIUM | 4.2 | 0.2% | Jul 8, 2026 | ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulnerability in GetPixelIndex caused by OpenPixelCache... |
| CVE-2026-56360 | MEDIUM | 6.3 | — | Jul 8, 2026 | n8n before versions 1.123.18 and 2.6.2 fails to verify HMAC-SHA256 signatures on Zendesk webhooks in the ZendeskTrigger ... |
| CVE-2026-56359 | MEDIUM | 5.4 | 0.1% | Jul 8, 2026 | n8n before 2.8.0 contains a cross-site scripting vulnerability in the credential management flow where authenticated use... |
| CVE-2026-56298 | MEDIUM | 5.3 | — | Jul 8, 2026 | Capgo before 12.128.2 fails to strip EXIF metadata from images uploaded via the app information endpoint, exposing sensi... |
| CVE-2026-56297 | HIGH | 8.1 | 0.3% | Jul 8, 2026 | FreeRDP before 3.22.0 contains a use-after-free vulnerability in dvcman_channel_close and dvcman_call_on_receive due to ... |
| CVE-2026-56293 | MEDIUM | 5.4 | — | Jul 8, 2026 | Capgo before 12.128.2 contains an authorization flaw in transfer_app() that fails to update deploy_history.owner_org whe... |
| CVE-2026-56284 | MEDIUM | 6.9 | — | Jul 8, 2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST RPC func... |
| CVE-2026-56283 | MEDIUM | 5.4 | — | Jul 8, 2026 | Capgo before 12.128.2 contains an html injection vulnerability in the organization settings endpoint that allows attacke... |
| CVE-2026-56273 | MEDIUM | 6.5 | 0.3% | Jul 8, 2026 | Flowise before 3.1.0 contains a path traversal vulnerability in Faiss and SimpleStore vector store implementations that ... |
| CVE-2026-56250 | HIGH | 8.7 | — | Jul 8, 2026 | Capgo before 12.128.2 allows upload-scoped API keys to modify the mutable app_versions.r2_path field through PostgREST, ... |
| CVE-2026-56246 | HIGH | 8.1 | — | Jul 8, 2026 | Capgo before 12.128.2 contains a broken access control vulnerability in the organization management API where a scoped A... |
| CVE-2026-56226 | HIGH | 8.7 | — | Jul 8, 2026 | Capgo (Cap-go/capgo) before 12.128.2 exposes the Supabase PostgREST RPC function public.get_orgs_v6(userid uuid), which ... |
| CVE-2026-56220 | HIGH | 7.1 | — | Jul 8, 2026 | Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.manifest INSERT policy that allows re... |
| CVE-2026-56217 | MEDIUM | 5.3 | — | Jul 8, 2026 | Capgo before 12.128.2 contains a policy bypass vulnerability in app_versions update enforcement that allows app-scoped A... |
| CVE-2026-56086 | HIGH | 8.8 | — | Jul 8, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.6, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-54061 | CRITICAL | 9.1 | — | Jul 8, 2026 | Dgraph is an open source distributed GraphQL database. Prior to version 25.3.5, Dgraph Alpha exposes the RPCs used for e... |
| CVE-2026-53482 | HIGH | 7.5 | 0.3% | Jul 8, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-53480 | LOW | 2.7 | — | Jul 8, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
| CVE-2026-44840 | HIGH | 7.5 | 0.5% | Jul 8, 2026 | Dgraph is an open source distributed GraphQL database. Prior to version 25.3.4, the `checkUserPassword` GraphQL query in... |
| CVE-2026-41122 | HIGH | 7.1 | — | Jul 8, 2026 | Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 release version 8.6.1.0 through 8.6.1.10, LTS2025 r... |
