CVE Vulnerability Database

Search and browse 391,091 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-56369MEDIUM6.3ImageMagick before 7.1.2-22 contains an information disclosure vulnerability in the PasskeyEncipherImage method due to A...
CVE-2026-56365MEDIUM5.3ImageMagick before 7.1.2-19 contains a memory leak vulnerability in the PNG encoder when writing MNG images. Attackers c...
CVE-2026-56364LOW1.9ImageMagick before 7.1.2-13 contains a memory leak vulnerability in LoadOpenCLDeviceBenchmark() function when parsing ma...
CVE-2026-56363MEDIUM4.8ImageMagick before 7.1.2-22 contains a division by zero vulnerability in binomial kernel processing that allows attacker...
CVE-2026-56361HIGH7.1ImageMagick before 7.1.2-19 contains an off-by-one error in morphology validation allowing out-of-bounds heap buffer rea...
CVE-2026-56356MEDIUM5.4n8n contains a stored cross-site scripting vulnerability in the Chat Trigger node's Custom CSS field due to a misconfigu...
CVE-2026-56350HIGH7.7n8n before 2.8.0 contains an authentication bypass vulnerability allowing authenticated SSO users to disable SSO enforce...
CVE-2026-56334MEDIUM5.3Capgo before 12.128.2 lacks an UPDATE row-level security policy for the build_requests table, preventing API-key and ano...
CVE-2026-56333MEDIUM5.3Capgo before 12.128.2 contains a server-side validation bypass vulnerability in organization security settings that allo...
CVE-2026-56331MEDIUM6.9Capgo before 12.128.2 contains improper error handling in the /private/accept_invitation endpoint that returns HTTP 500 ...
CVE-2026-56328HIGH7.1Capgo before 12.128.2 allows multiple public channels for the same app and platform to coexist simultaneously, while unn...
CVE-2026-56327MEDIUM6.9Capgo before 12.128.2 contains an information disclosure vulnerability in the public.invite_user_to_org RPC function tha...
CVE-2026-56320HIGH7.1Capgo before 12.128.2 contains an authorization flaw in POST /private/create_device that accepts a caller-supplied org_i...
CVE-2026-56318MEDIUM6.9Capgo before 12.128.2 contains an information disclosure vulnerability in the /private/validate_password_compliance endp...
CVE-2026-56300HIGH8.7Capgo before 12.128.2 contains unauthenticated security definer RPC functions get_user_id and get_org_perm_for_apikey th...
CVE-2026-56286HIGH8.1Capgo before 12.128.2 contains an authentication bypass vulnerability in the account deletion endpoint that allows delet...
CVE-2026-56278CRITICAL9.3Flowise before 3.1.0 (affected versions 3.0.13 and earlier) uses a weak hardcoded default secret ('flowise') for the exp...
CVE-2026-56277MEDIUM6.5Flowise before 3.1.2 sets Access-Control-Allow-Origin to a hardcoded wildcard (*) on its text-to-speech (TTS) generation...
CVE-2026-56264MEDIUM6.1Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js en...
CVE-2026-56249HIGH7.6Capgo before 12.128.2 contains an authorization bypass vulnerability in the channel creation endpoint that allows authen...
CVE-2026-56247HIGH8.8Capgo before 12.128.2 allows org admins to assign org-scoped RBAC roles at app scope without validating role scope compa...
CVE-2026-56233HIGH8.7Capgo before 12.128.2 contains a path traversal vulnerability in the builder upload proxy that allows authenticated user...
CVE-2026-56230HIGH8.8Capgo before 12.128.2 contains a broken object level authorization vulnerability in middlewareKey() that accepts the cli...
CVE-2026-56224MEDIUM5.4Capgo console.capgo.app/login before 12.128.2 accepts access_token and refresh_token in URL query parameters, automatica...
CVE-2026-56219HIGH8.7Capgo before 12.128.2 contains a NULL-auth bypass vulnerability in the public.get_org_user_access_rbac function that all...