CVE Vulnerability Database

Search and browse 389,949 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-59259MEDIUM6.5n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling...
CVE-2026-59254MEDIUM6.3n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in wo...
CVE-2026-59236MEDIUM6.9Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, Pro...
CVE-2026-58655HIGH8.8The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side templ...
CVE-2026-57996HIGH8.8phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAd...
CVE-2026-56764MEDIUM6.3Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-consta...
CVE-2026-56699Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy,...
CVE-2026-56400CRITICAL9.6open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow...
CVE-2026-56398CRITICAL9Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the ...
CVE-2026-56375MEDIUM4.8ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers ca...
CVE-2026-56353MEDIUM6.3n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configu...
CVE-2026-56352MEDIUM6.4n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, ...
CVE-2026-56349MEDIUM6.3n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypa...
CVE-2026-56339HIGH8.7Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY...
CVE-2026-59235HIGH8.7Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListContro...
CVE-2026-40633MEDIUM5.5Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sen...
CVE-2026-8281Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
CVE-2026-58077HIGH8.7Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vu...
CVE-2026-57833HIGH8.6Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vu...
CVE-2026-57821HIGH8.1A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and ...
CVE-2026-56287HIGH8.1A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versi...
CVE-2026-49501MEDIUM6.7Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Pri...
CVE-2026-35152HIGH8.8A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to a...
CVE-2026-57832HIGH8.7Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocma...
CVE-2026-57831HIGH8.7Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla e...