CVE Vulnerability Database
Search and browse 389,949 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-59259 | MEDIUM | 6.5 | 0.3% | Jul 15, 2026 | n8n before versions 1.123.61, 2.27.4, and 2.28.1 contains a permission bypass vulnerability in external secrets handling... |
| CVE-2026-59254 | MEDIUM | 6.3 | — | Jul 15, 2026 | n8n before 2.28.1 contains an information disclosure vulnerability where external secrets are incorrectly resolved in wo... |
| CVE-2026-59236 | MEDIUM | 6.9 | — | Jul 15, 2026 | Authorization Bypass Through User-Controlled Key (CWE-639) in the Excel import handlers (CustomerImport, LeadImport, Pro... |
| CVE-2026-58655 | HIGH | 8.8 | — | Jul 15, 2026 | The bundled Grav Flex Objects plugin (getgrav/grav-plugin-flex-objects) before 1.4.0 contains a stored server-side templ... |
| CVE-2026-57996 | HIGH | 8.8 | 0.2% | Jul 15, 2026 | phpMyFAQ before 4.1.5 contains a privilege escalation vulnerability in the user/add API endpoint that allows non-SuperAd... |
| CVE-2026-56764 | MEDIUM | 6.3 | — | Jul 15, 2026 | Hono before 4.11.10 contains a timing attack vulnerability in the basicAuth and bearerAuth middlewares due to non-consta... |
| CVE-2026-56699 | — | — | 0.4% | Jul 15, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Per Wazuh's Security Policy,... |
| CVE-2026-56400 | CRITICAL | 9.6 | 0.3% | Jul 15, 2026 | open-webui before 0.3.14 contains a cross-origin resource sharing misconfiguration allowing arbitrary origins with allow... |
| CVE-2026-56398 | CRITICAL | 9 | 0.3% | Jul 15, 2026 | Open WebUI before 0.9.5 contains a stored cross-site scripting vulnerability in the OAuth authentication flow where the ... |
| CVE-2026-56375 | MEDIUM | 4.8 | — | Jul 15, 2026 | ImageMagick through 7.1.2-18 contains a memory leak vulnerability in the ASHLAR coder when an action fails. Attackers ca... |
| CVE-2026-56353 | MEDIUM | 6.3 | 0.2% | Jul 15, 2026 | n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configu... |
| CVE-2026-56352 | MEDIUM | 6.4 | — | Jul 15, 2026 | n8n before 2.19.3 contains a file path restriction bypass in the legacy ExecuteWorkflow node's localFile source option, ... |
| CVE-2026-56349 | MEDIUM | 6.3 | — | Jul 15, 2026 | n8n before version 2.10.0 contains an input validation vulnerability in the Guardrail node that allows attackers to bypa... |
| CVE-2026-56339 | HIGH | 8.7 | — | Jul 15, 2026 | Capgo (Cap-go/capgo) before 12.128.2 contains an information disclosure vulnerability in the Supabase PostgREST SECURITY... |
| CVE-2026-59235 | HIGH | 8.7 | — | Jul 15, 2026 | Missing Authorization (CWE-862) in BankAccountListController (app/Http/Controllers/Api/BankAccount/BankAccountListContro... |
| CVE-2026-40633 | MEDIUM | 5.5 | — | Jul 15, 2026 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, versions 9.11.0.0 through 9.13.0.2 contains an Insertion of Sen... |
| CVE-2026-8281 | — | — | — | Jul 15, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. |
| CVE-2026-58077 | HIGH | 8.7 | 0.4% | Jul 15, 2026 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vu... |
| CVE-2026-57833 | HIGH | 8.6 | 0.4% | Jul 15, 2026 | Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vu... |
| CVE-2026-57821 | HIGH | 8.1 | 0.3% | Jul 15, 2026 | A SQL Injection vulnerability exists in Apache Fineract's Office Search API (GET /api/v1/offices) in versions up to and ... |
| CVE-2026-56287 | HIGH | 8.1 | 0.3% | Jul 15, 2026 | A boolean-based SQL Injection vulnerability exists in Apache Fineract's Client Search API (GET /api/v1/clients) in versi... |
| CVE-2026-49501 | MEDIUM | 6.7 | 0.2% | Jul 15, 2026 | Dell PowerScale OneFS versions 9.5.0.0 through 9.10.1.7, and versions 9.11.0.0 through 9.13.0.2 contains an Improper Pri... |
| CVE-2026-35152 | HIGH | 8.8 | 0.3% | Jul 15, 2026 | A SQL Injection vulnerability exists in Apache Fineract's Report Execution API (runreports endpoint) in versions up to a... |
| CVE-2026-57832 | HIGH | 8.7 | 0.2% | Jul 15, 2026 | Joomla Extension - joomdonation.com - Unauthenticated blind SQL injection in EDocman < 3.9 - The Joomla extension EDocma... |
| CVE-2026-57831 | HIGH | 8.7 | 0.2% | Jul 15, 2026 | Joomla Extension - digital-peak.com - Unauthenticated blind SQL injection in DP Calendar 8.18.0 - 10.11.2 - The Joomla e... |
