Search
9,831 CVEs
CVEs (9,831, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 401–425 of 9,831 (capped at 500)
| CVE ID ↓ | Severity | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65689 | CRITICAL | Patched | 9.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated att… |
| CVE-2026-65688 | CRITICAL | Patched | 9.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attac… |
| CVE-2026-65687 | CRITICAL | Patched | 9.8 | 2026-07-23 | Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attack… |
| CVE-2026-65650 | MEDIUM | Patched | 4.3 | 2026-07-22 | Elgg before 7.0.0 does not check image dimensions to prevent denial of service via a large avatar upload. |
| CVE-2026-65608 | HIGH | Patched | 8.8 | 2026-07-23 | Grav versions >= 1.7.0 and before 2.0.9 contain a remote code execution vulnerability. FlexDirectory::dynamicDataField() resolves blueprint data-*@: directives by calling c… |
| CVE-2026-65607 | MEDIUM | 6.5 | 2026-07-23 | SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main … | |
| CVE-2026-65606 | CRITICAL | 9.6 | 2026-07-23 | SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an i… | |
| CVE-2026-65605 | CRITICAL | 9.6 | 2026-07-23 | SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/… | |
| CVE-2026-65604 | HIGH | 8.2 | 2026-07-23 | Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body e… | |
| CVE-2026-65603 | HIGH | Patched | 8.8 | 2026-07-22 | The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the… |
| CVE-2026-65602 | NONE | Patched | — | 2026-07-22 | Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allo… |
| CVE-2026-65601 | NONE | Patched | — | 2026-07-22 | Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[]… |
| CVE-2026-65600 | NONE | Patched | — | 2026-07-22 | Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path traversal in the ReplacePathRegex middleware. When Rep… |
| CVE-2026-65599 | NONE | Patched | — | 2026-07-22 | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key wa… |
| CVE-2026-65598 | NONE | Patched | — | 2026-07-22 | n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by sw… |
| CVE-2026-65597 | NONE | Patched | — | 2026-07-22 | n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into a… |
| CVE-2026-65596 | NONE | Patched | — | 2026-07-22 | n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAut… |
| CVE-2026-65595 | NONE | Patched | — | 2026-07-22 | n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. On instances where the… |
| CVE-2026-65594 | NONE | Patched | — | 2026-07-22 | n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated … |
| CVE-2026-65593 | NONE | Patched | — | 2026-07-22 | n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated atta… |
| CVE-2026-65592 | NONE | Patched | — | 2026-07-22 | n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cach… |
| CVE-2026-65591 | NONE | Patched | — | 2026-07-22 | n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions… |
| CVE-2026-65590 | NONE | Patched | — | 2026-07-22 | n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on… |
| CVE-2026-65589 | NONE | Patched | — | 2026-07-22 | n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow executi… |
| CVE-2026-6556 | CRITICAL | Patched | 9.1 | 2026-06-30 | @fastify/express versions 4.0.6 and earlier only rewrite the plugin prefix for middleware mount paths when the path argument is a string. Non-string mount paths (arrays of … |