Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

3,173 CVEs

CVEs (3,173, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 126–150 of 3,173 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-65607 MEDIUM 6.5 2026-07-23 SiYuan before v3.7.2 contains a path traversal vulnerability in the /export/temp/ short-circuit branch of the serveExport handler (kernel/server/serve.go). Unlike the main …
CVE-2026-65606 CRITICAL 9.6 2026-07-23 SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an i&hellip;
CVE-2026-65605 CRITICAL 9.6 2026-07-23 SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/&hellip;
CVE-2026-65604 HIGH 8.2 2026-07-23 Skipper contains an incomplete fix for CVE-2026-50197 in which oversized request bodies bypass Open Policy Agent (OPA) deny-on-presence Rego policies. When a request body e&hellip;
CVE-2026-65603 HIGH Patched 8.8 2026-07-22 The Grav Login plugin (grav-plugin-login) versions <= 3.8.11 contain a privilege escalation flaw in the authenticated profile self-update handler (processUserProfile(), the&hellip;
CVE-2026-65602 NONE Patched &mdash; 2026-07-22 Traefik 3.6.0 through 3.6.22 and 3.7.0 through 3.7.6 fail to enforce the crossProviderNamespaces allowlist for IngressRouteTCP service serversTransport references (the allo&hellip;
CVE-2026-65601 NONE Patched &mdash; 2026-07-22 Traefik versions 3.7.0 through 3.7.6 contain a namespace confusion vulnerability in the Kubernetes Gateway API provider. When resolving HTTPRoute.spec.rules[].backendRefs[]&hellip;
CVE-2026-65600 NONE Patched &mdash; 2026-07-22 Traefik versions <= v2.11.51, >= v3.6.0 <= v3.6.22, and >= v3.7.0 <= v3.7.6 contain an authentication bypass via path traversal in the ReplacePathRegex middleware. When Rep&hellip;
CVE-2026-65599 NONE Patched &mdash; 2026-07-22 n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key wa&hellip;
CVE-2026-65598 NONE Patched &mdash; 2026-07-22 n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by sw&hellip;
CVE-2026-65597 NONE Patched &mdash; 2026-07-22 n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into a&hellip;
CVE-2026-65596 NONE Patched &mdash; 2026-07-22 n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAut&hellip;
CVE-2026-65595 NONE Patched &mdash; 2026-07-22 n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. On instances where the&hellip;
CVE-2026-65594 NONE Patched &mdash; 2026-07-22 n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated &hellip;
CVE-2026-65593 NONE Patched &mdash; 2026-07-22 n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated atta&hellip;
CVE-2026-65592 NONE Patched &mdash; 2026-07-22 n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cach&hellip;
CVE-2026-65591 NONE Patched &mdash; 2026-07-22 n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions&hellip;
CVE-2026-65590 NONE Patched &mdash; 2026-07-22 n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on&hellip;
CVE-2026-65589 NONE Patched &mdash; 2026-07-22 n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow executi&hellip;
CVE-2026-65550 MEDIUM 5.9 2026-07-23 Shop Manager Cross Site Scripting (XSS) in Tabs <= 2.5 versions.
CVE-2026-65540 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Request Forgery (CSRF) in Popup for CF7 with Sweet Alert <= 1.6.5 versions.
CVE-2026-65539 HIGH 7.1 2026-07-23 Unauthenticated Cross Site Request Forgery (CSRF) in Kwayy HTML Sitemap <= 4.0 versions.
CVE-2026-65538 MEDIUM 5.9 2026-07-23 Author Cross Site Scripting (XSS) in Machete <= 5.2 versions.
CVE-2026-65537 MEDIUM 4.3 2026-07-23 Subscriber Broken Access Control in Cyr to Lat reloaded – transliteration of links and file names <= 1.3.3 versions.
CVE-2026-65536 MEDIUM 6.5 2026-07-23 Unauthenticated Cross Site Request Forgery (CSRF) in افزونه حمل و نقل ووکامرس (پست پیشتاز و سفارشی، پیک موتوری) <= 4.4.5 versions.