Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
48891
Total
3931
Critical
14494
High
14248
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-46670 | CRITICAL | 9.8 | YesWiki is a wiki system written in PHP. Prior to version 4.6.4, an unauthenticated SQL injection in the Bazar form-import path (`FormManager::create()`) allows any unauthenticated … | Aug 11, 2026 |
| CVE-2026-19539 | UNKNOWN | — | Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read … | Aug 11, 2026 |
| CVE-2026-19434 | UNKNOWN | — | Cross-site Scripting in the finding renderer in maalfer Pentestify before 2.3.1 allows authenticated users to execute arbitrary JavaScript in the application origin via HTML markup … | Aug 11, 2026 |
| CVE-2026-72785 | MEDIUM | 4.3 | Craft CMS 5.0.0-RC1 through 5.10.5 contains an incorrect authorization vulnerability. A control-panel user holding only the viewCategories permission (without saveCategories) for a category group can … | Aug 11, 2026 |
| CVE-2026-72784 | MEDIUM | 5.4 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a server-side request forgery vulnerability in the GraphQL save<Volume>Asset mutation, which fetches … | Aug 11, 2026 |
| CVE-2026-72783 | MEDIUM | 6.2 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 contain a theoretical path traversal weakness in the ensurePathIsContained function of the Local … | Aug 11, 2026 |
| CVE-2026-72782 | MEDIUM | 6.5 | Craft CMS versions >= 5.0.0-RC1 before 5.10.6 and >= 4.0.0-RC1 before 4.18.2 interpolate environment variables and secrets (via ${ENV_VAR} strings in the elementId parameter) into … | Aug 11, 2026 |
| CVE-2026-72781 | HIGH | 8.8 | Craft CMS versions >= 5.0.0-RC1 before 5.10.7 and >= 4.0.0-RC1 before 4.18.3 contain a remote code execution vulnerability in the Twig sandbox mechanism. Because Craft … | Aug 11, 2026 |
| CVE-2026-72780 | MEDIUM | 6.5 | Craft CMS before 5.10.5 fails to persist updated credential counters after WebAuthn assertion validation in the passkey login endpoint. Attackers can replay captured login request … | Aug 11, 2026 |
| CVE-2026-72779 | MEDIUM | 4.5 | Craft CMS 5.0.0-RC1 before 5.10.6 and 4.0.0-RC1 before 4.18.2 contain an arbitrary file read vulnerability. The create() Twig function restricts class instantiation using a 5-entry … | Aug 11, 2026 |
| CVE-2026-72778 | HIGH | 8.8 | Craft CMS versions from 4.0.0-RC1 before 4.18.2 and from 5.0.0-RC1 before 5.10.6 contain an authenticated remote code execution vulnerability in the control panel element-search condition … | Aug 11, 2026 |
| CVE-2026-72775 | UNKNOWN | — | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a SQL injection vulnerability in the PostgresTrigger node, which interpolates user-supplied identifier parameters (channel, function, and trigger names) … | Aug 11, 2026 |
| CVE-2026-72774 | UNKNOWN | — | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a credential authorization bypass in the HTTP Request node. An authenticated member with edit access to a shared … | Aug 11, 2026 |
| CVE-2026-72773 | UNKNOWN | — | n8n before 2.31.5 and 2.32.x before 2.32.1 contain a path-confinement bypass in the @n8n/computer-use file-search (search_files) tool. A crafted search pattern can bypass the base-directory … | Aug 11, 2026 |
| CVE-2026-72772 | UNKNOWN | — | n8n before 2.32.1 (and before 2.31.5) is vulnerable to account takeover via the Token Exchange Embed Login feature. When a validly-signed incoming token was matched … | Aug 11, 2026 |
| CVE-2026-72771 | UNKNOWN | — | n8n versions before 2.32.1 fail to enforce the Allowed HTTP Request Domains allowlist in multiple AI and LLM nodes when user-supplied base or endpoint URLs … | Aug 11, 2026 |
| CVE-2026-72770 | UNKNOWN | — | n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operations that allows authenticated users to bypass repository-path … | Aug 11, 2026 |
| CVE-2026-72769 | UNKNOWN | — | n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a … | Aug 11, 2026 |
| CVE-2026-72768 | UNKNOWN | — | n8n versions before 2.32.1 contain a server-side request forgery protection bypass vulnerability in the MCP Client node that allows authenticated users to bypass SSRF protections. … | Aug 11, 2026 |
| CVE-2026-72767 | UNKNOWN | — | n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users with rights to … | Aug 11, 2026 |
| CVE-2026-72766 | UNKNOWN | — | n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a type confusion vulnerability in the Send Email node, which does not enforce that … | Aug 11, 2026 |
| CVE-2026-72765 | UNKNOWN | — | n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can … | Aug 11, 2026 |
| CVE-2026-72764 | UNKNOWN | — | n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.31.5, and 2.32.1), a user able … | Aug 11, 2026 |
| CVE-2026-72763 | UNKNOWN | — | n8n before 1.123.67, 2.31.5, and 2.32.1 validates credential-access only for a node's top-level credentials and not for credentials referenced inside an Execute Sub-workflow node's inline … | Aug 11, 2026 |
| CVE-2026-72762 | UNKNOWN | — | n8n versions before 1.123.67, 2.31.5, and 2.32.1 contain an arbitrary file write vulnerability in the Edit Image node, which passes its output format parameter to … | Aug 11, 2026 |