Vulnerability Database
A comprehensive hub for tracking high-impact vulnerabilities across application code and third-party libraries, for security teams and developers.
Trusted by Startups to Fortune 500
CVE-2026-1609
(8.1)
Improper Access Control (CWE-284) in Keycloak JWT Grants
Unauthorized Access and Privilege Misuse
CVE-2026-55652
(9.8)
Header Login Bypass (CWE-287) in Wekan Kanban Auth
Full Account Takeover and Privilege Escalation
CVE-2026-55234
(8.5)
Authorization Bypass (CWE-284) in Wekan Board Updates
Unauthorized Access to Private Board Content
CVE-2026-54458
(9.6)
Stored DOM XSS (CWE-79) in AVideo YPTSocket Plugin
Authenticated Session Hijack and Administrative Account Takeover
CVE-2026-52891
(9.9)
OS Command Injection (CWE-78) in Wekan Avatar Upload
Remote Code Execution on Server
CVE-2026-52890
(7.1)
Path Traversal & DoS (CWE-22) in Wekan Attachments
Arbitrary File Read and Denial of Service
CVE-2026-45313
(7.7)
Privilege Escalation (CWE-284) via Sandboxie GUI Hooks
Sandbox Escape and Arbitrary Code Execution as SYSTEM
CVE-2026-62312
(8.8)
Command Injection (CWE-78) in 9Router MCP Plugin Routing
Remote Code Execution on Host OS
CVE-2026-54052
(9.9)
Improper Tenant Access Control (CWE-639) in n8n-MCP
Cross-Tenant Data Exposure and Destructive Actions
CVE-2026-52887
(10.0)
SQL Injection (CWE-89) in NocoBase In-App Messages
Remote Code Execution via Database SQL Injection


















