Search
31,862 CVEs
CVEs (31,862, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 226–250 of 31,862 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-86076 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and di… |
| CVE-2026-86077 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed a paused execution without chec… |
| CVE-2026-86078 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows a… |
| CVE-2026-86079 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled inde… |
| CVE-2026-86080 | NONE | Patched | — | 2026-09-08 | n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub return… |
| CVE-2026-53933 | NONE | — | 2026-09-08 | Maravel, a PHP framework oriented towards dependency injection, prior to version 10.73.1 has a side-channel information disclosure issue. When a route was compiled with dyn… | |
| CVE-2026-49153 | NONE | — | 2026-09-08 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-49154 | NONE | — | 2026-09-08 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-49155 | NONE | — | 2026-09-08 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-49156 | NONE | — | 2026-09-08 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-78742 | NONE | — | 2026-09-08 | Silverpeas Core <=6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Multimedia library application introduction. | |
| CVE-2026-78971 | NONE | — | 2026-09-08 | In Halo <= 2.25.4, the plugin management feature allows users to install/update malicious plugins, which could let attackers execute any command with Halo process permissions. | |
| CVE-2026-79588 | NONE | — | 2026-09-08 | U-speed WIFI4 N300 T1 Pro v1.0.0 is vulnerable to Cleartext transmission of administration credentials over HTTP. | |
| CVE-2026-7809 | NONE | — | 2026-09-08 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-78738 | NONE | — | 2026-09-08 | Silverpeas Core 6.4.6 is vulnerable to Cross Site Scripting (XSS) via the Document management file upload feature. | |
| CVE-2026-45219 | NONE | — | 2026-09-08 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-45220 | NONE | — | 2026-09-08 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| CVE-2026-30754 | NONE | Patched | — | 2026-09-08 | A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP encoding process. In the nal_send function in libavformat/rtpenc_h264_hevc.c, a negative size paramet… |
| CVE-2026-86464 | NONE | — | 2026-09-08 | In the current development version of Eclipse aeriOS, for which no official release has yet been published, the Identity Manager (IdM) deployment included insecure default … | |
| CVE-2026-84197 | NONE | — | 2026-09-08 | In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclip… | |
| CVE-2026-85484 | NONE | Patched | — | 2026-09-08 | HTML::FormHandler versions before 0.410002 for Perl render option group labels and radio button labels into HTML without escaping. The Select, RadioGroup, CheckboxGroup an… |
| CVE-2026-85485 | NONE | Patched | — | 2026-09-08 | HTML::FormHandler versions before 0.410002 for Perl render some error messages into HTML without escaping. The Table form layout and the Bootstrap 2 and 3 wrappers splice … |
| CVE-2026-85630 | NONE | Patched | — | 2026-09-08 | HTML::FormHandler versions before 0.410002 for Perl render field attributes into HTML without escaping using the process_attrs method. Any application with fields or field… |
| CVE-2026-52486 | NONE | — | 2026-09-08 | An issue in OpenDDS 3.33.x allows a local attacker to cause a denial of service via the verify function in the SIgnedDocument module | |
| CVE-2026-49883 | NONE | — | 2026-09-08 | In checkReadPermission of PermissionsManager.java, there is a possible way to monitor sensitive device state data due to a missing permission check. This could lead to loca… |