Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

66,771 CVEs

CVEs (66,771, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 101–125 of 66,771 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-65595 NONE Patched — 2026-07-22 n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. On instances where the…
CVE-2026-65596 NONE Patched — 2026-07-22 n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAut…
CVE-2026-65597 NONE Patched — 2026-07-22 n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into a…
CVE-2026-65014 NONE Patched — 2026-07-22 n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allo…
CVE-2026-65015 NONE Patched — 2026-07-22 n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project …
CVE-2026-65016 NONE Patched — 2026-07-22 n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an Id…
CVE-2026-65589 NONE Patched — 2026-07-22 n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow executi…
CVE-2026-65590 NONE Patched — 2026-07-22 n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on…
CVE-2026-16551 NONE — 2026-07-22 Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only.
CVE-2026-63264 NONE &mdash; 2026-07-22 Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the prod&hellip;
CVE-2026-63048 NONE &mdash; 2026-07-22 Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file &hellip;
CVE-2026-45820 NONE &mdash; 2026-07-22 fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=&hellip;
CVE-2026-56844 NONE &mdash; 2026-07-22 A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the u&hellip;
CVE-2026-56817 NONE Patched &mdash; 2026-07-21 Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final&hellip;
CVE-2026-16415 NONE &mdash; 2026-07-21 Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) v&hellip;
CVE-2026-16416 NONE &mdash; 2026-07-21 Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chr&hellip;
CVE-2026-16417 NONE &mdash; 2026-07-21 Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafte&hellip;
CVE-2026-16418 NONE &mdash; 2026-07-21 Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium&hellip;
CVE-2026-16419 NONE &mdash; 2026-07-21 Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HT&hellip;
CVE-2026-16420 NONE &mdash; 2026-07-21 Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium &hellip;
CVE-2026-16421 NONE &mdash; 2026-07-21 Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pa&hellip;
CVE-2026-16413 NONE &mdash; 2026-07-21 Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox es&hellip;
CVE-2026-16414 NONE &mdash; 2026-07-21 Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malic&hellip;
CVE-2026-8986 NONE &mdash; 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP serv&hellip;
CVE-2026-8987 NONE &mdash; 2026-07-21 Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated at&hellip;