Search
23,162 CVEs
CVEs (23,162, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 101–125 of 23,162 (capped at 500)
| CVE ID | Severity ↓ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-65595 | NONE | Patched | — | 2026-07-22 | n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. On instances where the… |
| CVE-2026-65596 | NONE | Patched | — | 2026-07-22 | n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAut… |
| CVE-2026-65597 | NONE | Patched | — | 2026-07-22 | n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into a… |
| CVE-2026-65014 | NONE | Patched | — | 2026-07-22 | n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allo… |
| CVE-2026-65015 | NONE | Patched | — | 2026-07-22 | n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project … |
| CVE-2026-65016 | NONE | Patched | — | 2026-07-22 | n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an Id… |
| CVE-2026-65589 | NONE | Patched | — | 2026-07-22 | n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow executi… |
| CVE-2026-65590 | NONE | Patched | — | 2026-07-22 | n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on… |
| CVE-2026-16551 | NONE | — | 2026-07-22 | Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only. | |
| CVE-2026-63264 | NONE | — | 2026-07-22 | Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the prod… | |
| CVE-2026-63048 | NONE | — | 2026-07-22 | Joomla Extension - joomlack.fr - Improper access control in Page Builder CK < 3.6.2 - The Joomla extension Page Builder CK is vulnerable to an authenticated arbitrary file … | |
| CVE-2026-45820 | NONE | — | 2026-07-22 | fflate through 0.8.2 is vulnerable to denial of service via an infinite loop in unzipSync(). A crafted ZIP archive with a central directory entry declaring compressed_size=… | |
| CVE-2026-56844 | NONE | — | 2026-07-22 | A vulnerability in the Veeam Updater component of the Veeam Software Appliance that could allow a local user to elevate their privileges and gain root-level access to the u… | |
| CVE-2026-56817 | NONE | Patched | — | 2026-07-21 | Netty is a network application framework for development of protocol servers and clients. In versions 4.2.0.Final through 4.2.15.Final and 4.1.0.Final through 4.1.135.Final… |
| CVE-2026-16415 | NONE | — | 2026-07-21 | Insufficient validation of untrusted input in Extensions in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) v… | |
| CVE-2026-16416 | NONE | — | 2026-07-21 | Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malicious network traffic. (Chr… | |
| CVE-2026-16417 | NONE | — | 2026-07-21 | Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafte… | |
| CVE-2026-16418 | NONE | — | 2026-07-21 | Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium… | |
| CVE-2026-16419 | NONE | — | 2026-07-21 | Out of bounds read and write in ANGLE in Google Chrome on Android prior to 150.0.7871.182 allowed a remote attacker to potentially perform a sandbox escape via a crafted HT… | |
| CVE-2026-16420 | NONE | — | 2026-07-21 | Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium … | |
| CVE-2026-16421 | NONE | — | 2026-07-21 | Inappropriate implementation in WebAudio in Google Chrome prior to 150.0.7871.182 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML pa… | |
| CVE-2026-16413 | NONE | — | 2026-07-21 | Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox es… | |
| CVE-2026-16414 | NONE | — | 2026-07-21 | Insufficient validation of untrusted input in Chromecast in Google Chrome prior to 150.0.7871.182 allowed a local attacker to potentially perform a sandbox escape via malic… | |
| CVE-2026-8986 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 is vulnerable to OS command injection when processing OCPP GetDiagnostics requests. A malicious or compromised OCPP serv… | |
| CVE-2026-8987 | NONE | — | 2026-07-21 | Autel Maxi Charger Single firmware through V1.03.51 contains a heap-based buffer overflow in the set_ap_param command handled by the /localcfg endpoint. An authenticated at… |