Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-103261 | MEDIUM | 5.3 | Tornado before 6.5.9 fails to limit the number of query string fields in HTTPServerRequest.__init__, allowing remote attackers to cause event-loop stalling by sending requests with … | Oct 01, 2026 |
| CVE-2026-103260 | MEDIUM | 4.0 | n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an approval bypass vulnerability in the Send and Wait node's Approve Within Chat mode. Attackers can … | Oct 01, 2026 |
| CVE-2026-103259 | HIGH | 7.6 | n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver … | Oct 01, 2026 |
| CVE-2026-103258 | MEDIUM | 6.8 | n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation vulnerability in SendGrid, Freshservice, and ServiceNow nodes that allows attackers to bypass … | Oct 01, 2026 |
| CVE-2026-103257 | HIGH | 7.7 | n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the n8n node that fails to … | Oct 01, 2026 |
| CVE-2026-103256 | HIGH | 7.1 | n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to … | Oct 01, 2026 |
| CVE-2026-103255 | CRITICAL | 9.0 | n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId … | Oct 01, 2026 |
| CVE-2026-103254 | MEDIUM | 6.3 | n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in signed resume URL generation for Send-and-Wait … | Oct 01, 2026 |
| CVE-2026-103253 | HIGH | 8.7 | n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle Database node's Delete Table … | Oct 01, 2026 |
| CVE-2026-103252 | HIGH | 7.7 | n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the credential test endpoint that resolves … | Oct 01, 2026 |
| CVE-2026-103251 | HIGH | 7.1 | n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for … | Oct 01, 2026 |
| CVE-2026-103250 | HIGH | 8.1 | n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQL injection vulnerability in the MongoDB Chat Memory node that … | Oct 01, 2026 |
| CVE-2026-103249 | HIGH | 7.6 | n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown … | Oct 01, 2026 |
| CVE-2026-103248 | CRITICAL | 9.0 | n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode … | Oct 01, 2026 |
| CVE-2026-103247 | HIGH | 8.5 | n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared … | Oct 01, 2026 |
| CVE-2026-103246 | HIGH | 7.7 | n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inline agent node-tool introspection. Attackers can reference arbitrary credential IDs to … | Oct 01, 2026 |
| CVE-2026-103245 | MEDIUM | 5.3 | n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to verify the x-webflow-signature HMAC in the Webflow Trigger node webhook … | Oct 01, 2026 |
| CVE-2026-103244 | CRITICAL | 9.8 | ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup mode. … | Oct 01, 2026 |
| CVE-2026-103082 | HIGH | 7.2 | Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forgery.This issue affects LA-Studio Element Kit for Elementor: … | Oct 01, 2026 |
| CVE-2026-96577 | HIGH | 7.1 | A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of … | Oct 01, 2026 |
| CVE-2026-96256 | MEDIUM | 6.4 | The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Map … | Oct 01, 2026 |
| CVE-2026-92144 | HIGH | 7.2 | The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in … | Oct 01, 2026 |
| CVE-2026-83589 | MEDIUM | 6.1 | A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit … | Oct 01, 2026 |
| CVE-2026-7176 | UNKNOWN | — | CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for an … | Oct 01, 2026 |
| CVE-2026-7175 | UNKNOWN | — | CVE-2026-7175: the Business Name parameter in the /promoters/edit endpoint of the My Profile section of a promoter’s profile, which allows the injection of JavaScript code … | Oct 01, 2026 |