Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.7 HIGH
CVE-2026-103257 — n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via n8n Node

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the n8n node that fails to validate resource identifiers. Attackers can…

n8n | Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-103256 — n8n before 2.39.6 and 2.40.x before 2.40.1 Credentials Leak via preAuthentication Hook

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a credentials leak vulnerability in the Wekan and Baserow username-and-password credentials that sends unencrypted passwords to unvalidated…

n8n | Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.0 CRITICAL
CVE-2026-103255 — n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal and Query Injection via Supabase

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in the Supabase node where the tableId parameter is inserted into request …

n8n | Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.3 MEDIUM
CVE-2026-103254 — n8n before 1.123.80, 2.39.6, and 2.40.1 Path Traversal via Resume URL Generation

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a path traversal vulnerability in signed resume URL generation for Send-and-Wait approvals. Attackers wit…

n8n | Remote | Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.7 HIGH
CVE-2026-103253 — n8n before 1.123.80, 2.39.6, and 2.40.1 SQL Injection via Oracle Database Drop Table

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an SQL injection vulnerability in the Oracle Database node's Delete Table Drop operation. Attackers can i…

n8n | Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.7 HIGH
CVE-2026-103252 — n8n before 1.123.80, 2.39.6, and 2.40.1 Information Disclosure via Credential Test Endpoi…

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain an authorization bypass vulnerability in the credential test endpoint that resolves project-scoped variab…

n8n | Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-103251 — n8n before 1.123.80, 2.39.6, and 2.40.1 Package Install Validation Bypass via PubSub

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a validation bypass vulnerability in the community package installation handler for queue mode deployment…

n8n | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.1 HIGH
CVE-2026-103250 — n8n before 1.123.80, 2.39.6, and 2.40.1 NoSQL Injection via MongoDB Chat Memory

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a NoSQL injection vulnerability in the MongoDB Chat Memory node that fails to validate the sessionId para…

n8n | Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.6 HIGH
CVE-2026-103249 — n8n before 1.123.80, 2.39.6, and 2.40.1 Stored DOM XSS via Resource Locator

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a stored DOM cross-site scripting vulnerability in Resource Locator parameter dropdown link handling. Wor…

n8n | Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.0 CRITICAL
CVE-2026-103248 — n8n before 1.123.80, 2.39.6, and 2.40.1 PostgREST Filter Injection via Supabase

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 contain a filter injection vulnerability in the Supabase node's Filters (String) mode that fails to escape field …

n8n | Remote | Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.5 HIGH
CVE-2026-103247 — n8n before 1.123.80 Credential Tampering via Duplicate Node IDs

n8n versions before 1.123.80 contain a credential tampering vulnerability where duplicate node IDs bypass the workflow credential tamper guard. Attackers with editor access to shared workflows can ex…

n8n | Remote | Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.7 HIGH
CVE-2026-103246 — n8n before 2.39.6 and 2.40.x before 2.40.1 Credential Disclosure via Node-Tool Introspect…

n8n versions before 2.39.6 and 2.40.0 before 2.40.1 fail to validate credential ownership during inline agent node-tool introspection. Attackers can reference arbitrary credential IDs to decrypt and …

n8n | Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.3 MEDIUM
CVE-2026-103245 — n8n before 1.123.80, 2.39.6, and 2.40.1 Missing Webhook Signature Verification

n8n versions before 1.123.80, from 2.0.0 before 2.39.6, and from 2.40.0 before 2.40.1 fail to verify the x-webflow-signature HMAC in the Webflow Trigger node webhook handler. Unauthenticated attacker…

n8n | Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.8 CRITICAL
CVE-2026-103244 — ground-station before 0.8.0 Authentication Bypass via setup.restore

ground-station versions before 0.8.0 contain an authentication bypass vulnerability in the setup.restore command that allows unauthenticated attackers to execute arbitrary SQL during first-run setup …

Remote | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-103082 — WordPress LA-Studio Element Kit for Elementor plugin <= 1.6.2 - Server Side Request Forge…

Server-Side Request Forgery (SSRF) vulnerability in LA-Studio LA-Studio Element Kit for Elementor lastudio-element-kit allows Server Side Request Forgery.This issue affects LA-Studio Element Kit for …

element_kit_for_elementor | Remote | Server-Side Request Forgery
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.1 HIGH
CVE-2026-96577 — Oc-mirror__release-4.21: embedded local cache registry listens on all interfaces without …

A flaw was found in oc-mirror. During mirroring operations, the embedded local cache registry binds to all network interfaces without authentication or encryption instead of restricting access to the…

openshift_container_platform | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.4 MEDIUM
CVE-2026-96256 — Gutenberg Essential Blocks <= 6.4.5 - Authenticated (Contributor+) Stored Cross-Site Scri…

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Google Map block's 'marker' attribute in versio…

essential_blocks | Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-92144 — Forminator Forms <= 1.57.2 - Unauthenticated Stored Cross-Site Scripting via 'postdata-1[…

The Forminator Forms – Contact Form, Payment Form & Custom Form Builder plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'postdata-1[post-custom]' Parameter in all versions up to…

forminator | Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.1 MEDIUM
CVE-2026-83589 — Oauth-proxy: open redirect via /\ and /\t bypass in post-login redirect

A flaw was found in oauth-proxy. The application fails to properly validate the destination redirect parameter (`rd`) during post-login redirection. A remote attacker can exploit this vulnerability b…

openshift_container_platform | Remote | Misconfiguration
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
4.8 MEDIUM
CVE-2026-7176 — Multiple vulnerabilities in Entradium by Crocantickets

CVE-2026-7176: the Help text and Title parameters in the endpoint /events/<event_name>-<event_city>/custom_form/edit during the process of creating or modifying forms associated with ticket sales for…

Remote | Cross-Site Scripting
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Showing 20 of 15063 Results