Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.1 MEDIUM
CVE-2026-65599 — n8n before 1.123.64 Credential Exposure via JWT Header

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a credential exposure vulnerability: when configured with a Google Service Account key, the full PEM private key was mistakenly placed in the …

n8n | Remote | Information Disclosure
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.9 HIGH
CVE-2026-65598 — n8n before 1.123.64 Remote Code Execution via Git Clone

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a sy…

n8n | Remote | Race Condition
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.2 HIGH
CVE-2026-65597 — n8n before 1.123.64 DOM-Based XSS via Unsandboxed iframe

n8n before 1.123.64, 2.x before 2.29.8, and before 2.30.1 contains a DOM-based cross-site scripting vulnerability in the HTML preview, which renders execution output into an iframe srcdoc without the…

n8n | Remote | Cross-Site Scripting
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
5.1 MEDIUM
CVE-2026-65596 — n8n before 1.123.64 Credential Exfiltration via GraphQL Node

n8n before 1.123.64, 2.29.8, and 2.30.1 fails to enforce the "Allowed HTTP Request Domains" restriction on HTTP-based credentials (Header Auth, Basic Auth, Query Auth, OAuth) in the GraphQL node, unl…

n8n | Remote | Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.9 HIGH
CVE-2026-65595 — n8n before 2.30.1 Privilege Escalation via Token Exchange

n8n before 2.30.1 and 2.29.8 assigns all Public API key scopes to JWTs issued through the Token Exchange module regardless of the acting user's role. On instances where the Token Exchange feature and…

n8n | Remote | Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
5.1 MEDIUM
CVE-2026-65594 — n8n before 2.30.1 Missing OAuth Authorization Check

n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the work…

n8n | Remote | Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.3 MEDIUM
CVE-2026-65593 — n8n before 1.123.64 SSRF via Dynamic Node Parameters

n8n versions before 1.123.64 contain a server-side request forgery vulnerability in the dynamic-node-parameters endpoints that lack authorization scopes. Authenticated attackers can supply absolute U…

n8n | Remote | Server-Side Request Forgery
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.4 HIGH
CVE-2026-65592 — n8n before 1.123.64 Stored DOM XSS via cachedResultUrl

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a stored DOM cross-site scripting vulnerability in the Resource Locator component, which passes the workflow-persisted cachedResultUrl parameter to wi…

n8n | Remote | Cross-Site Scripting
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.9 HIGH
CVE-2026-65591 — n8n before 1.123.64 Sanitizer Bypass Remote Code Execution

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expr…

n8n | Remote | Injection
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
5.5 MEDIUM
CVE-2026-65590 — n8n before 2.30.1 Shell Sandbox Bypass on Linux Windows

n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands exe…

n8n | Remote | Misconfiguration
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
5.1 MEDIUM
CVE-2026-65589 — n8n before 1.123.64 Credential Exposure via LLM Node Execution Data

n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated u…

n8n | Remote | Information Disclosure
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.7 HIGH
CVE-2026-65016 — n8n before 1.123.64 Privilege Escalation via SSO Instance-Role

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an…

n8n | Remote | Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.2 HIGH
CVE-2026-65015 — n8n before 2.30.1 Privilege Escalation via run_node_tool

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate pr…

n8n | Remote | Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.3 MEDIUM
CVE-2026-65014 — n8n before 2.28.0 Authentication Bypass via test-webhook

n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated ne…

n8n | Remote | Authentication
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
5.3 MEDIUM
CVE-2026-61392 — Hikvision Camera Information Disclosure Vulnerability

There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.

Remote | Information Disclosure
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.2 HIGH
CVE-2026-61391 — Hikvision Camera Stack-Based Buffer Overflow

There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.

Remote | Memory Corruption
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.7 HIGH
CVE-2026-61390 — Hikvision Camera Heap Buffer Overflow

There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.

Remote | Memory Corruption
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
7.5 HIGH
CVE-2026-57600 — Hikvision Cameras Input Validation Vulnerability

Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.

Remote | Information Disclosure
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
6.6 MEDIUM
CVE-2026-57599 — Hikvision Camera Privilege Escalation Vulnerability

There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the d…

Remote | Authorization
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
8.1 HIGH
CVE-2026-4773 — OTP Bypass in Magarsus' IDM-MFA

Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.

Remote | Authentication
Jul 22, 2026 Jul 22, 2026
Jul 22, 2026
Jul 22, 2026
Showing 20 of 9684 Results