Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2025-70887 — Ralphje Signify Privilege Escalation Vulnerability

An issue in ralphje Signify before v.0.9.2 allows a remote attacker to escalate privileges via the signed_data.py and the context.py components

signify | Remote | Authentication
Mar 25, 2026 Apr 01, 2026
Mar 25, 2026
Apr 01, 2026
8.8 HIGH
CVE-2026-33713 — n8n Vulnerable to SQL Injection in Data Table Node via orderByColumn Expression

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could exploit a SQL injection v…

n8n | Remote | Injection
Mar 25, 2026 Mar 27, 2026
Mar 25, 2026
Mar 27, 2026
9.4 CRITICAL
CVE-2026-33696 — n8n Vulnerable to Prototype Pollution in XML & GSuiteAdmin node parameters lead to RCE

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with permission to create or modify workflows could exploit a prototype pollu…

n8n | Remote | Injection
Mar 25, 2026 Mar 27, 2026
Mar 25, 2026
Mar 27, 2026
8.8 HIGH
CVE-2026-33665 — n8n: LDAP Email-Based Account Linking Allows Privilege Escalation and Account Takeover

n8n is an open source workflow automation platform. Prior to versions 2.4.0 and 1.121.0, when LDAP authentication is enabled, n8n automatically linked an LDAP identity to an existing local account if…

n8n | Remote | Authentication
Mar 25, 2026 Mar 30, 2026
Mar 25, 2026
Mar 30, 2026
8.5 HIGH
CVE-2026-33663 — n8n Vulnerable to Credential Theft via Name-Based Resolution and Permission Checker Bypas…

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.27, an authenticated user with the `global:member` role could exploit chained authorization flaws in n8…

n8n | Remote | Authorization
Mar 25, 2026 Mar 31, 2026
Mar 25, 2026
Mar 31, 2026
9.4 CRITICAL
CVE-2026-33660 — n8n Has Multiple Remote Code Execution Vulnerabilities in Merge Node AlaSQL SQL Mode

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could use the Merge node's "Com…

n8n | Remote | Injection
Mar 25, 2026 Mar 30, 2026
Mar 25, 2026
Mar 30, 2026
8.7 HIGH
CVE-2026-30587 — Seafile Server Stored XSS Vulnerability

Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro, and 12.0.20-pro, via the Seadoc (sdoc) editor. The applica…

seafile_server | Remote | Cross-Site Scripting
Mar 25, 2026 Mar 31, 2026
Mar 25, 2026
Mar 31, 2026
7.1 HIGH
CVE-2026-27496 — n8n has In-Process Memory Disclosure in its Task Runner

n8n is an open source workflow automation platform. Prior to versions 1.123.22, 2.9.3, and 2.10.1, an authenticated user with permission to create or modify workflows could use the JavaScript Task Ru…

n8n | Remote | Information Disclosure
Mar 25, 2026 Mar 27, 2026
Mar 25, 2026
Mar 27, 2026
8.8 HIGH
CVE-2025-67030 — Plexus-utils Directory Traversal Remote Code Execution

Directory Traversal vulnerability in the extractFile method of org.codehaus.plexus.util.Expand in plexus-utils before 6d780b3378829318ba5c2d29547e0012d5b29642. This allows an attacker to execute arbi…

plexus-utils | Remote | Path Traversal
Mar 25, 2026 Apr 01, 2026
Mar 25, 2026
Apr 01, 2026
Showing 20 of 6069 Results