Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-53938 — OpenIDC/cjose has a heap buffer overflow in AES Key Wrap decryption (A128KW/A192KW/A256KW)

OpenIDC/cjose is a C library implementing the Javascript Object Signing and Encryption (JOSE). Prior to version 0.6.2.5, cjose's JWE decryption path for the AES Key Wrap key-management algorithms (`a…

| Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
0.0 NA
CVE-2026-53937 — MCP Kotlin SDK's unbounded line buffer in StdioServerTransport/StdioClientTransport leads…

MCP Kotlin SDK is the Kotlin Multiplatform software development kit for the Model Context Protocol. In versions 0.7.0 through 0.12.0, `ReadBuffer.append` in `kotlin-sdk-core/src/commonMain/kotlin/io/…

| Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
3.3 LOW
CVE-2026-86564 — Dpdk: dpdk: missing length validation before reading command_data in virtio-net control q…

A flaw was found in DPDK lib/vhost. Missing length validation before reading command_data in the virtio-net control-queue handler can cause an out-of-bounds read and a host process crash.

Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
8.7 HIGH
CVE-2026-55250 — Maravel-Framework Token Replay Vulnerability via Premature JWT Blacklist Eviction in Tagg…

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.74.0 has a high-severity Token Replay Vulnerability arising from a structural lifecycle mismatch between stateless …

Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.3 MEDIUM
CVE-2026-53639 — Sylius: IDOR on Shop Payment Request API endpoints

Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, the `GET /api/v2/shop/payment-requests/{hash}` and `PUT /api/v2/shop…

sylius | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
4.3 MEDIUM
CVE-2026-53638 — Sylius: Channel-based payment method restriction bypass on shop account orders API endpoi…

Sylius is an Open Source eCommerce Framework on Symfony. Starting in version 2.0.0 and prior to version 2.0.18, 2.1.15, and 2.2.6, an authorization bypass vulnerability exists in the shop account API…

sylius | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.5 MEDIUM
CVE-2026-53637 — Sylius: Cart FormComponent allows modification or deletion of an already-completed order

Sylius is an Open Source eCommerce Framework on Symfony. Versions 2.0.0 through 2.0.17, 2.1.0 through 2.1.14, and 2.2.0 through 2.2.5 contain an improper workflow enforcement vulnerability in the car…

sylius | Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
9.0 CRITICAL
CVE-2026-53581 — ntp: write path traversal

OPNsense is a FreeBSD based firewall and routing platform. Prior to version 26.1.9 of opnsense/core and version 26.4_20 of BE/opnsense/core, a path traversal vulnerability in the NTP configuration mo…

Remote | Path Traversal
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.3 MEDIUM
CVE-2026-47680 — Source controller: Improper path handling allows traversal

The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. In versions 0.0.17 through 1.…

source-controller | Remote | Path Traversal
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.1 MEDIUM
CVE-2026-18090 — Gdk-pixbuf: gdk-pixbuf: heap out-of-bounds read in uncompress() via crafted icns rle block

A flaw was found in gdk-pixbuf. This vulnerability allows a remote attacker to cause a heap out-of-bounds read by providing a specially crafted Apple Icon Image (.icns) file. The uncompress() functio…

enterprise_linux enterprise_linux | Memory Corruption
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.3 MEDIUM
CVE-2026-86996 — n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a work…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.3 MEDIUM
CVE-2026-86995 — n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling…

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote va…

Remote | Path Traversal
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.3 MEDIUM
CVE-2026-86994 — n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filt…

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardle…

Remote | Information Disclosure
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.9 MEDIUM
CVE-2026-86993 — n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership …

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
5.1 MEDIUM
CVE-2026-86085 — n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Ro…

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether t…

Remote | Authorization
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.0 MEDIUM
CVE-2026-86084 — n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled act…

Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.7 HIGH
CVE-2026-86083 — n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Le…

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printi…

Remote | Injection
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-86082 — n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model N…

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the …

Remote | Server-Side Request Forgery
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
7.1 HIGH
CVE-2026-86081 — n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a…

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_F…

Remote | Denial of Service
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
6.3 MEDIUM
CVE-2026-86080 — n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verifi…

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node re…

Remote | Authentication
Sep 08, 2026 Sep 08, 2026
Sep 08, 2026
Sep 08, 2026
Showing 20 of 13970 Results