Top technology
Linux 13140
Google 12544
Microsoft 12393
Oracle 7180
Apple 6692
Ibm 6470
Adobe 6390
Cisco 5759
Debian 3919
Mozilla 2912
Apache 2864
Redhat 2614
MEDIUM 5.3
CVE-2026-77082
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contains a regular expression denial of service (ReDoS) vulnerability in the Filter …
No fix yet
MEDIUM 5.1
CVE-2026-77081
n8n before 1.123.69, 2.x before 2.33.4, and 2.x before 2.34.1 contain an allowed-domains bypass in the GraphQL node. When the node's Authentication p…
No fix yet
HIGH 8.7
CVE-2026-77080
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which …
No fix yet
HIGH 7.4
CVE-2026-77079
n8n before 2.34.1 and 2.33.4 contains an authorization bypass in the custom project role deletion (reassignment) path. When deleting a custom project…
No fix yet
HIGH 7.2
CVE-2026-77077
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's prototype-freezing routine covers g…
No fix yet
HIGH 7.1
CVE-2026-77076
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain an information disclosure vulnerability in the GraphQL node. When a GraphQL request fails at…
No fix yet
HIGH 8.4
CVE-2026-77075
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an expression injection vulnerability in resource-locator field link preview…
No fix yet
MEDIUM 6.0
CVE-2026-77074
n8n versions before 1.123.69 contain a server-side request forgery vulnerability in the Edit Image node's Draw Text operation that allows authenticat…
No fix yet
MEDIUM 5.3
CVE-2026-77073
n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an exp…
No fix yet
HIGH 8.4
CVE-2026-77072
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a stored cross-site scripting vulnerability in the Form node's completion page. The completion page …
No fix yet
HIGH 7.1
CVE-2026-77071
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a PostgREST filter injection vulnerability in the Supabase node's Row Get Many, Delete, and Update o…
No fix yet
HIGH 7.1
CVE-2026-77070
n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggregate operations, which …
No fix yet
HIGH 8.7
CVE-2026-77068
n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP nod…
No fix yet
HIGH 7.5
CVE-2026-74021
Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.
No fix yet
HIGH 7.5
CVE-2026-74020
Unauthenticated Broken Access Control in Koji <= 2.2.1 versions.
No fix yet
HIGH 7.1
CVE-2026-74019
Unauthenticated Broken Access Control in EPROLO Dropshipping <= 2.4.2 versions.
No fix yet
CRITICAL 9.9
CVE-2026-74018
Subscriber Arbitrary File Upload in Warehouse Cargo <= 2.6.9 versions.
No fix yet
CRITICAL 9.9
CVE-2026-74016
Subscriber Arbitrary File Upload in Smart Cleaning <= 4.8.6 versions.
No fix yet
CRITICAL 9.9
CVE-2026-74014
Subscriber Arbitrary File Upload in IT Residence <= 3.2.1 versions.
No fix yet
HIGH 8.5
CVE-2026-74013
Subscriber SQL Injection in eShipper Commerce <= 2.16.13 versions.
No fix yet
CRITICAL 9.8
CVE-2026-74001
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
No fix yet
HIGH 8.5
CVE-2026-73998
Subscriber SQL Injection in WP w3all phpBB <= 3.0.5 versions.
No fix yet
CRITICAL 9.8
CVE-2026-73993
Unauthenticated PHP Object Injection in FundEngine <= 1.7.9 versions.
No fix yet
CRITICAL 9.9
CVE-2026-73992
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
No fix yet
MEDIUM 6.5
CVE-2026-73402
Subscriber Cross Site Scripting (XSS) in WP BASE Booking <= 6.3.2 versions.
No fix yet
CRITICAL 9.3
CVE-2026-68566
Unauthenticated SQL Injection in BookingPress Appointment Booking Pro <= 6.0.2 versions.
No fix yet
HIGH 7.1
CVE-2026-68564
Unauthenticated Cross Site Scripting (XSS) in NotificationX Pro <= 3.1.4 versions.
No fix yet
CRITICAL 9.8
CVE-2026-66682
Unauthenticated Privilege Escalation in Abandoned Cart Pro for WooCommerce <= 10.4.0 versions.
No fix yet
CRITICAL 9.3
CVE-2026-66680
Unauthenticated SQL Injection in Locatoraid Store Locator <= 3.9.72 versions.
No fix yet
HIGH 7.6
CVE-2026-66677
Subscriber Broken Authentication in Leyka <= 3.32.3 versions.
No fix yet