Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-42180 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-42180 (CVE-2026-42180)
SSRF in CVE-2026-42180 (CVE-2026-42180). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v3/post.`.
|
| CVE-2026-44694 |
|
Vulnerability in n8n-mcp (CVE-2026-44694)
vulnerability in n8n-mcp (CVE-2026-44694). Risk of unauthorized operations or information disclosure. Exploitable via ``N8N_API_URL``. Mitigation: upgrade to `2.50.2` or later.
|
| CVE-2026-42176 |
|
Vulnerability in CVE-2026-42176 (CVE-2026-42176)
vulnerability in CVE-2026-42176 (CVE-2026-42176). Confidential information can be exposed externally.
|
| CVE-2026-41495 |
|
Vulnerability in CVE-2026-41495 (CVE-2026-41495)
vulnerability in CVE-2026-41495 (CVE-2026-41495). Risk of unauthorized operations or information disclosure. Exploitable via `POST /mcp`.
|
| CVE-2026-42160 |
|
Vulnerability in CVE-2026-42160 (CVE-2026-42160)
vulnerability in CVE-2026-42160 (CVE-2026-42160). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8178 |
|
Vulnerability in Amazon aws (CVE-2026-8178)
vulnerability in Amazon aws (CVE-2026-8178). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41511 |
|
Vulnerability in c (CVE-2026-41511)
vulnerability in c (CVE-2026-41511). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29202 |
|
Vulnerability in CVE-2026-29202 (CVE-2026-29202)
vulnerability in CVE-2026-29202 (CVE-2026-29202). Successful exploitation can lead to full system takeover. Exploitable via ``plugin``.
|
| CVE-2026-29201 |
|
Vulnerability in CVE-2026-29201 (CVE-2026-29201)
vulnerability in CVE-2026-29201 (CVE-2026-29201). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41889 |
|
SQL Injection in sqli (CVE-2026-41889)
SQL injection in sqli (CVE-2026-41889). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42028 |
|
Path Traversal in path-traversal (CVE-2026-42028)
path traversal in path-traversal (CVE-2026-42028). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-42030 |
|
Vulnerability in CVE-2026-42030 (CVE-2026-42030)
vulnerability in CVE-2026-42030 (CVE-2026-42030). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41887 |
|
Path Traversal in CVE-2026-41887 (CVE-2026-41887)
path traversal in CVE-2026-41887 (CVE-2026-41887). Confidential information can be exposed externally.
|
| CVE-2026-38360 |
|
Path Traversal in path-traversal (CVE-2026-38360)
path traversal in path-traversal (CVE-2026-38360). Successful exploitation can lead to full system takeover.
|
| CVE-2026-44499 |
|
Vulnerability in zebrad (CVE-2026-44499)
vulnerability in zebrad (CVE-2026-44499). Risk of unauthorized operations or information disclosure. Exploitable via ``inv``. Mitigation: upgrade to `4.4.0` or later.
|
| CVE-2026-42353 |
|
Path Traversal in express (CVE-2026-42353)
path traversal in express (CVE-2026-42353). Confidential information can be exposed externally.
|
| CVE-2026-42793 |
|
Vulnerability in dos (CVE-2026-42793)
vulnerability in dos (CVE-2026-42793). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41886 |
|
Cross-Site Scripting (XSS) in CVE-2026-41886 (CVE-2026-41886)
cross-site scripting in CVE-2026-41886 (CVE-2026-41886). Data can be tampered with by attackers.
|
| CVE-2026-42794 |
|
Cross-Site Scripting (XSS) in CVE-2026-42794 (CVE-2026-42794)
cross-site scripting in CVE-2026-42794 (CVE-2026-42794). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41591 |
|
Cross-Site Scripting (XSS) in CVE-2026-41591 (CVE-2026-41591)
cross-site scripting in CVE-2026-41591 (CVE-2026-41591). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41070 |
|
Authentication Bypass in openvpn (CVE-2026-41070)
authentication bypass in openvpn (CVE-2026-41070). Confidential information can be exposed externally. Exploitable via ``plugin``.
|
| CVE-2026-41690 |
|
Path Traversal in express (CVE-2026-41690)
path traversal in express (CVE-2026-41690). Data can be tampered with by attackers.
|
| CVE-2026-41683 |
|
Cross-Site Scripting (XSS) in express (CVE-2026-41683)
cross-site scripting in express (CVE-2026-41683). Data can be tampered with by attackers.
|
| CVE-2026-41693 |
|
Path Traversal in CVE-2026-41693 (CVE-2026-41693)
path traversal in CVE-2026-41693 (CVE-2026-41693). Confidential information can be exposed externally.
|
| CVE-2026-41885 |
|
Path Traversal in CVE-2026-41885 (CVE-2026-41885)
path traversal in CVE-2026-41885 (CVE-2026-41885). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41883 |
|
Vulnerability in CVE-2026-41883 (CVE-2026-41883)
vulnerability in CVE-2026-41883 (CVE-2026-41883). Successful exploitation can lead to full system takeover.
|
| CVE-2026-34354 |
|
Vulnerability in privilege-escalation (CVE-2026-34354)
vulnerability in privilege-escalation (CVE-2026-34354). Successful exploitation can lead to full system takeover.
|
| CVE-2026-29974 |
|
Vulnerability in CVE-2026-29974 (CVE-2026-29974)
vulnerability in CVE-2026-29974 (CVE-2026-29974). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29975 |
|
Vulnerability in c (CVE-2026-29975)
vulnerability in c (CVE-2026-29975). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-29972 |
|
Vulnerability in c (CVE-2026-29972)
vulnerability in c (CVE-2026-29972). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44500 |
|
Vulnerability in deserialization (CVE-2026-44500)
vulnerability in deserialization (CVE-2026-44500). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44497 |
|
Vulnerability in zfnd (CVE-2026-44497)
vulnerability in zfnd (CVE-2026-44497). Data can be tampered with by attackers. Exploitable via ``zcashd``. Mitigation: upgrade to `4.4.0` or later.
|
| CVE-2026-41588 |
|
Vulnerability in timing-attack (CVE-2026-41588)
vulnerability in timing-attack (CVE-2026-41588). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41574 |
|
Authentication Bypass in CVE-2026-41574 (CVE-2026-41574)
authentication bypass in CVE-2026-41574 (CVE-2026-41574). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41570 |
|
Vulnerability in phpunit-project (CVE-2026-41570)
vulnerability in phpunit-project (CVE-2026-41570). Successful exploitation can lead to full system takeover.
|
| CVE-2026-41524 |
|
Cross-Site Scripting (XSS) in laravel (CVE-2026-41524)
cross-site scripting in laravel (CVE-2026-41524). Confidential information can be exposed externally.
|
| CVE-2026-41576 |
|
Cross-Site Scripting (XSS) in CVE-2026-41576 (CVE-2026-41576)
cross-site scripting in CVE-2026-41576 (CVE-2026-41576). Confidential information can be exposed externally.
|
| CVE-2026-41575 |
|
Cross-Site Scripting (XSS) in CVE-2026-41575 (CVE-2026-41575)
cross-site scripting in CVE-2026-41575 (CVE-2026-41575). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41308 |
|
Vulnerability in CVE-2026-41308 (CVE-2026-41308)
vulnerability in CVE-2026-41308 (CVE-2026-41308). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-41487 |
|
Vulnerability in CVE-2026-41487 (CVE-2026-41487)
vulnerability in CVE-2026-41487 (CVE-2026-41487). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-38361 |
|
Vulnerability in CVE-2026-38361 (CVE-2026-38361)
vulnerability in CVE-2026-38361 (CVE-2026-38361). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-37431 |
|
SQL Injection in sqli (CVE-2026-37431)
SQL injection in sqli (CVE-2026-37431). Successful exploitation can lead to full system takeover.
|
| CVE-2025-67486 |
|
Vulnerability in CVE-2025-67486 (CVE-2025-67486)
vulnerability in CVE-2025-67486 (CVE-2025-67486). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-7864 |
|
Vulnerability in CVE-2026-7864 (CVE-2026-7864)
vulnerability in CVE-2026-7864 (CVE-2026-7864). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44340 |
|
Path Traversal in praison (CVE-2026-44340)
path traversal in praison (CVE-2026-44340). Data can be tampered with by attackers.
|
| CVE-2026-44336 |
|
Vulnerability in praison (CVE-2026-44336)
vulnerability in praison (CVE-2026-44336). Successful exploitation can lead to full system takeover. Exploitable via ``praisonai.rules.create``.
|
| CVE-2026-44334 |
|
Code Injection in praison (CVE-2026-44334)
code injection in praison (CVE-2026-44334). Successful exploitation can lead to full system takeover. Exploitable via `POST /v1/recipes/run`.
|
| CVE-2026-44337 |
|
Vulnerability in praison (CVE-2026-44337)
vulnerability in praison (CVE-2026-44337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44129 |
|
Vulnerability in CVE-2026-44129 (CVE-2026-44129)
vulnerability in CVE-2026-44129 (CVE-2026-44129). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-44339 |
|
Vulnerability in praison (CVE-2026-44339)
vulnerability in praison (CVE-2026-44339). Data can be tampered with by attackers.
|