Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-8j4f-66v7-mqxc |
|
MINI-8j4f-66v7-mqxc |
| GHSA-jwm3-qcfw-c5pp |
|
Vulnerability in n8n (GHSA-jwm3-qcfw-c5pp)
vulnerability in n8n (GHSA-jwm3-qcfw-c5pp). Risk of unauthorized operations or information disclosure. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `2.25.7` or later.
|
| CVE-2026-54302 |
|
Cross-Site Scripting (XSS) in n8n (CVE-2026-54302)
cross-site scripting in n8n (CVE-2026-54302). Risk of unauthorized operations or information disclosure. Exploitable via ``webhookId``. Mitigation: upgrade to `2.25.7` or later.
|
| CVE-2026-54303 |
|
Cross-Site Scripting (XSS) in n8n (CVE-2026-54303)
cross-site scripting in n8n (CVE-2026-54303). Risk of unauthorized operations or information disclosure. Exploitable via ``NODES_EXCLUDE``. Mitigation: upgrade to `2.24.0` or later.
|
| CVE-2026-54312 |
|
Vulnerability in n8n (CVE-2026-54312)
vulnerability in n8n (CVE-2026-54312). Risk of unauthorized operations or information disclosure. Exploitable via ``Object.prototype``. Mitigation: upgrade to `2.24.0` or later.
|
| GHSA-mmhq-hrgp-xjhx |
|
Vulnerability in backoffice-charges-module (GHSA-mmhq-hrgp-xjhx)
vulnerability in backoffice-charges-module (GHSA-mmhq-hrgp-xjhx). Risk of unauthorized operations or information disclosure. Exploitable via ``preinstall``.
|
| MINI-v7pw-cxmh-2g6w |
|
MINI-v7pw-cxmh-2g6w |
| MINI-47x5-xw45-79gr |
|
MINI-47x5-xw45-79gr |
| GHSA-69qj-pvh9-c5wg |
|
OS Command Injection in yt-dlp (GHSA-69qj-pvh9-c5wg)
OS command injection in yt-dlp (GHSA-69qj-pvh9-c5wg). Successful exploitation can lead to full system takeover. Exploitable via ``printf``. Mitigation: upgrade to `2026.6.9` or later.
|
| MINI-c2j4-grmm-f8fj |
|
MINI-c2j4-grmm-f8fj |
| MINI-4rgj-mwqx-hcrx |
|
MINI-4rgj-mwqx-hcrx |
| GHSA-9p79-38q4-f6wc |
|
Vulnerability in bubblestr (GHSA-9p79-38q4-f6wc)
vulnerability in bubblestr (GHSA-9p79-38q4-f6wc). Risk of unauthorized operations or information disclosure.
|
| GHSA-w8vm-43w2-4xqf |
|
Vulnerability in vite-config-field (GHSA-w8vm-43w2-4xqf)
vulnerability in vite-config-field (GHSA-w8vm-43w2-4xqf). Risk of unauthorized operations or information disclosure. Exploitable via ``data.Cookie``.
|
| MAL-2026-5933 |
|
Vulnerability in react-vite-assert (MAL-2026-5933)
vulnerability in react-vite-assert (MAL-2026-5933). Risk of unauthorized operations or information disclosure. Exploitable via ``data.config``.
|
| GHSA-5xwj-q4j9-v44q |
|
Vulnerability in ssr-auth-sync (GHSA-5xwj-q4j9-v44q)
vulnerability in ssr-auth-sync (GHSA-5xwj-q4j9-v44q). Risk of unauthorized operations or information disclosure.
|
| GHSA-q8q6-p47p-ppp3 |
|
Vulnerability in package-uploader (GHSA-q8q6-p47p-ppp3)
vulnerability in package-uploader (GHSA-q8q6-p47p-ppp3). Risk of unauthorized operations or information disclosure. Exploitable via ``mailconfirmer``.
|
| GHSA-7cjh-m5vf-hp3r |
|
Vulnerability in mci-sdk (GHSA-7cjh-m5vf-hp3r)
vulnerability in mci-sdk (GHSA-7cjh-m5vf-hp3r). Risk of unauthorized operations or information disclosure. Exploitable via ``mci``.
|
| MAL-2026-5928 |
|
Vulnerability in chai-test-mocks (MAL-2026-5928)
vulnerability in chai-test-mocks (MAL-2026-5928). Risk of unauthorized operations or information disclosure. Exploitable via ``genMock``.
|
| MINI-hc4p-fvvv-mrjm |
|
MINI-hc4p-fvvv-mrjm |
| MINI-xwfm-q7gq-gx8g |
|
MINI-xwfm-q7gq-gx8g |
| MINI-5wg7-6cw8-4m4c |
|
MINI-5wg7-6cw8-4m4c |
| MINI-296g-f8f2-cqv6 |
|
MINI-296g-f8f2-cqv6 |
| MINI-w474-hp4r-fx89 |
|
MINI-w474-hp4r-fx89 |
| MINI-vv9q-h5jv-rr56 |
|
MINI-vv9q-h5jv-rr56 |
| MINI-9ppm-9rr8-m385 |
|
MINI-9ppm-9rr8-m385 |
| MINI-xh57-fj5g-36mc |
|
MINI-xh57-fj5g-36mc |
| MINI-qpcj-r6vp-6hqg |
|
MINI-qpcj-r6vp-6hqg |
| MINI-4749-m7pv-4w8f |
|
MINI-4749-m7pv-4w8f |
| MINI-pvm7-9cph-c52g |
|
MINI-pvm7-9cph-c52g |
| MINI-rhm3-rm5w-456q |
|
MINI-rhm3-rm5w-456q |
| MINI-ffww-3cm5-5ch8 |
|
MINI-ffww-3cm5-5ch8 |
| MINI-j5p8-rhwr-4ffg |
|
MINI-j5p8-rhwr-4ffg |
| MINI-rqqh-662w-2frj |
|
MINI-rqqh-662w-2frj |
| GHSA-cqfc-w7g9-4c7p |
|
Vulnerability in aillmgen (GHSA-cqfc-w7g9-4c7p)
vulnerability in aillmgen (GHSA-cqfc-w7g9-4c7p). Risk of unauthorized operations or information disclosure. Exploitable via ``aillmgen``.
|
| CVE-2026-22312 |
|
Vulnerability in CVE-2026-22312 (CVE-2026-22312)
vulnerability in CVE-2026-22312 (CVE-2026-22312). Data can be tampered with by attackers.
|
| CVE-2026-10303 |
|
Vulnerability in path-traversal (CVE-2026-10303)
vulnerability in path-traversal (CVE-2026-10303). Confidential information can be exposed externally.
|
| CVE-2026-22313 |
|
OS Command Injection in CVE-2026-22313 (CVE-2026-22313)
OS command injection in CVE-2026-22313 (CVE-2026-22313). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12117 |
|
Information Disclosure in devolutions (CVE-2026-12117)
vulnerability in devolutions (CVE-2026-12117). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0164 |
|
Vulnerability in google (CVE-2026-0164)
vulnerability in google (CVE-2026-0164). Successful exploitation can lead to full system takeover.
|
| CVE-2026-12425 |
|
Cross-Site Scripting (XSS) in powerschool (CVE-2026-12425)
cross-site scripting in powerschool (CVE-2026-12425). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12105 |
|
Vulnerability in devolutions (CVE-2026-12105)
vulnerability in devolutions (CVE-2026-12105). Confidential information can be exposed externally.
|
| CVE-2026-11890 |
|
Vulnerability in devolutions (CVE-2026-11890)
vulnerability in devolutions (CVE-2026-11890). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0162 |
|
Vulnerability in cpp (CVE-2026-0162)
vulnerability in cpp (CVE-2026-0162). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0165 |
|
Vulnerability in google (CVE-2026-0165)
vulnerability in google (CVE-2026-0165). Confidential information can be exposed externally.
|
| CVE-2026-0161 |
|
Vulnerability in cpp (CVE-2026-0161)
vulnerability in cpp (CVE-2026-0161). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0152 |
|
Buffer Overflow in c (CVE-2026-0152)
vulnerability in c (CVE-2026-0152). Successful exploitation can lead to full system takeover.
|
| CVE-2026-46448 |
|
Vulnerability in nova (CVE-2026-46448)
vulnerability in nova (CVE-2026-46448). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `33.0.2` or later.
|
| CVE-2026-0153 |
|
Out-of-Bounds Write in google (CVE-2026-0153)
out-of-bounds write in google (CVE-2026-0153). Successful exploitation can lead to full system takeover.
|
| CVE-2026-0156 |
|
Vulnerability in cpp (CVE-2026-0156)
vulnerability in cpp (CVE-2026-0156). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0158 |
|
Vulnerability in google (CVE-2026-0158)
vulnerability in google (CVE-2026-0158). Risk of unauthorized operations or information disclosure.
|