VulnSea

Tagged “cve.org”

CVEs tagged cve.org, newest first.

20576 CVEsRSS

CVE-2026-86994Medium· 4.3
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the /rest/active-workflows endpoint returned every active workflow ID on the instance to any member regardless of sharing. Workflow activation, de…

▾ Sunlitn8n · n8nEPSS 0.34%via NVD
CVE-2026-86993Medium· 4.9
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, a Log Streaming event destination could reference a generic HTTP credential and decrypt whichever credential ID it named without an ownership chec…

▾ Sunlitn8n · n8nEPSS 0.46%via NVD
CVE-2026-86085Medium· 4.9
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. …

▾ Sunlitn8n · n8nEPSS 0.44%via NVD
CVE-2026-86084Medium· 5.5
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the public OIDC login and callback endpoints completed authentication even when OIDC was not the enabled active authentication method. An Enterpri…

▾ Sunlitn8n · n8nEPSS 0.46%via NVD
CVE-2026-86083High· 8.8
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and inter…

▾ Twilightn8n · n8nEPSS 0.66%via NVD
CVE-2026-86082Medium· 6.5
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow edit…

▾ Sunlitn8n · n8nEPSS 0.41%via NVD
CVE-2026-86081High· 7.1
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The p…

▾ Twilightn8n-io · n8nEPSS 0.56%via NVD
CVE-2026-86080Medium· 5.3
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the GitHub Trigger generated a webhook secret but discarded it when GitHub returned HTTP 422 and the node reused an existing webhook. Workflow sta…

▾ Sunlitn8n · n8nEPSS 0.26%via NVD
CVE-2026-86079Medium· 6.5
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Elasticsearch and ElasticSecurity nodes interpolated workflow-controlled index and document identifiers directly into REST request paths. An i…

▾ Sunlitn8n · n8nEPSS 0.49%via NVD
CVE-2026-86078Medium· 6.5
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API…

▾ Sunlitn8n · n8nEPSS 0.59%via NVD
CVE-2026-86077Medium· 6.5
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed a paused execution without checking that the target node supported chat messages. An anonymous f…

▾ Sunlitn8n · n8nEPSS 0.43%via NVD
CVE-2026-86076High· 8.8
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and did not reject reserved class member names. A class field named __s…

▾ Twilightn8n · n8nEPSS 0.79%via NVD
CVE-2026-86075High· 7.5
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the OAuth Dynamic Client Registration endpoint bounded redirect_uris but accepted arbitrarily large client_name and grant_types values. An unauthenticated re…

▾ Twilightn8n · n8nEPSS 0.61%via NVD
CVE-2026-81904Medium· 6.3
1mo ago

Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block

Concrete CMS below 9.5.3 registered view assets for every sub-block of a Stack, Container, or layout area without checking whether the requesting user could view that sub-block. An unauthenticated visitor could recover configuration valu…

▾ SunlitConcrete CMS · Concrete CMSEPSS 0.46%via NVD
CVE-2026-53933Medium· 6.9
1mo ago

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.73.1 has a side-channel information disclosure issue

Maravel, a PHP framework oriented towards dependency injection, prior to version 10.73.1 has a side-channel information disclosure issue. When a route was compiled with dynamic placeholders (e.g., `/api/v1/users/{id}`), the raw string pl…

▾ Sunlitmacropay-solutions · maravel-frameworkEPSS 0.54%via NVD
CVE-2026-86996Medium· 5.4
1mo ago

n8n is an open source workflow automation platform

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the workflow setting named This workflow can be called by was enforced by the Execute Workflow node but not when a workflow was attached to an Agent as a too…

▾ Sunlitn8n · n8nEPSS 0.29%via NVD
CVE-2026-78635Medium· 5.0
1mo ago

The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments

The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the und…

▾ SunlitOkta · Okta Privileged Access ClientEPSS 0.20%via NVD
CVE-2026-78631Medium· 5.3
1mo ago

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion

The Okta Hyperdrive Agent writes the decoded SAML bearer assertion to a local application log file at the default log level on every successful MFA completion. This insertion of sensitive information into the log file makes a live authen…

▾ Sunlitokta · hyperdriveEPSS 0.14%via NVD
CVE-2026-78630Medium· 6.7
1mo ago

The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands

The Okta Access Gateway does not neutralize shell metacharacters in SNMP configuration values before a privileged script uses them to construct OS commands. An authenticated local user with access to the management interface can supply c…

▾ Sunlitokta · access_gatewayEPSS 0.22%via NVD
CVE-2026-78629Medium· 5.6
1mo ago

The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user

The Okta Hyperdrive agent plugin returns a success response without a signed SAML assertion when the organization's policy requires no MFA for a given user. The response contains only a bare boolean validation indicator with no cryptogra…

▾ Sunlitokta · hyperdriveEPSS 0.14%via NVD
CVE-2026-19651High· 7.4
1mo ago

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5, and 3.33.1 through 3.33.3 could allow an attacker to bypass authorization by manipulating URL query parameters due to incorrect mapping of values to untrusted query string input.

▾ TwilightIBM · Enterprise Build of QuarkusEPSS 0.26%via NVD
CVE-2026-85983High· 7.8
1mo ago

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup

The Auth0 AD/LDAP Connector improperly processes a configuration value during service startup. This allows a low-privileged user on the host system to modify the connector's configuration. When the service restarts, the modified configur…

▾ TwilightAuth0 · Auth0 AD/LDAP ConnectorEPSS 0.20%via NVD
CVE-2026-85982Critical· 9.0
1mo ago

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel

The Auth0 AD/LDAP Connector is vulnerable to stored Cross-Site Scripting (XSS) issues due to improper HTML encoding of data in search results and updater log content displayed in the admin panel. An authenticated user with privileges to …

▾ MidnightAuth0 · Auth0 AD/LDAP ConnectorEPSS 0.40%via NVD
CVE-2026-85981Medium· 6.7
1mo ago

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication

The administrative panel of the Auth0 AD/LDAP Connector (versions 6.5.0 and earlier) listens on the local loopback interface without requiring authentication. This allows a local, low-privileged user or process on the host system to acce…

▾ SunlitAuth0 · Auth0 AD/LDAP ConnectorEPSS 0.18%via NVD
CVE-2026-84685Medium· 6.5
1mo ago

The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests

The react-native-auth0 SDK's web platform implementation does not scope its in-memory token cache to individual user sessions when operating in a server-side rendering (SSR) environment where module state persists across HTTP requests. U…

▾ SunlitAuth0 · react-native-auth0EPSS 0.28%via NVD
CVE-2026-81192High· 7.0
1mo ago

`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS

`OpenTelemetry.Resources.Host` NuGet package, which provides OpenTelemetry resource detectors for host, is affected by an untrusted search path vulnerability on macOS. Prior to version 1.16.0-beta.2, the `host.id` resource attribute dete…

▾ Twilightopen-telemetry · opentelemetry-dotnet-contribEPSS 0.18%via NVD
CVE-2026-78622Medium· 6.0
1mo ago

The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges

The Okta Verify for Windows uninstaller does not verify whether the user data directory is a filesystem junction before deleting its contents with elevated privileges. The delete operation follows the junction target, resulting in recurs…

▾ SunlitOkta · Okta Verify for WindowsEPSS 0.13%via NVD
CVE-2026-19625Medium· 5.3⚖ disputed
1mo ago

When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional…

When a Quarkus application has multiple endpoints secured by individual OIDC provider tenants, such as "/oidc-provider1" that is secured by the OIDC Provider 1 and "/oidc-provider2" that is secured by the OIDC Provider 2, and an optional…

▾ SunlitIBM · Enterprise Build of QuarkusEPSS 0.23%via NVD
CVE-2026-86819High· 7.1
1mo ago

Waves Central for macOS contains a local privilege escalation in the privileged helper service

Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its own, rather than …

▾ TwilightWaves Audio Ltd. · Waves CentralEPSS 0.10%via NVD
CVE-2026-77827High· 7.1PoC
1mo ago

Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'

Maono Link 3.8.13 MaonoAiServices Windows service allows local privilege escalation for a standard user account via improper write privileges in 'C:\ProgramData\Maono'. Fixed in 4.0.80.

▾ MidnightMaono · Maono LinkEPSS 0.16%via NVD
CVEs tagged “cve.org” — page 468 · VulnSea