4.3

CVSS3.1

CVE-2026-23624 - GLPI is vulnerable to session stealing on externally authenticated user change

GLPI is a free asset and IT management software package. In versions starting from 0.71 to before 10.0.23 and before 11.0.5, when remote authentication is used, based on SSO variables, a user can steal a GLPI session previously opened by another user on the same machine. This issue has been patched…

πŸ“… Published: Feb. 4, 2026, 5:15 p.m. πŸ”„ Last Modified: April 17, 2026, 11:30 p.m.

4.1

CVSS3.1

CVE-2026-22247 - GLPI is Vulnerable to SSRF via Webhooks

GLPI is a free asset and IT management software package. From version 11.0.0 to before 11.0.5, a GLPI administrator can perform SSRF request through the Webhook feature. This issue has been patched in version 11.0.5.

πŸ“… Published: Feb. 4, 2026, 5:10 p.m. πŸ”„ Last Modified: April 17, 2026, 11:30 p.m.

9.4

CVSS4.0

CVE-2026-25115 - n8n is vulnerable to Python sandbox escape

n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environment and execute code outside the intended security boundary. This issue has been patched in version 2.4.8.

πŸ“… Published: Feb. 4, 2026, 4:48 p.m. πŸ”„ Last Modified: April 17, 2026, 11:30 p.m.

9.4

CVSS4.0

CVE-2026-25056 - n8n Arbitrary File Write leading to RCE in n8n Merge Node

n8n is an open source workflow automation platform. Prior to versions 1.118.0 and 2.4.0, a vulnerability in the Merge node's SQL Query mode allowed authenticated users with permission to create or modify workflows to write arbitrary files to the n8n server's filesystem potentially leading to remote…

πŸ“… Published: Feb. 4, 2026, 4:47 p.m. πŸ”„ Last Modified: April 18, 2026, 2 p.m.

7.1

CVSS4.0

CVE-2026-25055 - n8n Arbitrary File Write on Remote Systems via SSH Node

n8n is an open source workflow automation platform. Prior to versions 1.123.12 and 2.4.0, when workflows process uploaded files and transfer them to remote servers via the SSH node without validating their metadata the vulnerability can lead to files being written to unintended locations on those r…

πŸ“… Published: Feb. 4, 2026, 4:47 p.m. πŸ”„ Last Modified: April 18, 2026, 2 p.m.

8.5

CVSS4.0

CVE-2026-25054 - n8n is Vulnerable to Stored Cross-Site Scripting via Markdown Rendering in Workflow UI

n8n is an open source workflow automation platform. Prior to versions 1.123.9 and 2.2.1, a Cross-Site Scripting (XSS) vulnerability existed in a markdown rendering component used in n8n's interface, including workflow sticky notes and other areas that support markdown content. An authenticated user…

πŸ“… Published: Feb. 4, 2026, 4:47 p.m. πŸ”„ Last Modified: April 17, 2026, 11:30 p.m.

9.4

CVSS4.0

CVE-2026-25053 - n8n is Vulnerable to OS Command Injection in Git Node

n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to execute arbitrary system commands or read arbitrary files on the n8n host. This issue has been patch…

πŸ“… Published: Feb. 4, 2026, 4:47 p.m. πŸ”„ Last Modified: April 17, 2026, 11:30 p.m.

9.4

CVSS4.0

CVE-2026-25052 - n8n Improper File Access Controls Allow Arbitrary File Read by Authenticated Users

n8n is an open source workflow automation platform. Prior to versions 1.123.18 and 2.5.0, a vulnerability in the file access controls allows authenticated users with permission to create or modify workflows to read sensitive files from the n8n host system. This can be exploited to obtain critical c…

πŸ“… Published: Feb. 4, 2026, 4:47 p.m. πŸ”„ Last Modified: April 17, 2026, 11:30 p.m.

8.5

CVSS4.0

CVE-2026-25051 - n8n Improper CSP Enforcement in Webhook Responses May Allow Stored XSS

n8n is an open source workflow automation platform. Prior to version 1.123.2, a Cross-Site Scripting (XSS) vulnerability has been identified in the handling of webhook responses and related HTTP endpoints. Under certain conditions, the Content Security Policy (CSP) sandbox protection intended to is…

πŸ“… Published: Feb. 4, 2026, 4:46 p.m. πŸ”„ Last Modified: April 17, 2026, 11:30 p.m.

7.7

CVSS3.1

CVE-2025-61917 - n8n Unsafe Buffer Allocation Allows In-Process Memory Disclosure in Task Runner

n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to allocate uninitialized memory. Such uninitialized buffers could contain residual data from within the …

πŸ“… Published: Feb. 4, 2026, 4:46 p.m. πŸ”„ Last Modified: Feb. 18, 2026, 5:46 p.m.
Total resulsts: 347946
Page 1679 of 34,795
Β« previous page Β» next page
Filters