Total CVEs

150,998

Critical Severity

5,040

High Severity

17,683

Last 7 Days

2,050
Quick preset (or use dates below)
Clear Filters
πŸ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years β†’
Showing 2,781 - 2,800 of 47,403 CVEs
CVE-2026-65589 MEDIUM - 6.5

n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can read exposed header values and credentials that persist in the...

Vendor: n8n-io
Product: n8n
Published: Jul 22, 2026
Source: NVD
CVE-2026-65016 HIGH - 8.8

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent assignment of the global:owner role (unlike the token-exchange ...

Vendor: n8n-io
Product: n8n
Published: Jul 22, 2026
Source: NVD
CVE-2026-65015 HIGH - 8.8

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that has node tools enabled, executing arbitrary nodes and accessi...

Vendor: n8n-io
Product: n8n
Published: Jul 22, 2026
Source: NVD
CVE-2026-65014 MEDIUM - 5.3

n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to cancel that workflow's active test webhook registration....

Vendor: n8n-io
Product: n8n
Published: Jul 22, 2026
Source: NVD
CVE-2026-61392 MEDIUM - 5.3

There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.

Vendor: Hikvision
Product: DS-2CD Series, DS-2DE Series
Published: Jul 22, 2026
Source: NVD
CVE-2026-61391 HIGH - 7.2

There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.

Vendor: Hikvision
Product: DS-2CD Series, DS-2DE Series
Published: Jul 22, 2026
Source: NVD
CVE-2026-61390 HIGH - 7.7

There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.

Vendor: Hikvision
Product: DS-2CD Series, DS-2DE Series
Published: Jul 22, 2026
Source: NVD
CVE-2026-57600 HIGH - 7.5

Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.

Vendor: Hikvision
Product: DS-2CD Series, DS-2DE Series, DS-2DP Series, DS-2TD Series
Published: Jul 22, 2026
Source: NVD
CVE-2026-57599 MEDIUM - 6.6

There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.

Vendor: Hikvision
Product: DS-2CD Series
Published: Jul 22, 2026
Source: NVD
CVE-2026-4773 HIGH - 8.1

Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.

Published: Jul 22, 2026
Source: NVD
CVE-2026-44192 MEDIUM - 6.6

A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection. By doing so, the attacker can cause the server to write files to unauthorized locations on the ...

Vendor: Red Hat
Product: Red Hat Ansible Automation Platform 2
Published: Jul 22, 2026
Source: NVD
CVE-2026-44190 HIGH - 7.8

A flaw was found in the Ansible Lightspeed Visual Studio Code extension. This Command Injection vulnerability (CWE-78) allows a remote attacker to execute unauthorized commands on a user's system. The issue occurs because the `ansible.python.activationScript` setting, intended for a virtual env...

Vendor: Red Hat
Product: Red Hat Ansible Automation Platform 2
Published: Jul 22, 2026
Source: NVD
CVE-2026-44189 HIGH - 7.8

A flaw was found in the Visual Studio Code Ansible Lightspeed extension's AnsiblePlaybookRunProvider. This command injection vulnerability allows an attacker to craft a malicious playbook filename containing special characters. When a victim runs the playbook, these characters are not properly ...

Vendor: Red Hat
Product: Red Hat Ansible Automation Platform 2
Published: Jul 22, 2026
Source: NVD

A flaw was found in the Ansible Lightspeed extension for Visual Studio Code. This vulnerability allows an attacker with local access to the workstation, or malware running with the user's privileges, to read the Google Gemini API key. The extension insecurely stores the API key in plain text wi...

Vendor: Red Hat
Product: Red Hat Ansible Automation Platform 2
Published: Jul 22, 2026
Source: NVD

Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB module) allows Excessive Allocation. This issue affects OpenCanary 0.9.8 only.

Vendor: Thinkst Applied Research
Product: OpenCanary
Published: Jul 22, 2026
Source: NVD
CVE-2026-16544 MEDIUM - 6.5

A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). Three event groups - inventory_update_events, project_update_events, and system_job_e...

Vendor: Red Hat
Product: Red Hat Ansible Automation Platform 2
Published: Jul 22, 2026
Source: NVD
CVE-2025-13146 MEDIUM - 6.5

The The Contact Form 7 – Dynamic Text Extension plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.0.6. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This m...

Vendor: sevenspark
Product: Contact Form 7 – Dynamic Text Extension
Published: Jul 22, 2026
Source: NVD
CVE-2026-16473 MEDIUM - 4.3

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audio to read a single byte of adjacent heap memory.

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jul 22, 2026
Source: NVD
CVE-2026-14551 HIGH - 8.8

The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory %ProgramData...

Vendor: servereye GmbH
Product: servereye Windows Agent (Sensorhub)
Published: Jul 22, 2026
Source: NVD

Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.

Vendor: joomshopping.com
Product: JoomShopping extension for Joomla
Published: Jul 22, 2026
Source: NVD