The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,638
Mitigations15,990
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
next>= 16.0.0, < 16.2.11
NPM: Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
8.3
18 minutes ago
next>= 13.0.0, < 15.5.21
NPM: Next.js: Denial of Service in App Router using Server Actions
8.2
19 minutes ago
n8n< 1.123.64
NPM: n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
5.1
24 minutes ago
n8n< 2.27.4
NPM: n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
6.3
41 minutes ago
n8n< 1.123.64
NPM: n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
5.1
45 minutes ago
n8n< 2.29.8
NPM: n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
5.1
47 minutes ago
n8n< 2.29.8
NPM: n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
5.5
49 minutes ago
n8n< 1.123.58
NPM: n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
5.3
52 minutes ago
n8n< 2.28.0
NPM: n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
5.3
53 minutes ago
n8n< 2.27.4
NPM: n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
6.3
54 minutes ago
n8n< 1.123.61
NPM: n8n: MySQL v1 Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
5.3
55 minutes ago
n8n< 1.123.61
NPM: n8n: External Secrets Permission Bypass via Expression Parser Mismatch
6
56 minutes ago
n8n< 2.31.5
NPM: n8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
4.9
1 hour ago
n8n< 1.123.67
NPM: n8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
6.1
1 hour ago
n8n< 1.123.67
NPM: n8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
7.1
1 hour ago
n8n< 1.123.67
NPM: n8n: Edit Image Node Format Injection Allows Arbitrary File Write
7.7
1 hour ago
n8n< 1.123.67
NPM: n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
7.2
1 hour ago
n8n< 1.123.67
NPM: n8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
7.1
1 hour ago
n8n< 2.31.5
NPM: n8n: Expression sandbox escape via arrow-function bodies enabling command execution
8.7
1 hour ago
n8n< 1.123.67
NPM: n8n: Send Email Node Arbitrary File Read and SSRF via Nodemailer Content-Object Type Confusion
8.2
1 hour ago