The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total49,664
Mitigations16,000
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
n8n< 1.123.67
NPM: n8n: Snowflake Node executeQuery Operation Allows SQL Injection via Unparameterized Expression Interpolation
5.3
9 hours ago
n8n< 1.123.67
NPM: n8n: PostgresTrigger Node SQL Injection Allows Authenticated Users to Execute Arbitrary SQL on Connected PostgreSQL Instances
5.8
9 hours ago
n8n< 1.123.67
NPM: n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
5.8
9 hours ago
next>= 14.1.1, < 15.5.21
NPM: Next.js: Server-Side Request Forgery in Server Actions on custom servers
8.3
9 hours ago
next>= 13.0.0, < 15.5.21
NPM: Next.js: Cache confusion of response bodies for requests with bodies
6
9 hours ago
next>= 13.0.0, < 15.5.21
NPM: Next.js: Cache confusion of response bodies for requests with bodies containing invalid UTF-8 byte sequences
6.3
9 hours ago
next>= 13.0.0, < 15.5.21
NPM: Next.js: Unbounded Server Action payload in Edge runtime
6.3
9 hours ago
next>= 12.0.0, < 15.5.21
NPM: Next.js: Server-Side Request Forgery in rewrites via attacker-controlled destination hostname
8.3
9 hours ago
next>= 15.5.0, < 15.5.21
NPM: Next.js: Denial of Service in the Image Optimization API using SVGs
6.3
9 hours ago
next>= 13.0.0, < 15.5.21
NPM: Next.js: Unauthenticated disclosure of internal Server Function endpoints
6.3
9 hours ago
next>= 16.0.0, < 16.2.11
NPM: Next.js: Middleware / Proxy bypass in App Router applications using Turbopack and single locale
8.3
9 hours ago
next>= 13.0.0, < 15.5.21
NPM: Next.js: Denial of Service in App Router using Server Actions
8.2
9 hours ago
n8n< 1.123.64
NPM: n8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
5.1
9 hours ago
n8n< 2.27.4
NPM: n8n: Unauthenticated Endpoint Allows Cancellation of Any User's Active Test Webhook
6.3
9 hours ago
n8n< 1.123.64
NPM: n8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
5.1
9 hours ago
n8n< 2.29.8
NPM: n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
5.1
9 hours ago
n8n< 2.29.8
NPM: n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
5.5
9 hours ago
n8n< 1.123.58
NPM: n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
5.3
9 hours ago
n8n< 2.28.0
NPM: n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
5.3
10 hours ago
n8n< 2.27.4
NPM: n8n: External Secrets Accessible via Workflow Expressions Outside Credentials
6.3
10 hours ago