Common Vulnerabilities and Exposures (CVE)

CVE-2026-65589

Jul 22, 2026 11:21:39 UTC

n8n versions before 1.123.64 fail to properly mask custom HTTP header credentials in LLM sub-node execution data, writing plaintext API keys and secrets to workflow execution records. Authenticated users with access to execution data can re...

CVE-2026-65016

Jul 22, 2026 11:21:38 UTC

n8n versions before 1.123.64, 2.29.8, and 2.30.1 contain a privilege escalation vulnerability in Enterprise SSO instance-role provisioning. The provisioning path maps an IdP-asserted role claim to an n8n global role but does not prevent ass...

CVE-2026-65015

Jul 22, 2026 11:21:38 UTC

n8n versions before 2.30.1 contain a privilege escalation vulnerability in the AI Agents feature where the node-execution tool lacks proper authorization checks. A Project Viewer user can escalate privileges by chatting with an agent that h...

CVE-2026-65014

Jul 22, 2026 11:21:37 UTC

n8n before 2.28.0 (and before 2.27.4 on the 2.27.x branch) registers the DELETE /${restEndpoint}/test-webhook/:id endpoint before authentication middleware is applied, allowing any unauthenticated network caller who knows a workflow ID to c...

CVE-2026-16544

Jul 22, 2026 11:15:53 UTC

A flaw was found in AWX. The websocket event consumer performs RBAC authorization checks only for event groups that are mapped in the consumer_access() function (job_events, workflow_events, ad_hoc_command_events). Three event groups - inve...

CVE-2026-61392

Jul 22, 2026 11:03:11 UTC

There is a information disclosure vulnerability in some Hikvision cameras, allowing unauthenticated attackers to obtain partial information from the device’s memory.

CVE-2026-61391

Jul 22, 2026 11:02:27 UTC

There is a stack-based buffer overflow vulnerability in some Hikvision cameras, which may allow authenticated attackers to cause device malfunction by sending specially crafted packets.

CVE-2026-61390

Jul 22, 2026 11:02:00 UTC

There is a heap buffer overflow vulnerability in some Hikvision cameras, which may allow unauthenticated attackers to cause device malfunction by sending specially crafted packets.

CVE-2026-57600

Jul 22, 2026 11:01:36 UTC

Insufficient validation of input parameters in the firmware of some Hikvision cameras allows unauthenticated attackers to retrieve partial sensitive data.

CVE-2026-57599

Jul 22, 2026 11:00:49 UTC

There is a privilege escalation vulnerability in some Hikvision cameras. Due to incorrect permission allocation in the device program, attackers can escalate privileges and gain full control of the device after authenticating via SSH.

CVE-2026-16473

Jul 22, 2026 10:07:12 UTC

A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one error in the SBC frame decoder allows a crafted audio payload to trigger a one-byte heap out-of-bounds read. This could allow an adjacent attacker streaming Bluetooth audi...

CVE-2026-14551

Jul 22, 2026 09:42:34 UTC

The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running...

CVE-2026-2406

Jul 22, 2026 08:51:21 UTC

Authorization bypass through User-Controlled key vulnerability in Universe Software Computer Marketing Trade and Industry Inc. Online Registration and Workflow Management System allows Exploiting Trust in Client. This issue affects Online ...

CVE-2026-15787

Jul 22, 2026 08:33:30 UTC

The Ultimate Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Navigation Menu Widget data-toggle-icon/data-close-icon Attributes in all versions up to, and including, 2.9.1 due to insufficient input...

CVE-2026-63264

Jul 22, 2026 08:32:25 UTC

The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.