Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
41987
Total
3420
Critical
12405
High
12324
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-85167 | UNKNOWN | — | n8n before 2.35.4 and 2.36.x before 2.36.2 contain a query injection vulnerability in the Elasticsearch Document Get All and Google Cloud Firestore Document Query operations, … | Sep 03, 2026 |
| CVE-2026-85166 | UNKNOWN | — | n8n before 2.35.4 and 2.36.x before 2.36.2 does not validate credential references in the inline workflow JSON of nodes that execute an inline sub-workflow (e.g., … | Sep 03, 2026 |
| CVE-2026-85165 | UNKNOWN | — | n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated … | Sep 03, 2026 |
| CVE-2026-85164 | HIGH | 7.1 | WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate profileImg and backgroundImg URLs before … | Sep 03, 2026 |
| CVE-2026-85163 | MEDIUM | 6.5 | AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the EPG parser that allows authenticated uploaders to fetch arbitrary internal URLs. An attacker … | Sep 03, 2026 |
| CVE-2026-85162 | MEDIUM | 6.5 | AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in plugin/Live/saveLive.php that lacks forbidIfNotPost and forbidIfInvalidToken protections. Attackers can craft malicious image tags to … | Sep 03, 2026 |
| CVE-2026-85161 | MEDIUM | 4.3 | AVideo through commit c91b5975d contains a cross-site request forgery vulnerability in removePoster.php that lacks forbidIfNotPost or forbidIfInvalidToken checks. Attackers can craft malicious image tags to … | Sep 03, 2026 |
| CVE-2026-85160 | HIGH | 8.1 | AVideo through commit c91b5975d contains a cross-site request forgery and path traversal vulnerability in stopLive.php that allows attackers to delete directories by exploiting missing token … | Sep 03, 2026 |
| CVE-2026-85159 | MEDIUM | 5.4 | AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in userLogin.php where the cancelUri parameter is echoed in an href attribute after isSafeRedirectURL checks … | Sep 03, 2026 |
| CVE-2026-85158 | MEDIUM | 5.4 | AVideo through commit c91b5975d contains a reflected cross-site scripting vulnerability in videoEmbeded.php that echoes the link parameter inside an HTML comment with zero escaping. Attackers … | Sep 03, 2026 |
| CVE-2026-85157 | MEDIUM | 5.3 | WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parameter is supplied. Attackers … | Sep 03, 2026 |
| CVE-2026-85156 | MEDIUM | 5.3 | WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through hardcoded visibility … | Sep 03, 2026 |
| CVE-2026-85155 | HIGH | 7.5 | WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results … | Sep 03, 2026 |
| CVE-2026-85154 | CRITICAL | 9.8 | WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the … | Sep 03, 2026 |
| CVE-2026-85150 | HIGH | 7.5 | A NULL pointer dereference flaw was found in GStreamer's RTSP support library. The vulnerability occurs while parsing an Authorization or WWW-Authenticate header that uses Digest … | Sep 03, 2026 |
| CVE-2026-85124 | HIGH | 7.5 | @fastify/http-proxy versions before 11.6.2 do not validate proxied HTTP request paths for backslash based dot-segments before forwarding them to the configured upstream. The plain HTTP … | Sep 03, 2026 |
| CVE-2026-85107 | MEDIUM | 4.3 | A vulnerability was found in NousResearch hermes-agent 0.18.0. This vulnerability affects the function resourceBufferFromUrl of the file apps/desktop/electron/main.ts of the component Electron Main Process. Performing … | Sep 03, 2026 |
| CVE-2026-85106 | MEDIUM | 6.3 | A vulnerability has been found in NousResearch hermes-agent 0.18.0. This affects the function fetchLinkTitle of the file apps/desktop/src/app/artifacts/index.tsx of the component Link Title Fetch. Such … | Sep 03, 2026 |
| CVE-2026-85105 | HIGH | 7.3 | A flaw has been found in NousResearch hermes-agent 0.18.0. Affected by this issue is the function _sess_nowait of the file s71.py of the component Session … | Sep 03, 2026 |
| CVE-2026-85100 | MEDIUM | 4.3 | A vulnerability was detected in 2FastLabs agent-squad up to 1.1.4. Affected by this vulnerability is the function AgentSquad.routeRequest of the file agent-squad/typescript/src/orchestrator.ts of the component … | Sep 03, 2026 |
| CVE-2026-85093 | MEDIUM | 6.5 | Cheshire Cat AI's GET /memory/collections/{collection_id}/points endpoint fails to apply per-user filtering when retrieving episodic memory points. Authenticated attackers with MEMORY:READ permission can retrieve all users' … | Sep 03, 2026 |
| CVE-2026-85092 | MEDIUM | 6.6 | LiME through 1.12.0 fails to validate the disk acquisition output path and does not use O_NOFOLLOW when opening the operator-supplied path parameter, allowing unprivileged local … | Sep 03, 2026 |
| CVE-2026-85091 | HIGH | 7.4 | zlib versions 1.3.1.2 through 1.3.2 contain a heap buffer overflow vulnerability in the gz_vacate() function when processing non-blocking gzwrite() operations with stale external buffer pointers. … | Sep 03, 2026 |
| CVE-2026-85090 | MEDIUM | 5.4 | FreeRDP before 3.31.0 contains a heap out-of-bounds read vulnerability in the general_ChromaV1ToYUV444 function during AVC444 chroma plane reconstruction. A malicious RDP server can craft a … | Sep 03, 2026 |
| CVE-2026-85089 | MEDIUM | 6.5 | FreeRDP versions 3.0.0 through 3.30.0 (before 3.31.0) transmit uninitialized heap memory in Save Session Info PDU reserved padding fields. Three PDU writers in libfreerdp/core/info.c (rdp_write_logon_info_v2, … | Sep 03, 2026 |