|
2271
|
7.5 |
HIGH
Network
|
n8n
|
n8n
|
n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters endpoints did not verify whether the authenticated caller was authorized to use …
|
CWE-862
Missing Authorization
|
CVE-2026-42226
|
2026-05-7 03:09 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2272
|
6.5 |
MEDIUM
Network
|
n8n
|
n8n
|
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped to variable:list could read variables from projec…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-42227
|
2026-05-7 03:08 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2273
|
6.5 |
MEDIUM
Network
|
n8n
|
n8n
|
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify tha…
|
CWE-862
Missing Authorization
|
CVE-2026-42228
|
2026-05-7 03:08 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2274
|
9.8 |
CRITICAL
Network
|
n8n
|
n8n
|
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the…
|
CWE-89
SQL Injection
|
CVE-2026-42233
|
2026-05-7 03:07 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2275
|
8.8 |
HIGH
Network
|
n8n
|
n8n
|
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows containing a Python Code Node c…
|
CWE-94
Code Injection
|
CVE-2026-42234
|
2026-05-7 03:05 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2276
|
9.6 |
CRITICAL
Network
|
n8n
|
n8n
|
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a crafted client_name.…
|
CWE-79 CWE-87
Cross-site Scripting Improper Neutralization of Alternate XSS Syntax
|
CVE-2026-42235
|
2026-05-7 03:05 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2277
|
7.3 |
HIGH
Network
|
apache
|
thrift
|
Improper Validation of Certificate with Host Mismatch vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixe…
|
CWE-297
Improper Validation of Certificate with Host Mismatch
|
CVE-2026-43869
|
2026-05-7 03:05 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2278
|
5.3 |
MEDIUM
Network
|
apache
|
thrift
|
Memory Allocation with Excessive Size Value vulnerability in Apache Thrift.
This issue affects Apache Thrift: before 0.23.0.
Users are recommended to upgrade to version 0.23.0, which fixes the issu…
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-43868
|
2026-05-7 03:05 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2279
|
7.3 |
HIGH
Network
|
apache
|
thrift
|
Origin Validation Error, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting'),…
|
CWE-22 CWE-113 CWE-346 CWE-400
Path Traversal HTTP Response Splitting Origin Validation Error Uncontrolled Resource Consumption
|
CVE-2026-43870
|
2026-05-7 03:05 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2280
|
7.5 |
HIGH
Network
|
qualcomm
|
fastconnect_6200_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware flight_rb5_5g_firmware fwa_gen_3_ultra_firmware g2_gen_1_firmware g3x_gen_…
|
Transient DOS when processing target power rate tables during channel configuration.
|
CWE-126 CWE-125
Buffer Over-read Out-of-bounds Read
|
CVE-2025-47401
|
2026-05-7 03:03 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|