Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.3 CVE-2026-50023

yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)_CVE-2026-50023

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbit...

yt-dlp yt-dlp < 2026.06.09 CVE
HIGH 7.1 CVE-2026-49444

n8n: Python sandbox escape_CVE-2026-49444

n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modif...

n8n-io n8n < 1.123.48 CVE
HIGH 8.3 CVE-2026-45732

n8n: Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints_CVE-2026-45732

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints aut...

n8n-io n8n < 1.123.43 CVE
HIGH 8.8 CVE-2026-44959

CVE-2026-44959_CVE-2026-44959

A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an...

Revive Adserver CVE
HIGH 8.9 CVE-2026-44792

n8n: Source Control Pull SQL Injection_CVE-2026-44792

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository conn...

n8n-io n8n < 1.123.43 CVE
HIGH 8.8 CVE-2026-34916

CVE-2026-34916_CVE-2026-34916

A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use t...

Revive Adserver Revive Adserver CVE
HIGH 8.3 CVE-2026-34914

CVE-2026-34914_CVE-2026-34914

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the c...

Revive Adserver CVE
HIGH 8.8 CVE-2026-33760

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints_CVE-2026-33760

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoint...

langflow-ai langflow < 1.9.0 CVE
HIGH 7.5 CVE-2026-13007

Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure_CVE-2026-13007

Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data inclu...

tenable Tenable Identity Exposure CVE
HIGH 8.5 CVE-2026-12958

Arbitrary file write in Language Servers for AWS_CVE-2026-12958

Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur wh...

Amazon Web Services Language Servers for AWS CVE