Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.4 CVE-2026-44789

n8n: HTTP Request Node Pagination Prototype Pollution to RCE_CVE-2026-44789

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modif...

n8n-io n8n < 1.123.43 CVE
MEDIUM 6.5 CVE-2026-42867

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint_CVE-2026-42867

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Know...

langflow-ai langflow < 1.9.0 CVE
MEDIUM 4.3 CVE-2026-34917

CVE-2026-34917_CVE-2026-34917

Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication is normally restricted to a...

Revive Adserver CVE
HIGH 8.8 CVE-2026-34916

CVE-2026-34916_CVE-2026-34916

A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use t...

Revive Adserver Revive Adserver CVE
MEDIUM 6.1 CVE-2026-34915

CVE-2026-34915_CVE-2026-34915

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to explo...

Revive Adserver CVE
HIGH 8.3 CVE-2026-34914

CVE-2026-34914_CVE-2026-34914

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the c...

Revive Adserver CVE
MEDIUM 4.3 CVE-2026-34913

CVE-2026-34913_CVE-2026-34913

A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier cou...

Revive Adserver CVE
MEDIUM 4.3 CVE-2026-34912

CVE-2026-34912_CVE-2026-34912

A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive Adserver 6.0.6 and earlier...

Revive Adserver CVE
HIGH 8.8 CVE-2026-33760

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints_CVE-2026-33760

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoint...

langflow-ai langflow < 1.9.0 CVE
HIGH 7.5 CVE-2026-13007

Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure_CVE-2026-13007

Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data inclu...

tenable Tenable Identity Exposure CVE