Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.3 CVE-2026-50574

yt-dlp: Arbitrary code execution via manifest downloads with aria2c_CVE-2026-50574

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format ...

yt-dlp yt-dlp < 2026.06.09 CVE
HIGH 8.3 CVE-2026-50023

yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)_CVE-2026-50023

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbit...

yt-dlp yt-dlp < 2026.06.09 CVE
HIGH 7.1 CVE-2026-49444

n8n: Python sandbox escape_CVE-2026-49444

n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modif...

n8n-io n8n < 1.123.48 CVE
HIGH 8.3 CVE-2026-45732

n8n: Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints_CVE-2026-45732

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints aut...

n8n-io n8n < 1.123.43 CVE
HIGH 8.8 CVE-2026-44959

CVE-2026-44959_CVE-2026-44959

A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an...

Revive Adserver CVE
HIGH 8.9 CVE-2026-44792

n8n: Source Control Pull SQL Injection_CVE-2026-44792

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository conn...

n8n-io n8n < 1.123.43 CVE
HIGH 8.8 CVE-2026-34916

CVE-2026-34916_CVE-2026-34916

A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use t...

Revive Adserver Revive Adserver CVE
HIGH 8.3 CVE-2026-34914

CVE-2026-34914_CVE-2026-34914

A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the c...

Revive Adserver CVE
HIGH 8.8 CVE-2026-33760

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints_CVE-2026-33760

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoint...

langflow-ai langflow < 1.9.0 CVE
HIGH 7.5 CVE-2026-13007

Insecure Public Caching on REST API Endpoints in Tenable Identity Exposure_CVE-2026-13007

Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive application configuration data inclu...

tenable Tenable Identity Exposure CVE