Skip to content

GitHub Advisory Database

Security vulnerability database inclusive of CVEs and GitHub originated security advisories from the world of open source software.

8,990 advisories

Loading
mtholmquist Credited to mtholmquist
n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check Moderate
CVE-2026-86993 was published for n8n (npm) Sep 10, 2026
nlgbao1340 Credited to nlgbao1340
n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter Moderate
CVE-2026-86994 was published for n8n (npm) Sep 10, 2026
tr4ce-ju Credited to tr4ce-ju
n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket Moderate
CVE-2026-86077 was published for n8n (npm) Sep 10, 2026
tr4ce-ju Credited to tr4ce-ju
Subscriber Settings Change in WP-Stateless <= 4.4.1 versions. High Unreviewed
CVE-2026-81801 was published Sep 10, 2026
Unauthenticated Broken Access Control in WP Fast Total Search <= 1.82.284 versions. High Unreviewed
CVE-2026-84821 was published Sep 10, 2026
Subscriber Broken Access Control in IMPress for IDX Broker <= 3.3.0 versions. Moderate Unreviewed
CVE-2026-81788 was published Sep 10, 2026
Unauthenticated Broken Access Control in BuddyForms <= 2.9.0 versions. Moderate Unreviewed
CVE-2026-81785 was published Sep 10, 2026
Unauthenticated Broken Access Control in Salon booking system <= 10.31.5 versions. Moderate Unreviewed
CVE-2026-81793 was published Sep 10, 2026
Open WebUI: Channel members can overwrite another member's message via the chat completions endpoint Moderate
CVE-2026-87994 was published for open-webui (pip) Sep 10, 2026
Classic298 Credited to Classic298
ProTip! Advisories are also available from the GraphQL API