Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-87016Highopen-webui: Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLiteCVE-2026-88062Criticalomniroute: OmniRoute ACP Custom-Agent Remote Code Execution (RCE)CVE-2026-86073Mediumn8n: n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource SubstitutionCVE-2026-86074Mediumn8n: n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched ContentCVE-2026-86995Mediumn8n: n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository ReadCVE-2026-86085Mediumn8n: n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment EndpointsCVE-2026-86993Mediumn8n: n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership CheckCVE-2026-86084Mediumn8n: n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid SessionsCVE-2026-86080Mediumn8n: n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-OpenCVE-2026-86079Mediumn8n: n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded IdentifiersCVE-2026-86078Mediumn8n: n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of ServiceCVE-2026-86994Mediumn8n: n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId FilterCVE-2026-86083Highn8n: n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code ExecutionCVE-2026-86077Mediumn8n: n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocketCVE-2026-88011Mediumgithub.com/traefik/traefik/v2: Traefik: ForwardAuth identity spoofing via dot-form header aliasCVE-2026-88012Mediumgithub.com/traefik/traefik/v2: Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unboundedCVE-2026-88060High@angular/platform-server: Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content ElementsCVE-2026-88056High@angular/platform-server: Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSRCVE-2026-88059Medium@angular/common: Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`CVE-2026-88057Medium@angular/core: Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compilerCVE-2026-55416Highpimcore/pimcore: Pimcore: SQL Injection in Custom Reports via Malicious Report ConfigurationCVE-2026-86082Highn8n: n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model NodeCVE-2026-86081Highn8n: n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone PathCVE-2026-86075Highn8n: n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration EndpointCVE-2026-86076Highn8n: n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution

Stop the waste.
Protect your environment with Kodem.