Kodem's Vulnerability Database

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-86079Mediumn8n: n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded IdentifiersCVE-2026-86078Mediumn8n: n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of ServiceCVE-2026-86994Mediumn8n: n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId FilterCVE-2026-86083Highn8n: n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code ExecutionCVE-2026-86077Mediumn8n: n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocketCVE-2026-88011Mediumgithub.com/traefik/traefik/v2: Traefik: ForwardAuth identity spoofing via dot-form header aliasCVE-2026-88012Mediumgithub.com/traefik/traefik/v2: Traefik: respondingTimeouts.readTimeout is not applied to HTTP/3, leaving slow-body uploads unboundedCVE-2026-88060High@angular/platform-server: Angular: SSR XSS via Unescaped <template> Content Across DocumentFragment Boundaries in Fallback Raw-Content ElementsCVE-2026-88056High@angular/platform-server: Angular: SSRF and Cross-Origin Credential Disclosure via URL Resolution Discrepancy in SSRCVE-2026-88059Medium@angular/common: Angular: Information Leak via `HttpTransferCache` Bypass When Using `withRequestsMadeViaParent`CVE-2026-88057Medium@angular/core: Angular: Sanitization bypass via directive host bindings on concrete host elements in @angular/core and @angular/compilerCVE-2026-55416Highpimcore/pimcore: Pimcore: SQL Injection in Custom Reports via Malicious Report ConfigurationCVE-2026-86082Highn8n: n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model NodeCVE-2026-86081Highn8n: n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone PathCVE-2026-86075Highn8n: n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration EndpointCVE-2026-86076Highn8n: n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code ExecutionCVE-2026-87017Mediumopen-webui: Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backendsCVE-2026-87994Mediumopen-webui: Open WebUI: Channel members can overwrite another member's message via the chat completions endpointCVE-2026-87995Highopen-webui: Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-originCVE-2026-87996Highopen-webui: Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loaderCVE-2026-87997Mediumopen-webui: Open WebUI: Any authenticated user can inject chats into another user's folder via chat completionsCVE-2026-87998Highopen-webui: Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletionCVE-2026-87999Highopen-webui: Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetchCVE-2026-88005Mediumopen-webui: Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchangeCVE-2026-59161Highgithub.com/xuri/excelize/v2: Excelize: Streaming GetRows row-bound bypass causes attacker-controlled allocation

Stop the waste.
Protect your environment with Kodem.