Total CVEs

140,167

Critical Severity

3,700

High Severity

13,319

Last 7 Days

1,704
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,941 - 2,960 of 36,572 CVEs
CVE-2026-54314 MEDIUM - 5.9

n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expanded attacker-controlled archives into memory without enforcing limits on decompressed output size. An unauthenticated attacker could send a small compressed archive to a public ...

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54302 HIGH - 7.6

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with workflow edit access could inject arbitrary JavaScript into the Chat Trigger's generated page by setting a malicious webhookId. When a logged-in user visited the chat URL, the i...

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54303 MEDIUM - 7.6

n8n is an open source workflow automation platform. Prior to 2.24.0, an endpoint in the Meta and Microsoft Teams trigger nodes reflects a query parameter into the HTTP response without sanitization or Content-Security-Policy headers, enabling reflected XSS in the n8n origin when a logged-in user vis...

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54312 HIGH - 8.5

n8n is an open source workflow automation platform. Prior to 2.24.0, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via the Microsoft SQL node by supplying a crafted value as the table parameter. This pollutes Object.prototype process-wid...

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54322 HIGH - 7.7

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. Prior to 0.185.0, Daytona's organization role update and delete endpoints authorized the caller as an owner of the organization named in the request path, but resolved and mutated the tar...

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52846 MEDIUM - 4.2

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddyโ€™s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as <<>img src=x onerror=alert()>, can bypass the tag-stripping logic, potentially le...

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52845 HIGH - 8.1

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the exact client-supplied identity header before copying the trusted value from the auth gateway. But when the request later goes through php_fastcgi, Caddy normalizes HTTP headers int...

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52844 HIGH - 7.5

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server later resolves the same request path as private\secret.txt on disk. An unauthenticated remote client can bypass Caddy pat...

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: Jun 16, 2026
Source: GitHub
CVE-2026-50574 HIGH - 8.3

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insufficiently sanitized input to aria2c that allows an attacker to perform an arbitrary file write. On Windo...

Vendor: pip
Product: yt-dlp
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54321 HIGH - 7.0

Daytona is a secure and elastic infrastructure runtime for AI-generated code execution and agent workflows. From 0.101.0 until 0.184.0, sandbox previews that were switched from public to private could remain reachable without authentication for a short period after the change, due to a cached visibi...

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 16, 2026
Source: GitHub
CVE-2026-53622 HIGH - 10.0

Traefik is an HTTP reverse proxy and load balancer. Prior to 3.7.3, there is a critical vulnerability in Traefik's HTTP/3 (QUIC) TLS configuration selection that allows unauthenticated clients to bypass router-specific mTLS enforcement. When HTTP/3 is enabled on an entrypoint, the TLS handshake...

Vendor: go
Product: Traefik
Published: Jun 16, 2026
Source: GitHub
CVE-2026-53755 HIGH - 8.6

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl target URL only, not to the proxy address. An unauthenticated request could supply a proxy pointing at an internal IP and route the browser through...

Vendor: pip
Product: crawl4ai
Published: Jun 16, 2026
Source: GitHub
CVE-2026-53754 HIGH - 7.5

Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.8, the Docker API server's SSRF protection (validate_webhook_url / validate_url_destination in deploy/docker/utils.py) used an explicit IPv4/IPv6 CIDR blocklist that missed several address families. An attacker coul...

Vendor: pip
Product: crawl4ai
Published: Jun 16, 2026
Source: GitHub
CVE-2026-50023 HIGH - 8.3

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .webloc) to the user's filesystem, bypassing the remediation for CVE-2024-38519. The allowlist expli...

Vendor: pip
Product: yt-dlp
Published: Jun 16, 2026
Source: GitHub
CVE-2026-50019 MEDIUM - 6.1

yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downloader for yt-dlp, cookies may be leaked to an unintended host upon HTTP redirect or when the host for download fragments differs from their parent manifest's. At the file downl...

Vendor: pip
Product: yt-dlp
Published: Jun 16, 2026
Source: GitHub

FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in backend/http/public.go which joins user-controlled fromPath and toPath body fields with the trusted d.share...

Vendor: gtsteffaniak
Product: filebrowser
Published: Jun 16, 2026
Source: NVD
CVE-2026-47750 HIGH - 7.8

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in the GLOBAL opcode hand...

Vendor: leejet
Product: stable-diffusion.cpp
Published: Jun 16, 2026
Source: NVD
CVE-2026-47747 HIGH - 7.8

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in the BINUNICODE opcode h...

Vendor: leejet
Product: stable-diffusion.cpp
Published: Jun 16, 2026
Source: NVD
CVE-2026-46448 MEDIUM - 5.4

In OpenStack Nova before 33.0.2, the server create API does not strip certain hint data. The resulting instance has no Placement allocation.

Vendor: OpenStack
Product: Nova
Published: Jun 16, 2026
Source: NVD
CVE-2026-22313 CRITICAL - 9.1

The device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability an authenticated attacker can send arbitrary commands to the device that are executed with administrative permissions by the underlying operati...

Vendor: Radiflow
Product: iSAP Smart Collector
Published: Jun 16, 2026
Source: NVD