Total CVEs

137,287

Critical Severity

3,310

High Severity

12,270

Last 7 Days

1,288
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 21 - 40 of 11,967 CVEs
CVE-2026-54304 HIGH - 7.7

n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54309 HIGH - 10.0

n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54305 HIGH - 9.9

n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54307 HIGH - 9.6

n8n: Credential Exfiltration via Permission Bypass

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54302 HIGH - 7.6

n8n: Stored XSS in Chat Trigger Node

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54312 HIGH - 8.5

n8n: Microsoft SQL Node Prototype Pollution

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54322 HIGH - 7.7

Daytona: Cross-org IDOR in organization role update/delete โ€” any org owner can rewrite or destroy another org's roles

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52845 HIGH - 8.1

Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52844 HIGH - 7.5

Caddy: Windows `file_server` path authorization bypass via encoded backslash

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: Jun 16, 2026
Source: GitHub
CVE-2026-50574 HIGH - 8.3

yt-dlp: Arbitrary code execution via manifest downloads with aria2c

Vendor: pip
Product: yt-dlp
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54321 HIGH - 7.0

Daytona: Public sandbox previews remain accessible for up to one hour after being made private

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 16, 2026
Source: GitHub

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

Vendor: go
Product: Traefik
Published: Jun 16, 2026
Source: GitHub
CVE-2026-53755 HIGH - 8.6

Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check

Vendor: pip
Product: crawl4ai
Published: Jun 16, 2026
Source: GitHub
CVE-2026-53754 HIGH - 7.5

Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)

Vendor: pip
Product: crawl4ai
Published: Jun 16, 2026
Source: GitHub
CVE-2026-50023 HIGH - 8.3

yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)

Vendor: pip
Product: yt-dlp
Published: Jun 16, 2026
Source: GitHub
CVE-2026-47750 HIGH - 7.8

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in the GLOBAL opcode hand...

Vendor: leejet
Product: stable-diffusion.cpp
Published: Jun 16, 2026
Source: NVD
CVE-2026-47747 HIGH - 7.8

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in the BINUNICODE opcode h...

Vendor: leejet
Product: stable-diffusion.cpp
Published: Jun 16, 2026
Source: NVD
CVE-2026-22312 HIGH - 8.6

The device has a webserver that exposes a REST API authenticated with a constant token. The unauthenticated API can be used by an attacker to get access to system settings, modify the configuration and execute some commands (e.g. system reboot).

Vendor: Radiflow
Product: iSAP Smart Collector
Published: Jun 16, 2026
Source: NVD
CVE-2026-10303 HIGH - 7.4

In ServerCo getssl version 2.49 and prior, the ACME challenge token returned to the client was not strictly validated against RFC 8555 before being used in challenge-file handling, allowing a maliciously crafted token to influence local path/filename usage during validation. An attacker who can supp...

Vendor: ServerCo
Product: getssl
Published: Jun 16, 2026
Source: NVD
CVE-2026-53866 HIGH - 8.1

OpenClaw before 2026.5.12 contains an allowlist bypass vulnerability in shell inline-command parsing that allows authenticated operators to execute unapproved commands. A command request using shell inline-command forms could route through a parser case missing the expected allowlist decision, enabl...

Vendor: OpenClaw
Product: OpenClaw
Published: Jun 16, 2026
Source: NVD