Total CVEs

138,210

Critical Severity

3,547

High Severity

12,695

Last 7 Days

1,888
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 981 - 1,000 of 34,615 CVEs
CVE-2026-54309 HIGH - 10.0

n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54305 HIGH - 9.9

n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54307 HIGH - 9.6

n8n: Credential Exfiltration via Permission Bypass

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54314 MEDIUM - 5.9

n8n: Denial of Service via ZIP decompression in webhook workflow

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54302 HIGH - 7.6

n8n: Stored XSS in Chat Trigger Node

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54303 MEDIUM - 7.6

n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54312 HIGH - 8.5

n8n: Microsoft SQL Node Prototype Pollution

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54322 HIGH - 7.7

Daytona: Cross-org IDOR in organization role update/delete โ€” any org owner can rewrite or destroy another org's roles

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52846 MEDIUM - 4.2

Caddy: stripHTML template function bypass

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52845 HIGH - 8.1

Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52844 HIGH - 7.5

Caddy: Windows `file_server` path authorization bypass via encoded backslash

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: Jun 16, 2026
Source: GitHub
CVE-2026-50574 HIGH - 8.3

yt-dlp: Arbitrary code execution via manifest downloads with aria2c

Vendor: pip
Product: yt-dlp
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54321 HIGH - 7.0

Daytona: Public sandbox previews remain accessible for up to one hour after being made private

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 16, 2026
Source: GitHub

Traefik: HTTP/3 mTLS bypass via exact SNI TLSOptions lookup for wildcard and mixed-case hosts

Vendor: go
Product: Traefik
Published: Jun 16, 2026
Source: GitHub
CVE-2026-53755 HIGH - 8.6

Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check

Vendor: pip
Product: crawl4ai
Published: Jun 16, 2026
Source: GitHub
CVE-2026-53754 HIGH - 7.5

Crawl4AI: SSRF filter bypass in Docker server via IPv6 transition forms (NAT64 / 6to4 / unspecified / v4-mapped)

Vendor: pip
Product: crawl4ai
Published: Jun 16, 2026
Source: GitHub
CVE-2026-50023 HIGH - 8.3

yt-dlp: Dangerous file type creation via insufficient filename sanitization (Bypass of CVE-2024-38519)

Vendor: pip
Product: yt-dlp
Published: Jun 16, 2026
Source: GitHub
CVE-2026-50019 MEDIUM - 6.1

yt-dlp: File Downloader cookie leak with curl

Vendor: pip
Product: yt-dlp
Published: Jun 16, 2026
Source: GitHub

FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable, 1.4.0-beta and 1.4.1-beta are vulnerable to Path Traversal through the publicPatchHandler in backend/http/public.go which joins user-controlled fromPath and toPath body fields with the trusted d.share...

Vendor: gtsteffaniak
Product: filebrowser
Published: Jun 16, 2026
Source: NVD
CVE-2026-47750 HIGH - 7.8

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. In versions prior to master-584-0a7ae07, the pickle .ckpt parser in src/model.cpp contained a heap buffer overflow vulnerability in the GLOBAL opcode hand...

Vendor: leejet
Product: stable-diffusion.cpp
Published: Jun 16, 2026
Source: NVD