Total CVEs

138,417

Critical Severity

3,561

High Severity

12,797

Last 7 Days

1,955
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,181 - 1,200 of 34,822 CVEs
CVE-2026-26231 HIGH - 8.5

Gitea: Authorization Bypass via "Allow edits from maintainers" allows unauthorized commits to any readable repo

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 16, 2026
Source: GitHub
CVE-2026-28699 HIGH - 8.1

Gitea: OAuth2 access token scope enforcement bypass via HTTP Basic authentication

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52797 HIGH - 8.5

Gogs: Overwriting critical files results in a denial of service

Vendor: go
Product: gogs.io/gogs
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49980 CRITICAL - 9.8

Rclone: Unauthenticated command execution in `rclone rcd --rc-serve` via inline remote instantiation, bypassing CVE-2026-41179 fix

Vendor: go
Product: github.com/rclone/rclone
Published: Jun 16, 2026
Source: GitHub

LiteLLM: Authentication Bypass via Host Header Injection

Vendor: pip
Product: litellm
Published: Jun 16, 2026
Source: GitHub
CVE-2026-28744 HIGH - 8.1

Gitea: Git Smart HTTP Skips Repository Token Scopes for Bearer Tokens

Vendor: go
Product: code.gitea.io/gitea
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54304 HIGH - 7.7

n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54309 HIGH - 10.0

n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54305 HIGH - 9.9

n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54307 HIGH - 9.6

n8n: Credential Exfiltration via Permission Bypass

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54314 MEDIUM - 5.9

n8n: Denial of Service via ZIP decompression in webhook workflow

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54302 HIGH - 7.6

n8n: Stored XSS in Chat Trigger Node

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54303 MEDIUM - 7.6

n8n: Reflected XSS via Facebook, WhatsApp, and Microsoft Teams Trigger Webhook Verification Endpoints

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54312 HIGH - 8.5

n8n: Microsoft SQL Node Prototype Pollution

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54322 HIGH - 7.7

Daytona: Cross-org IDOR in organization role update/delete โ€” any org owner can rewrite or destroy another org's roles

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52846 MEDIUM - 4.2

Caddy: stripHTML template function bypass

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52845 HIGH - 8.1

Caddy: FastCGI header normalization bypass in `forward_auth copy_headers`

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: Jun 16, 2026
Source: GitHub
CVE-2026-52844 HIGH - 7.5

Caddy: Windows `file_server` path authorization bypass via encoded backslash

Vendor: go
Product: github.com/caddyserver/caddy/v2
Published: Jun 16, 2026
Source: GitHub
CVE-2026-50574 HIGH - 8.3

yt-dlp: Arbitrary code execution via manifest downloads with aria2c

Vendor: pip
Product: yt-dlp
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54321 HIGH - 7.0

Daytona: Public sandbox previews remain accessible for up to one hour after being made private

Vendor: go
Product: github.com/daytonaio/daytona
Published: Jun 16, 2026
Source: GitHub