Total CVEs

138,463

Critical Severity

3,569

High Severity

12,815

Last 7 Days

1,995
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,341 - 1,360 of 34,868 CVEs
CVE-2026-47749 HIGH - 7.8

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are vulnerable to heap buffer overflow in SHORT_BINUNICODE parsing for PyTorch checkpoint files. The pickle .ckpt pars...

Vendor: leejet
Product: stable-diffusion.cpp
Published: Jun 16, 2026
Source: NVD
CVE-2026-47748 MEDIUM - 5.5

stable-diffusion.cpp is a pure C/C++ library for running diffusion model (Stable Diffusion, Flux, Wan, Qwen Image, Z-Image, and more) inference. Versions prior to master-584-0a7ae07 are vulnerable to an out-of-bounds reads error through PyTorch checkpoint pickle opcode parsing. The pickle .ckpt pars...

Vendor: leejet
Product: stable-diffusion.cpp
Published: Jun 16, 2026
Source: NVD

An authenticated user with the nx-licensing-create privilege can upload a specially crafted license file to execute arbitrary operating system commands as the Nexus process user in Sonatype Nexus Repository 3 versions before 3.92.0.

Vendor: Sonatype
Product: Nexus Repository
Published: Jun 16, 2026
Source: NVD
CVE-2024-39575 HIGH - 7.4

update_disk_psu_baseline.sh requires password in plain text

Vendor: Dell
Product: Dell EMC VxRail Appliance
Published: Jun 16, 2026
Source: NVD
CVE-2026-49401 MEDIUM - 5.2

Deno: Permission Bypass via Unicode Normalization Mismatch on macOS (APFS)

Vendor: rust
Product: deno
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49406 MEDIUM - 5.5

Deno: BYONM module resolution allows `package.json` main path traversal to bypass `--allow-read` restrictions

Vendor: rust
Product: deno
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49411 MEDIUM - 6.5

Deno: Node TCPWrap numeric hostname aliases bypass --deny-net resolved-IP deny checks

Vendor: rust
Product: deno
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49440 HIGH - 7.4

Deno: Miller-Rabin Primality Test Allows Zero Rounds

Vendor: rust
Product: deno
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49402 HIGH - 8.1

Deno: Command Injection via spawnSync & spawn on Windows

Vendor: rust
Product: deno
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49983 MEDIUM - 5.2

Deno: process.loadEnvFile() bypasses env permission checks and mutates process.env with only read access

Vendor: rust
Product: deno
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49860 MEDIUM - 5.2

Deno: WebSocket API sandbox bypass via missing post-DNS check

Vendor: rust
Product: deno
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49859 MEDIUM - 5.2

Deno: `fetch()` API sandbox bypass via missing DNS resolution check

Vendor: rust
Product: deno
Published: Jun 16, 2026
Source: GitHub

Traefik: SNICheck ignores wildcard TLSOptions mappings, allowing domain-fronted mTLS bypass

Vendor: go
Product: Traefik
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54311 MEDIUM - 6.3

n8n: Merge Node SQL Mode Prototype Pollution

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54306 MEDIUM - 5.4

n8n: Prototype Pollution enables confused-deputy execution via public webhooks

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54301 HIGH - 7.6

n8n: Same-Origin XSS in Respond to Webhook Node

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54308 MEDIUM - 7.2

n8n: Missing Token Validation on Microsoft Agent 365 Trigger and Stripe Nodes

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54313 MEDIUM - 7.7

n8n: NoSQL Injection in MongoDB Node Find And Replace Operation

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54310 MEDIUM - 9.9

n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49465 MEDIUM - 7.7

n8n: Git Node Clone and Push Operations Bypass File Sandbox

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub