Total CVEs

138,466

Critical Severity

3,569

High Severity

12,817

Last 7 Days

1,987
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,361 - 1,380 of 34,871 CVEs
CVE-2026-54313 MEDIUM - 7.7

n8n: NoSQL Injection in MongoDB Node Find And Replace Operation

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-54310 MEDIUM - 9.9

n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49465 MEDIUM - 7.7

n8n: Git Node Clone and Push Operations Bypass File Sandbox

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-49444 HIGH - 8.5

n8n: Python sandbox escape

Vendor: npm
Product: n8n
Published: Jun 16, 2026
Source: GitHub
CVE-2026-48746 CRITICAL - 9.1

vLLM: OpenAI auth bypass

Vendor: pip
Product: vllm
Published: Jun 16, 2026
Source: GitHub
CVE-2026-48520 MEDIUM - 6.1

Langflow: Unauthenticated Shareable Playground arbitrary local or S3 file read

Vendor: pip
Product: langflow
Published: Jun 16, 2026
Source: GitHub
CVE-2026-48519 CRITICAL - 9.6

Langflow: Unauthenticated RCE in Shareable Playgrounds

Vendor: pip
Product: langflow
Published: Jun 16, 2026
Source: GitHub
CVE-2026-42867 MEDIUM - 6.5

Langflow: Path Traversal in Knowledge Bases API via Creation Endpoint

Vendor: pip
Product: langflow
Published: Jun 16, 2026
Source: GitHub
CVE-2026-41523 HIGH - 7.5

vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution

Vendor: pip
Product: vllm
Published: Jun 16, 2026
Source: GitHub
CVE-2026-33760 HIGH - 8.8

Langflow: IDOR/BOLA in Monitor API โ€” Missing Ownership Enforcement on 7 Endpoints

Vendor: pip
Product: langflow
Published: Jun 16, 2026
Source: GitHub
CVE-2026-53776 CRITICAL - 9.1

Perry before 0.5.1166 contains a JWT validation vulnerability that allows remote attackers to bypass token expiration by exploiting the unconditional setting of validate_exp = false in the verify_decode helper within the stdlib JWT verification path. Attackers in possession of a previously issued be...

Vendor: PerryTS
Product: perry
Published: Jun 16, 2026
Source: NVD
CVE-2026-44932 HIGH - 8.8

Passing of unsanitized strings from DHCP replies into the wicked dhcp client before wicked 0.6.79 could be used by attackers operating a malicious DHCP server to execute code on the local machine.

Vendor: SUSE
Product: wicked
Published: Jun 16, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jun 16, 2026
Source: NVD

Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

Published: Jun 16, 2026
Source: NVD
CVE-2026-24228 HIGH - 7.8

NVIDIA NeMo Framework for Linux contains a vulnerability where an attacker may cause deserialization of untrusted data. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, data tampering, and information disclosure.

Vendor: NVIDIA
Product: NeMo Framework
Published: Jun 16, 2026
Source: NVD
CVE-2026-24155 HIGH - 7.8

NVIDIA NeMo Framework for all platforms contains a code injection vulnerability. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, and data tampering.

Vendor: NVIDIA
Product: NeMo Framework
Published: Jun 16, 2026
Source: NVD

Rejected reason: loading template...

Published: Jun 16, 2026
Source: NVD

To allow builds of Python to be run from an in-tree layout (rather than an installed file layout), the VPATH variable is defined at build time and used to locate certain landmarks - specifically, Modules/setup.local. When this landmark is found relative to VPATH relative to the executable, Python as...

Vendor: Python Software Foundation
Product: CPython
Published: Jun 16, 2026
Source: NVD
CVE-2026-10649 HIGH - 8.6

A flaw was found in Pacemaker. An unauthenticated remote attacker can exploit an integer overflow vulnerability in the remote message decompression process. By sending a specially crafted compressed remote message before authentication, an attacker can cause memory corruption, leading to a denial of...

Vendor: Red Hat
Product: Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9, Red Hat OpenShift Container Platform 4
Published: Jun 16, 2026
Source: NVD
CVE-2024-38487 HIGH - 7.0

api-gateway container running with root privilege would allow an attacker to escape the container and access host system to perform unintended actions.

Vendor: Dell
Product: EMC VxRail Appliance
Published: Jun 16, 2026
Source: NVD