2026 CVE Vulnerabilities
60,200 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54012 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ... |
| CVE-2026-54011 | MEDIUM | 5.4 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6,Open W... |
| CVE-2026-54010 | HIGH | 8.3 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ... |
| CVE-2026-54009 | MEDIUM | 6.5 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST ... |
| CVE-2026-54008 | HIGH | 8.5 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, backe... |
| CVE-2026-54007 | MEDIUM | 6.5 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the c... |
| CVE-2026-54006 | MEDIUM | 4.3 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST ... |
| CVE-2026-53662 | CRITICAL | 9.6 | 0.2% | Jun 23, 2026 | immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a refl... |
| CVE-2026-52846 | MEDIUM | 4.2 | 0.1% | Jun 23, 2026 | Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function ca... |
| CVE-2026-52845 | HIGH | 8.1 | 0.2% | Jun 23, 2026 | Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, forward_auth copy_headers deletes the ... |
| CVE-2026-52844 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat ... |
| CVE-2026-50221 | MEDIUM | 5.4 | 0.2% | Jun 23, 2026 | In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Dev... |
| CVE-2026-49983 | MEDIUM | 5.2 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permis... |
| CVE-2026-49860 | MEDIUM | 5.2 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno ... |
| CVE-2026-49859 | MEDIUM | 5.2 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the des... |
| CVE-2026-49440 | HIGH | 7.4 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, node:crypto.checkPrime(candidate[, options][,... |
| CVE-2026-49411 | MEDIUM | 6.5 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked th... |
| CVE-2026-49406 | MEDIUM | 5.5 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModules... |
| CVE-2026-49402 | HIGH | 8.1 | 0.3% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation pro... |
| CVE-2026-49401 | HIGH | 8.4 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem... |
| CVE-2026-45692 | LOW | 3.8 | 0.1% | Jun 23, 2026 | Caddy is an extensible server platform that uses TLS by default. From 2.4.0 until 2.11.3, the authorization layer and th... |
| CVE-2026-45135 | HIGH | 8.1 | 0.4% | Jun 23, 2026 | Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitP... |
| CVE-2026-44726 | CRITICAL | 9.1 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatib... |
| CVE-2026-0864 | MEDIUM | 5.5 | 0.1% | Jun 23, 2026 | When using the "configparser" module to write configuration files containing multi-line text values with carriage return... |
| CVE-2026-56968 | MEDIUM | 5.3 | 0.3% | Jun 23, 2026 | GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now