2026 CVE Vulnerabilities

45,132 CVEs published in 2026.

Filter:MEDIUMClear
CVE IDSeverityCVSSDescription
CVE-2026-54016MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ...
CVE-2026-54015MEDIUM6.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ...
CVE-2026-54014MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, a pat...
CVE-2026-54011MEDIUM5.4Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6,Open W...
CVE-2026-54009MEDIUM6.5Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST ...
CVE-2026-54007MEDIUM6.5Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the c...
CVE-2026-54006MEDIUM4.3Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST ...
CVE-2026-52846MEDIUM4.2Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function ca...
CVE-2026-50221MEDIUM5.4In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Dev...
CVE-2026-49983MEDIUM5.2Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permis...
CVE-2026-49860MEDIUM5.2Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno ...
CVE-2026-49859MEDIUM5.2Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the des...
CVE-2026-49411MEDIUM6.5Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked th...
CVE-2026-49406MEDIUM5.5Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModules...
CVE-2026-0864MEDIUM4.1When using the "configparser" module to write configuration files containing multi-line text values with carriage return...
CVE-2026-56968MEDIUM5.3GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could...
CVE-2026-56117MEDIUM5.5dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handl...
CVE-2026-56114MEDIUM6.5dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_mak...
CVE-2026-56113MEDIUM6.5dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated...
CVE-2026-55423MEDIUM6.1Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does no...
CVE-2026-54306MEDIUM6.4n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allo...
CVE-2026-54302MEDIUM5.4n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with wo...
CVE-2026-54301MEDIUM5.4n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with wo...
CVE-2026-48520MEDIUM6.1Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playgroun...
CVE-2026-44958MEDIUM5.4An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now