2026 CVE Vulnerabilities
45,132 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-54016 | MEDIUM | 4.3 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ... |
| CVE-2026-54015 | MEDIUM | 6.4 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open ... |
| CVE-2026-54014 | MEDIUM | 4.3 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, a pat... |
| CVE-2026-54011 | MEDIUM | 5.4 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6,Open W... |
| CVE-2026-54009 | MEDIUM | 6.5 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST ... |
| CVE-2026-54007 | MEDIUM | 6.5 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the c... |
| CVE-2026-54006 | MEDIUM | 4.3 | 0.2% | Jun 23, 2026 | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST ... |
| CVE-2026-52846 | MEDIUM | 4.2 | 0.1% | Jun 23, 2026 | Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function ca... |
| CVE-2026-50221 | MEDIUM | 5.4 | 0.2% | Jun 23, 2026 | In OpenStack Swift before 2.37.2, proxy-server does not strip internal update headers (X-Container-Host, X-Container-Dev... |
| CVE-2026-49983 | MEDIUM | 5.2 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permis... |
| CVE-2026-49860 | MEDIUM | 5.2 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno ... |
| CVE-2026-49859 | MEDIUM | 5.2 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when fetch() was called, Deno checked the des... |
| CVE-2026-49411 | MEDIUM | 6.5 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked th... |
| CVE-2026-49406 | MEDIUM | 5.5 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModules... |
| CVE-2026-0864 | MEDIUM | 4.1 | 0.1% | Jun 23, 2026 | When using the "configparser" module to write configuration files containing multi-line text values with carriage return... |
| CVE-2026-56968 | MEDIUM | 5.3 | 0.3% | Jun 23, 2026 | GNU SASL before 2.2.4 lacks sanitization of a short challenge in _gsasl_ntlm_client_step in the NTLM client, which could... |
| CVE-2026-56117 | MEDIUM | 5.5 | 0.1% | Jun 23, 2026 | dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-after-free vulnerability in the control socket handl... |
| CVE-2026-56114 | MEDIUM | 6.5 | 0.2% | Jun 23, 2026 | dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte stack out-of-bounds write vulnerability in dhcp6_mak... |
| CVE-2026-56113 | MEDIUM | 6.5 | 0.2% | Jun 23, 2026 | dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated... |
| CVE-2026-55423 | MEDIUM | 6.1 | 0.2% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does no... |
| CVE-2026-54306 | MEDIUM | 6.4 | 0.3% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allo... |
| CVE-2026-54302 | MEDIUM | 5.4 | 0.2% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with wo... |
| CVE-2026-54301 | MEDIUM | 5.4 | 0.2% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with wo... |
| CVE-2026-48520 | MEDIUM | 6.1 | 0.2% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playgroun... |
| CVE-2026-44958 | MEDIUM | 5.4 | 0.3% | Jun 23, 2026 | An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now