2026 CVE Vulnerabilities
48,284 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-49402 | HIGH | 8.1 | 0.3% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation pro... |
| CVE-2026-49401 | HIGH | 8.4 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.14, Deno's permission system enforces filesystem... |
| CVE-2026-45135 | HIGH | 8.1 | 0.4% | Jun 23, 2026 | Caddy is an extensible server platform that uses TLS by default. From 2.7.0 until 2.11.3, the FastCGI transport's splitP... |
| CVE-2026-56116 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak vulnerability in the IPv6 Router Advertisement ro... |
| CVE-2026-56115 | HIGH | 8.8 | 0.3% | Jun 23, 2026 | Bootimus through 0.1.70 contains a broken access control vulnerability that allows authenticated low-privileged users to... |
| CVE-2026-55446 | HIGH | 7.5 | 0.3% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /... |
| CVE-2026-55255 | HIGH | 8.4 | 0.2% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object... |
| CVE-2026-54308 | HIGH | 7.2 | 0.3% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger and StripeT... |
| CVE-2026-54304 | HIGH | 7.7 | 0.4% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with pe... |
| CVE-2026-50019 | HIGH | 7.4 | 0.3% | Jun 23, 2026 | yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downlo... |
| CVE-2026-49465 | HIGH | 7.7 | 0.5% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with pe... |
| CVE-2026-49444 | HIGH | 8.5 | 0.4% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with pe... |
| CVE-2026-45732 | HIGH | 8.1 | 0.3% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credent... |
| CVE-2026-44959 | HIGH | 8.8 | 0.4% | Jun 23, 2026 | A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑p... |
| CVE-2026-44790 | HIGH | 8.8 | 0.6% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe... |
| CVE-2026-34916 | HIGH | 8.8 | 0.4% | Jun 23, 2026 | A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a l... |
| CVE-2026-34914 | HIGH | 8.3 | 0.3% | Jun 23, 2026 | A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileg... |
| CVE-2026-33760 | HIGH | 8.8 | 0.2% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monito... |
| CVE-2026-13007 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive applicati... |
| CVE-2026-12958 | HIGH | 8.5 | 0.1% | Jun 23, 2026 | Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust ... |
| CVE-2026-12957 | HIGH | 8.5 | 0.1% | Jun 23, 2026 | Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may all... |
| CVE-2026-11940 | HIGH | 7.8 | 0.8% | Jun 23, 2026 | tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink reference... |
| CVE-2026-56695 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | OpenHarness ohmo gateway /resume and /summary slash commands default remote_invocable to True, allowing admitted remote ... |
| CVE-2026-56402 | HIGH | 7.1 | 0.2% | Jun 23, 2026 | NanoClaw before 2.1.17 contains a privilege escalation vulnerability in the handleApprovalsResponse function that fails ... |
| CVE-2026-54314 | HIGH | 7.5 | 0.4% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 2.24.0, the Compression node's Decompress operation expande... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now