2026 CVE Vulnerabilities
43,931 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-53662 | CRITICAL | 9.6 | 0.2% | Jun 23, 2026 | immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a refl... |
| CVE-2026-44726 | CRITICAL | 9.1 | 0.1% | Jun 23, 2026 | Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatib... |
| CVE-2026-55450 | CRITICAL | 9.3 | 0.3% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can... |
| CVE-2026-55447 | CRITICAL | 9.6 | 0.4% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files th... |
| CVE-2026-54307 | CRITICAL | 9.6 | 0.3% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with edit... |
| CVE-2026-54305 | CRITICAL | 9.9 | 0.3% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by th... |
| CVE-2026-50574 | CRITICAL | 9.6 | 0.4% | Jun 23, 2026 | yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a ... |
| CVE-2026-50023 | CRITICAL | 9.6 | 0.5% | Jun 23, 2026 | yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a rem... |
| CVE-2026-48519 | CRITICAL | 9.6 | 0.5% | Jun 23, 2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground... |
| CVE-2026-44792 | CRITICAL | 9 | 0.3% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access... |
| CVE-2026-44791 | CRITICAL | 9.9 | 0.6% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe... |
| CVE-2026-44789 | CRITICAL | 9.9 | 0.6% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe... |
| CVE-2026-54310 | CRITICAL | 9.9 | 0.4% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to... |
| CVE-2026-54309 | CRITICAL | 10 | 0.4% | Jun 23, 2026 | n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP tra... |
| CVE-2026-35019 | CRITICAL | 9.2 | 0.4% | Jun 23, 2026 | NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows ... |
| CVE-2026-28496 | CRITICAL | 9.4 | 1.9% | Jun 23, 2026 | FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Temp... |
| CVE-2026-27604 | CRITICAL | 10 | 0.4% | Jun 23, 2026 | FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version ... |
| CVE-2026-56379 | CRITICAL | 9.2 | 0.9% | Jun 23, 2026 | ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows atta... |
| CVE-2026-56315 | CRITICAL | 9.8 | 0.8% | Jun 23, 2026 | picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _ai... |
| CVE-2026-56274 | CRITICAL | 9.9 | 2.7% | Jun 23, 2026 | Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to inco... |
| CVE-2026-56258 | CRITICAL | 9.2 | 0.7% | Jun 23, 2026 | Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows una... |
| CVE-2026-44089 | CRITICAL | 9.4 | 0.2% | Jun 23, 2026 | Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. Thi... |
| CVE-2026-11374 | CRITICAL | 9 | 1.2% | Jun 23, 2026 | In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated... |
| CVE-2026-9733 | CRITICAL | 9.1 | 0.3% | Jun 23, 2026 | Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no... |
| CVE-2026-12866 | CRITICAL | 9.8 | 0.5% | Jun 23, 2026 | All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execu... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now