2026 CVE Vulnerabilities

43,931 CVEs published in 2026.

Filter:CRITICALClear
CVE IDSeverityCVSSDescription
CVE-2026-53662CRITICAL9.6immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a refl...
CVE-2026-44726CRITICAL9.1Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatib...
CVE-2026-55450CRITICAL9.3Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can...
CVE-2026-55447CRITICAL9.6Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files th...
CVE-2026-54307CRITICAL9.6n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with edit...
CVE-2026-54305CRITICAL9.9n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by th...
CVE-2026-50574CRITICAL9.6yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a ...
CVE-2026-50023CRITICAL9.6yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a rem...
CVE-2026-48519CRITICAL9.6Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground...
CVE-2026-44792CRITICAL9n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access...
CVE-2026-44791CRITICAL9.9n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe...
CVE-2026-44789CRITICAL9.9n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe...
CVE-2026-54310CRITICAL9.9n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to...
CVE-2026-54309CRITICAL10n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP tra...
CVE-2026-35019CRITICAL9.2NetComm NF20MESH routers running firmware R6B031 and earlier contain an authentication bypass vulnerability that allows ...
CVE-2026-28496CRITICAL9.4FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Temp...
CVE-2026-27604CRITICAL10FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version ...
CVE-2026-56379CRITICAL9.2ImageMagick before 7.1.2-15 and 6.9.13-40 contains a command injection vulnerability in the SVG decoder that allows atta...
CVE-2026-56315CRITICAL9.8picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _ai...
CVE-2026-56274CRITICAL9.9Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to inco...
CVE-2026-56258CRITICAL9.2Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows una...
CVE-2026-44089CRITICAL9.4Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. Thi...
CVE-2026-11374CRITICAL9In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated...
CVE-2026-9733CRITICAL9.1Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no...
CVE-2026-12866CRITICAL9.8All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execu...

Check if your code is affected by 2026 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now