CVE Vulnerability Database

Search and browse 394,518 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-56113MEDIUM6.5dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated...
CVE-2026-55450CRITICAL9.3Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can...
CVE-2026-55447CRITICAL9.6Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files th...
CVE-2026-55446HIGH7.5Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /...
CVE-2026-55423MEDIUM6.1Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does no...
CVE-2026-55255HIGH8.4Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object...
CVE-2026-54308HIGH7.2n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, the MicrosoftAgent365Trigger and StripeT...
CVE-2026-54307CRITICAL9.6n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with edit...
CVE-2026-54306MEDIUM6.4n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allo...
CVE-2026-54305CRITICAL9.9n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by th...
CVE-2026-54304HIGH7.7n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.1, an authenticated user with pe...
CVE-2026-54302MEDIUM5.4n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with wo...
CVE-2026-54301MEDIUM5.4n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, an authenticated user with wo...
CVE-2026-50574CRITICAL9.6yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a ...
CVE-2026-50023CRITICAL9.6yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a rem...
CVE-2026-50019HIGH7.4yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downlo...
CVE-2026-49465HIGH7.7n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with pe...
CVE-2026-49444HIGH8.5n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with pe...
CVE-2026-48520MEDIUM6.1Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playgroun...
CVE-2026-48519CRITICAL9.6Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground...
CVE-2026-45732HIGH8.1n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credent...
CVE-2026-44961NONE0The XML‑RPC API addUser method has a validation bypass introduced in the fix for CVE‑2025‑55129. As a result, API users ...
CVE-2026-44960NONE0A stored XSS can be exploited by leveraging the usernames as an attack vector. When an admin user viewed the audit log d...
CVE-2026-44959HIGH8.8A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑p...
CVE-2026-44958MEDIUM5.4An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and...