Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Unclassified CRITICAL 9.0
CVE-2026-54157

LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy end…

Mitigation only
Fix from $2,300 2026-06-23
Unclassified CRITICAL 9.6
CVE-2026-53662

immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (X…

Patch available
Fix from $2,300 2026-06-23
Deno CRITICAL 9.1
CVE-2026-44726

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS…

Fix: 2.7.8+
Fix from $2,300 2026-06-23
Langflow CRITICAL 9.3
CVE-2026-55450

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to…

Fix: 1.9.1+
Fix from $2,300 2026-06-23
Langflow CRITICAL 9.6
CVE-2026-55447

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG,…

Fix: 1.9.2+
Fix from $2,300 2026-06-23
N8n CRITICAL 9.6
CVE-2026-54307

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflo…

Fix: 1.123.55 / 2.25.7+
Fix from $2,300 2026-06-23
N8n CRITICAL 9.9
CVE-2026-54305

n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature…

Fix: 1.123.55 / 2.25.7+
Fix from $2,300 2026-06-23
Yt Dlp CRITICAL 9.6
CVE-2026-50574

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (s…

Fix: 2026.06.09+
Fix from $2,300 2026-06-23
Yt Dlp CRITICAL 9.6
CVE-2026-50023

yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitra…

Fix: 2026.06.09+
Fix from $2,300 2026-06-23
Langflow CRITICAL 9.6
CVE-2026-48519

Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code)…

Fix: 1.9.2+
Fix from $2,300 2026-06-23
N8n CRITICAL 9.0
CVE-2026-44792

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connec…

Fix: 1.123.43 / 2.20.7+
Fix from $2,300 2026-06-23
N8n CRITICAL 9.9
CVE-2026-44791

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify …

Fix: 1.123.43 / 2.20.7+
Fix from $2,300 2026-06-23
N8n CRITICAL 9.9
CVE-2026-44789

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify …

Fix: 1.123.43 / 2.20.7+
Fix from $2,300 2026-06-23
N8n CRITICAL 9.9
CVE-2026-54310

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows c…

Fix: 2.25.7 / 2.26.2+
Fix from $2,300 2026-06-23
N8n CRITICAL 10.0
CVE-2026-54309

n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint…

Fix: 2.25.7 / 2.26.2+
Fix from $2,300 2026-06-23
Unclassified CRITICAL 9.4
CVE-2026-28496

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnera…

Mitigation only
Fix from $2,300 2026-06-23
Unclassified CRITICAL 10.0
CVE-2026-27604

FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypas…

Mitigation only
Fix from $2,300 2026-06-23
Unclassified CRITICAL 9.8
CVE-2026-56315

picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and…

Mitigation only
Fix from $2,300 2026-06-23
Flowise CRITICAL 9.9
CVE-2026-56274EPSS 8%

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validatio…

Fix: 3.1.2+
Fix from $2,300 2026-06-23
Unclassified CRITICAL 9.4
CVE-2026-44089

Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be expl…

Mitigation only
Fix from $2,300 2026-06-23
Unclassified CRITICAL 9.0
CVE-2026-11374

In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session…

Mitigation only
Fix from $2,300 2026-06-23
Unclassified CRITICAL 9.1
CVE-2026-9733

Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified…

Patch available
Fix from $2,300 2026-06-23
Unclassified CRITICAL 9.8
CVE-2026-12866

All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by su…

Mitigation only
Fix from $2,300 2026-06-23
Vllm CRITICAL 9.1
CVE-2026-48746

vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette'…

Fix: 0.22.0+
Fix from $2,300 2026-06-22
N8n CRITICAL 9.9
CVE-2026-56348

n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticat…

Fix: 2.20.0+
Fix from $2,300 2026-06-22
Messagepack CRITICAL 9.1
CVE-2026-48509

MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses def…

Fix: 2.5.301 / 3.1.7+
Fix from $2,300 2026-06-22
Litellm CRITICAL 9.8
CVE-2026-49468

LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM prox…

Fix: 1.84.0+
Fix from $2,300 2026-06-22
Unclassified CRITICAL 9.2
CVE-2026-45034

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohi…

No fix yet
Fix from $2,300 2026-06-22
Unclassified CRITICAL 9.0
CVE-2026-12249

An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-e…

Patch available
Fix from $2,300 2026-06-22
Fusion CRITICAL 9.6
CVE-2026-10789

A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability…

Fix: 2703.1.20+
Fix from $2,300 2026-06-22