Vulnerability index

Browse CVEs

10,000+ matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.0 CVE-2026-54157 LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.57, the /webapi/proxy end… Mitigation only Fix from $2,3002026-06-23 CRITICAL 9.6 CVE-2026-53662 immich is a high performance self-hosted photo and video management solution. From commit 4ffa26c9 until 4eb1003, a reflected cross-site scripting (X… Patch available Fix from $2,3002026-06-23 CRITICAL 9.1 CVE-2026-44726 Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.0.0 until 2.7.8, a flaw in Deno's Node.js tls compatibility layer could cause a TLS… Deno 2.7.8+ Fix from $2,3002026-06-23 CRITICAL 9.3 CVE-2026-55450 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to… Langflow 1.9.1+ Fix from $2,3002026-06-23 CRITICAL 9.6 CVE-2026-55447 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG,… Langflow 1.9.2+ Fix from $2,3002026-06-23 CRITICAL 9.6 CVE-2026-54307 n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, a member-level user with editor access to a shared workflo… N8n 1.123.55 / 2.25.7+ Fix from $2,3002026-06-23 CRITICAL 9.9 CVE-2026-54305 n8n is an open source workflow automation platform. Prior to 1.123.55, 2.25.7, and 2.26.2, three EE endpoints used by the Dynamic Credentials feature… N8n 1.123.55 / 2.25.7+ Fix from $2,3002026-06-23 CRITICAL 9.6 CVE-2026-50574 yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (s… Yt Dlp 2026.06.09+ Fix from $2,3002026-06-23 CRITICAL 9.6 CVE-2026-50023 yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitra… Yt Dlp 2026.06.09+ Fix from $2,3002026-06-23 CRITICAL 9.6 CVE-2026-48519 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code)… Langflow 1.9.2+ Fix from $2,3002026-06-23 CRITICAL 9.0 CVE-2026-44792 n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connec… N8n 1.123.43 / 2.20.7+ Fix from $2,3002026-06-23 CRITICAL 9.9 CVE-2026-44791 n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify … N8n 1.123.43 / 2.20.7+ Fix from $2,3002026-06-23 CRITICAL 9.9 CVE-2026-44789 n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify … N8n 1.123.43 / 2.20.7+ Fix from $2,3002026-06-23 CRITICAL 9.9 CVE-2026-54310 n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, an authenticated user with permission to create or modify workflows c… N8n 2.25.7 / 2.26.2+ Fix from $2,3002026-06-23 CRITICAL 10.0 CVE-2026-54309 n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, when @n8n/mcp-browser is run in HTTP transport mode, the MCP endpoint… N8n 2.25.7 / 2.26.2+ Fix from $2,3002026-06-23 CRITICAL 9.4 CVE-2026-28496 FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 have a Server-Side Template Injection (SSTI) vulnera… Mitigation only Fix from $2,3002026-06-23 CRITICAL 10.0 CVE-2026-27604 FOSSBilling is a free, open-source billing and client management system. Starting in version 0.5.4 and prior to version 0.8.0, an authorization bypas… Mitigation only Fix from $2,3002026-06-23 CRITICAL 9.8 CVE-2026-56315 picklescan before 1.0.4 fails to block at least seven Python standard library modules (including uuid, _osx_support, _aix_support, _pyrepl.pager, and… Mitigation only Fix from $2,3002026-06-23 CRITICAL 9.9 CVE-2026-56274EPSS 8% Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validatio… Flowise 3.1.2+ Fix from $2,3002026-06-23 CRITICAL 9.4 CVE-2026-44089 Totolink EX1200L router is vulnerable to Buffer Overflow in the login functionality in cgi-bin/cstecgi.cgi endpoint. This vulnerability could be expl… Mitigation only Fix from $2,3002026-06-23 CRITICAL 9.0 CVE-2026-11374 In ManageEngine ADSelfService Plus, RecoveryManager Plus, M365 Manager Plus, and ADAudit Plus, the SSO tickets generated to authenticate that session… Mitigation only Fix from $2,3002026-06-23 CRITICAL 9.1 CVE-2026-9733 Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter. When no state generator is specified… Patch available Fix from $2,3002026-06-23 CRITICAL 9.8 CVE-2026-12866 All versions of the package expr-eval are vulnerable to Code Execution via the toJSFunction() API. An attacker can execute arbitrary JavaScript by su… Mitigation only Fix from $2,3002026-06-23 CRITICAL 9.1 CVE-2026-48746 vLLM is an inference and serving engine for large language models (LLMs). From 0.3.0 until 0.22.0, a vulnerability in ASGI web servers and starlette'… Vllm 0.22.0+ Fix from $2,3002026-06-22 CRITICAL 9.9 CVE-2026-56348 n8n before 2.20.0 contains a credential exfiltration vulnerability in the POST /rest/dynamic-node-parameters/options endpoint that allows authenticat… N8n 2.20.0+ Fix from $2,3002026-06-22 CRITICAL 9.1 CVE-2026-48509 MessagePack for C# is a MessagePack serializer for C#. Prior to 2.5.301 and 3.1.7, the parameterless MessagePackInputFormatter() constructor uses def… Messagepack 2.5.301 / 3.1.7+ Fix from $2,3002026-06-22 CRITICAL 9.8 CVE-2026-49468 LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. Prior to 1.84.0, a Host-header parsing flaw in the LiteLLM prox… Litellm 1.84.0+ Fix from $2,3002026-06-22 CRITICAL 9.2 CVE-2026-45034 PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.5, CVE-2026-34084 was patched by the helper File::prohi… No fix yet Fix from $2,3002026-06-22 CRITICAL 9.0 CVE-2026-12249 An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-e… Patch available Fix from $2,3002026-06-22 CRITICAL 9.6 CVE-2026-10789 A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability… Fusion 2703.1.20+ Fix from $2,3002026-06-22