Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51856
Total
4111
Critical
15381
High
15070
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-13446 | CRITICAL | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound … | Jul 17, 2026 |
| CVE-2026-13445 | HIGH | 8.1 | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by … | Jul 17, 2026 |
| CVE-2026-8861 | MEDIUM | 5.3 | IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information … | Jul 17, 2026 |
| CVE-2026-8859 | CRITICAL | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the … | Jul 17, 2026 |
| CVE-2026-8635 | CRITICAL | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve … | Jul 17, 2026 |
| CVE-2026-8505 | CRITICAL | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The … | Jul 17, 2026 |
| CVE-2026-8481 | CRITICAL | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied … | Jul 17, 2026 |
| CVE-2026-8476 | CRITICAL | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() … | Jul 17, 2026 |
| CVE-2026-8056 | HIGH | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the … | Jul 17, 2026 |
| CVE-2026-7872 | HIGH | 7.5 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any … | Jul 17, 2026 |
| CVE-2026-7771 | MEDIUM | 5.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to … | Jul 17, 2026 |
| CVE-2026-7755 | HIGH | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files. | Jul 17, 2026 |
| CVE-2026-7754 | HIGH | 7.7 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF … | Jul 17, 2026 |
| CVE-2026-7667 | HIGH | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted … | Jul 17, 2026 |
| CVE-2026-7364 | LOW | 3.1 | IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and … | Jul 17, 2026 |
| CVE-2026-63030 | CRITICAL | 9.8 | WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query … | Jul 17, 2026 |
| CVE-2026-60137 | MEDIUM | 5.9 | WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection … | Jul 17, 2026 |
| CVE-2026-55254 | MEDIUM | 4.8 | NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src/NCalc.Core/Helpers/MathHelper.cs permits specially crafted expressions with extremely large … | Jul 17, 2026 |
| CVE-2026-54465 | UNKNOWN | — | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a … | Jul 17, 2026 |
| CVE-2026-54464 | UNKNOWN | — | ### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can be made to accept messages that … | Jul 17, 2026 |
| CVE-2026-54463 | UNKNOWN | — | websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that … | Jul 17, 2026 |
| CVE-2026-54171 | MEDIUM | 6.5 | Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and … | Jul 17, 2026 |
| CVE-2026-52199 | UNKNOWN | — | An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component | Jul 17, 2026 |
| CVE-2026-51833 | UNKNOWN | — | Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose … | Jul 17, 2026 |
| CVE-2026-50289 | UNKNOWN | — | systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the Debian/Ubuntu … | Jul 17, 2026 |