Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51856
Total
4111
Critical
15381
High
15070
Medium
CVE ID Severity Score Description Published
CVE-2026-13446 CRITICAL 9.8 IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound … Jul 17, 2026
CVE-2026-13445 HIGH 8.1 IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by … Jul 17, 2026
CVE-2026-8861 MEDIUM 5.3 IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information … Jul 17, 2026
CVE-2026-8859 CRITICAL 9.9 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the … Jul 17, 2026
CVE-2026-8635 CRITICAL 9.9 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve … Jul 17, 2026
CVE-2026-8505 CRITICAL 9.8 IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The … Jul 17, 2026
CVE-2026-8481 CRITICAL 9.9 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied … Jul 17, 2026
CVE-2026-8476 CRITICAL 9.9 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() … Jul 17, 2026
CVE-2026-8056 HIGH 8.8 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the … Jul 17, 2026
CVE-2026-7872 HIGH 7.5 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any … Jul 17, 2026
CVE-2026-7771 MEDIUM 5.5 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to … Jul 17, 2026
CVE-2026-7755 HIGH 8.8 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files. Jul 17, 2026
CVE-2026-7754 HIGH 7.7 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF … Jul 17, 2026
CVE-2026-7667 HIGH 8.8 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted … Jul 17, 2026
CVE-2026-7364 LOW 3.1 IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Identity Access Container 11.0 through 11.0.2 and … Jul 17, 2026
CVE-2026-63030 CRITICAL 9.8 WordPress 6.9.x before 6.9.5 and 7.0.x before 7.0.2 is affected by a REST API batch endpoint route confusion issue which, combined with the author__not_in WP_Query … Jul 17, 2026
CVE-2026-60137 MEDIUM 5.9 WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author__not_in parameter of WP_Query, which could allow SQL Injection … Jul 17, 2026
CVE-2026-55254 MEDIUM 4.8 NCalc is a fast, lightweight expression evaluator for .NET. Prior to 6.1.1, the factorial operator implementation in src/NCalc.Core/Helpers/MathHelper.cs permits specially crafted expressions with extremely large … Jul 17, 2026
CVE-2026-54465 UNKNOWN — websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, when websocket-driver is used to implement a WebSocket server on top of a … Jul 17, 2026
CVE-2026-54464 UNKNOWN — ### Impact If this library is used in tandem with the `permessage-deflate` extension, a WebSocket server or client can be made to accept messages that … Jul 17, 2026
CVE-2026-54463 UNKNOWN — websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.1, draft versions of the WebSocket protocol in websocket-driver include a length header that … Jul 17, 2026
CVE-2026-54171 MEDIUM 6.5 Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon's RedirectFollower middleware failed to strip additional sensitive headers when following redirects and … Jul 17, 2026
CVE-2026-52199 UNKNOWN — An issue in Generic OEM UZ801_v2.1 4G LTE Router V3.4.3 allows a remote attacker to execute arbitrary code via the sbin/adbd component Jul 17, 2026
CVE-2026-51833 UNKNOWN — Xenforo 2.3.8 is vulnerable to SSRF. Attackers that have administrator privileges or are able to add/save RSS feeds can enumerate internal services (ports) or expose … Jul 17, 2026
CVE-2026-50289 UNKNOWN — systeminformation is a System and OS information library for node.js. Prior to 5.31.7, networkInterfaces() on Linux is vulnerable to OS command injection through the Debian/Ubuntu … Jul 17, 2026