Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51943
Total
4127
Critical
15407
High
15098
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-52584 | UNKNOWN | — | Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function | Jul 17, 2026 |
| CVE-2026-52348 | UNKNOWN | — | cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java. | Jul 17, 2026 |
| CVE-2026-52203 | UNKNOWN | — | An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter. | Jul 17, 2026 |
| CVE-2026-50274 | HIGH | 7.5 | Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that implement W3C … | Jul 17, 2026 |
| CVE-2026-50272 | HIGH | 7.5 | dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/text_map.js parsed incoming baggage HTTP headers without enforcing … | Jul 17, 2026 |
| CVE-2026-50271 | HIGH | 7.5 | Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without … | Jul 17, 2026 |
| CVE-2026-49977 | MEDIUM | 4.3 | tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on any element with the purgeBtn class and does not check … | Jul 17, 2026 |
| CVE-2026-48062 | CRITICAL | 9.8 | CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of the … | Jul 17, 2026 |
| CVE-2026-45785 | MEDIUM | 6.2 | OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. In 3.1.3 and earlier, … | Jul 17, 2026 |
| CVE-2026-45784 | UNKNOWN | — | rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding … | Jul 17, 2026 |
| CVE-2026-44891 | HIGH | 7.5 | Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number … | Jul 17, 2026 |
| CVE-2026-16074 | MEDIUM | 6.3 | A vulnerability was detected in AstrBotDevs AstrBot up to 4.25.2. This affects the function update_plugin/update_all_plugins of the file astrbot/dashboard/routes/plugin.py of the component Plugin Update Handler. … | Jul 17, 2026 |
| CVE-2026-13446 | CRITICAL | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound … | Jul 17, 2026 |
| CVE-2026-13445 | HIGH | 8.1 | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by … | Jul 17, 2026 |
| CVE-2026-8861 | MEDIUM | 5.3 | IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information … | Jul 17, 2026 |
| CVE-2026-8859 | CRITICAL | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the … | Jul 17, 2026 |
| CVE-2026-8635 | CRITICAL | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve … | Jul 17, 2026 |
| CVE-2026-8505 | CRITICAL | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The … | Jul 17, 2026 |
| CVE-2026-8481 | CRITICAL | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied … | Jul 17, 2026 |
| CVE-2026-8476 | CRITICAL | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() … | Jul 17, 2026 |
| CVE-2026-8056 | HIGH | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the … | Jul 17, 2026 |
| CVE-2026-7872 | HIGH | 7.5 | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any … | Jul 17, 2026 |
| CVE-2026-7771 | MEDIUM | 5.5 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to … | Jul 17, 2026 |
| CVE-2026-7755 | HIGH | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files. | Jul 17, 2026 |
| CVE-2026-7754 | HIGH | 7.7 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF … | Jul 17, 2026 |