Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

51943
Total
4127
Critical
15407
High
15098
Medium
CVE ID Severity Score Description Published
CVE-2026-52584 UNKNOWN — Buffer Overflow vulnerability in libjxl v.0.11.2 and before allows a local attacker to obtain sensitive information via the DecodeImageAPNG function Jul 17, 2026
CVE-2026-52348 UNKNOWN — cool-admin-java 8.0.0 has a SQL injection vulnerability in the order() method of CrudOption.java. Jul 17, 2026
CVE-2026-52203 UNKNOWN — An issue in MCMS v.6.1.1 allows a remote attacker to obtain sensitive information via the source parameter. Jul 17, 2026
CVE-2026-50274 HIGH 7.5 Datadog dd-trace-go is a Go client library for Datadog application performance monitoring, profiling, and security monitoring. Prior to 2.8.1, Datadog tracing libraries that implement W3C … Jul 17, 2026
CVE-2026-50272 HIGH 7.5 dd-trace is the Datadog APM client for Node.js. Prior to 5.100.0, W3C baggage propagation in packages/dd-trace/src/baggage.js and packages/dd-trace/src/opentracing/propagation/text_map.js parsed incoming baggage HTTP headers without enforcing … Jul 17, 2026
CVE-2026-50271 HIGH 7.5 Datadog dd-trace-py is the Datadog Python APM client. Prior to 4.8.2, Datadog tracing libraries that implement W3C baggage propagation parse incoming baggage HTTP headers without … Jul 17, 2026
CVE-2026-49977 MEDIUM 4.3 tarteaucitron.js is a compliant and accessible cookie banner. Prior to 1.33.0, tarteaucitron.cookie.purge() is called on any element with the purgeBtn class and does not check … Jul 17, 2026
CVE-2026-48062 CRITICAL 9.8 CodeIgniter is a PHP full-stack web framework. Prior to 4.7.3, the ext_in upload validation rule in system/Validation/StrictRules/FileRules.php checked the MIME-derived guessed extension instead of the … Jul 17, 2026
CVE-2026-45785 MEDIUM 6.2 OpenMcdf is a fully .NET / C# library to manipulate Compound File Binary File Format files, also known as Structured Storage. In 3.1.3 and earlier, … Jul 17, 2026
CVE-2026-45784 UNKNOWN — rust-openssl provides OpenSSL bindings for the Rust programming language. From 0.10.50 until 0.10.80, CipherCtxRef::cipher_update_inplace in openssl/src/cipher_ctx.rs incorrectly sized output buffers when used with AES key-wrap-with-padding … Jul 17, 2026
CVE-2026-44891 HIGH 7.5 Netty is a network application framework for development of protocol servers and clients. Prior to 4.1.136.Final and 4.2.16.Final, io.netty.handler.codec.stomp.StompSubframeDecoder fails to limit the total number … Jul 17, 2026
CVE-2026-16074 MEDIUM 6.3 A vulnerability was detected in AstrBotDevs AstrBot up to 4.25.2. This affects the function update_plugin/update_all_plugins of the file astrbot/dashboard/routes/plugin.py of the component Plugin Update Handler. … Jul 17, 2026
CVE-2026-13446 CRITICAL 9.8 IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound … Jul 17, 2026
CVE-2026-13445 HIGH 8.1 IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to read and modify another user's uploaded files by … Jul 17, 2026
CVE-2026-8861 MEDIUM 5.3 IBM Security Verify could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information … Jul 17, 2026
CVE-2026-8859 CRITICAL 9.9 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the … Jul 17, 2026
CVE-2026-8635 CRITICAL 9.9 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system commands, and achieve … Jul 17, 2026
CVE-2026-8505 CRITICAL 9.8 IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The … Jul 17, 2026
CVE-2026-8481 CRITICAL 9.9 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied … Jul 17, 2026
CVE-2026-8476 CRITICAL 9.9 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() … Jul 17, 2026
CVE-2026-8056 HIGH 8.8 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the … Jul 17, 2026
CVE-2026-7872 HIGH 7.5 IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any … Jul 17, 2026
CVE-2026-7771 MEDIUM 5.5 IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a trap when compiling a specially crafted statements containing subqueries could lead to … Jul 17, 2026
CVE-2026-7755 HIGH 8.8 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files. Jul 17, 2026
CVE-2026-7754 HIGH 7.7 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF … Jul 17, 2026