Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
51943
Total
4127
Critical
15407
High
15098
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-9171 | HIGH | 7.5 | IBM PowerVM Novalink are vulnerable to a denial of service, caused by sending a specially-crafted request. A remote attacker could exploit this vulnerability to cause … | Jul 17, 2026 |
| CVE-2026-9135 | CRITICAL | 9.9 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that … | Jul 17, 2026 |
| CVE-2026-9103 | CRITICAL | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint … | Jul 17, 2026 |
| CVE-2026-58195 | HIGH | 8.8 | Agentic-Flow is an AI agent orchestration platform. Prior to 2.0.14, agentic-flow MCP server tools in src/mcp/standalone-stdio.ts, src/mcp/fastmcp/servers/claude-flow-sdk.ts, src/mcp/fastmcp/servers/stdio-full.ts, src/mcp/fastmcp/servers/http-streaming-updated.ts, src/mcp/fastmcp/servers/http-sse.ts, src/mcp/fastmcp/servers/poc-stdio.ts, src/mcp/fastmcp/tools/agent/{execute,list,parallel}.ts, src/mcp/fastmcp/tools/swarm/orchestrate.ts, and src/mcp/fastmcp/tools/hooks/pretrain.ts … | Jul 17, 2026 |
| CVE-2026-53712 | UNKNOWN | — | SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Prior to 3.3, … | Jul 17, 2026 |
| CVE-2026-52746 | HIGH | 7.5 | JSONata is a JSON query and transformation language. Prior to 2.2.0, malicious non-matching inputs to the $toMillis function can cause superlinear backtracking in the ISO-8601 … | Jul 17, 2026 |
| CVE-2026-50185 | UNKNOWN | — | RustCrypto CMOV provides conditional move CPU intrinsics which are guaranteed on major platforms to execute in constant-time and not be rewritten as branches by the … | Jul 17, 2026 |
| CVE-2026-49835 | MEDIUM | 5.9 | Sigstore Timestamp Authority is a service for issuing RFC 3161 timestamps. Prior to 2.1.0, the global wrapMetrics middleware records raw HTTP request path r.URL.Path and … | Jul 17, 2026 |
| CVE-2026-48487 | UNKNOWN | — | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.16, _read_character_string and _read_string in src/zeroconf/_protocol/incoming.py advanced self.offset by attacker-declared RDLENGTH without … | Jul 17, 2026 |
| CVE-2026-48045 | MEDIUM | 6.5 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.12, AsyncListener.handle_query_or_defer retained every truncated TC-bit incoming query, each up to _MAX_MSG_ABSOLUTE … | Jul 17, 2026 |
| CVE-2026-47184 | MEDIUM | 6.5 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.7, DNSCache._async_add inserted every response record into cache, _expirations, _expire_heap, and service_cache … | Jul 17, 2026 |
| CVE-2026-47183 | MEDIUM | 6.5 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.6, DNSIncoming._log_exception_debug and the four QuietLogger exception-dedup methods stored an unbounded _seen_logs … | Jul 17, 2026 |
| CVE-2026-47180 | MEDIUM | 6.5 | Zeroconf is a pure Python implementation of multicast DNS service discovery. Prior to 0.149.5, DNSIncoming._decode_labels_at_offset recurses once per DNS-name compression pointer, and a single mDNS … | Jul 17, 2026 |
| CVE-2026-45703 | MEDIUM | 6.4 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, the WordExport export flow in bundles/WordExportBundle/src/Controller/TranslationController.php only checks the … | Jul 17, 2026 |
| CVE-2026-45309 | UNKNOWN | — | AsyncSSH is a Python package which provides an asynchronous client and server implementation of the SSHv2 protocol on top of the Python asyncio framework. Prior … | Jul 17, 2026 |
| CVE-2026-45162 | HIGH | 8.0 | Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.17 (LTS) and 12.3.7, multiple Pimcore locations call PHP's unserialize() on data from … | Jul 17, 2026 |
| CVE-2026-16073 | LOW | 3.5 | A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function Star.text_to_image/NetworkRenderStrategy.render of the file astrbot/core/star/base.py of … | Jul 17, 2026 |
| CVE-2026-9762 | HIGH | 7.8 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution when jdbc url is under user control. | Jul 17, 2026 |
| CVE-2026-9202 | CRITICAL | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented deployment option), newly created … | Jul 17, 2026 |
| CVE-2026-9198 | CRITICAL | 9.8 | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via … | Jul 17, 2026 |
| CVE-2026-50273 | HIGH | 7.5 | Datadog .NET Tracer is a client library for Datadog APM for .NET applications. Prior to 3.43.0, Datadog tracing libraries that implement W3C baggage propagation parse … | Jul 17, 2026 |
| CVE-2026-48016 | MEDIUM | 4.3 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the Store API endpoint /store-api/handle-payment in src/Core/Checkout/Payment/SalesChannel/HandlePaymentMethodRoute.php accepts a user-controlled orderId and forwards it … | Jul 17, 2026 |
| CVE-2026-48015 | MEDIUM | 4.9 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, SVG files are in the allowed_extensions whitelist in src/Core/Framework/Resources/config/packages/shopware.yaml and can be uploaded via … | Jul 17, 2026 |
| CVE-2026-48014 | MEDIUM | 6.5 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, the order state transition features /api/_action/order/{orderId}/state/{transition} and similar transaction and delivery transition routes in … | Jul 17, 2026 |
| CVE-2026-48010 | MEDIUM | 6.5 | Shopware is an open commerce platform. Prior to 6.6.10.18 and 6.7.10.1, UserController::upsertUser() in src/Core/Framework/Api/Controller/UserController.php writes raw user data in SYSTEM_SCOPE without filtering the admin field, … | Jul 17, 2026 |