Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
42275
Total
3446
Critical
12492
High
12441
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-19294 | MEDIUM | 6.4 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private flow due to improper authorization. | Aug 28, 2026 |
| CVE-2026-19286 | CRITICAL | 9.8 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A … | Aug 28, 2026 |
| CVE-2026-18904 | HIGH | 8.2 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between … | Aug 28, 2026 |
| CVE-2026-18899 | HIGH | 7.5 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal. | Aug 28, 2026 |
| CVE-2026-18891 | HIGH | 8.2 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication. | Aug 28, 2026 |
| CVE-2026-18729 | HIGH | 8.8 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code. | Aug 28, 2026 |
| CVE-2026-18545 | MEDIUM | 4.3 | IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the … | Aug 28, 2026 |
| CVE-2026-18527 | CRITICAL | 9.9 | IBM Administration Runtime Expert for i 1R1M0 IBM Application Runtime Expert (ARE) for i could allow a remote attacker to gain elevated privileges, caused by … | Aug 28, 2026 |
| CVE-2026-17203 | HIGH | 7.5 | IBM Administration Runtime Expert for i 1R1M0 could allow a remote authenticated attacker to obtain sensitive information due to improper authentication enforcement. | Aug 28, 2026 |
| CVE-2026-16821 | HIGH | 7.0 | IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a local attacker to gain elevated privileges due to a format string vulnerability. | Aug 28, 2026 |
| CVE-2026-13735 | LOW | 3.7 | Zephyr's WireGuard implementation in subsys/net/lib/wireguard/wg_crypto.c mishandled keepalive packets. In wg_process_data_message(), any type-4 transport-data message whose payload was exactly 16 bytes (an empty plaintext plus a … | Aug 28, 2026 |
| CVE-2026-13734 | MEDIUM | 6.5 | Zephyr's WireGuard VPN data-plane receive handler wg_process_data_message() in subsys/net/lib/wireguard/wg_crypto.c validated the anti-replay counter too late. After AEAD decryption of a MESSAGE_TRANSPORT_DATA packet succeeded, the code … | Aug 28, 2026 |
| CVE-2025-64649 | MEDIUM | 5.9 | IBM Concert 1.0.0 through 2.3.1 could allow a remote attacker to perform unauthorized actions using man in the middle techniques due to improper certificate validation. | Aug 28, 2026 |
| CVE-2025-36290 | MEDIUM | 5.9 | IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information … | Aug 28, 2026 |
| CVE-2025-36271 | MEDIUM | 5.9 | IBM Integrated Analytics System 1.0.0.0 through 1.0.31.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. | Aug 28, 2026 |
| CVE-2026-82343 | MEDIUM | 6.1 | A flaw was found in the file-psd plugin in GIMP. When processing a specially crafted PSD image file, the plugin does not properly validate the … | Aug 28, 2026 |
| CVE-2026-82329 | CRITICAL | 9.8 | JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges. | Aug 28, 2026 |
| CVE-2026-82306 | MEDIUM | 6.5 | StarRocks through 4.0.13 contains an information disclosure vulnerability in the query_detail endpoint that returns unfiltered query history for all users. Authenticated attackers with low privileges … | Aug 28, 2026 |
| CVE-2026-82291 | HIGH | 8.1 | HeyForm before 3.0.0-rc.8 reflects the request Origin header in CORS responses while allowing credentials, enabling cross-origin requests with authentication. Attackers can execute authenticated GraphQL queries … | Aug 28, 2026 |
| CVE-2026-82290 | MEDIUM | 5.3 | Chainlit through 2.12.0 fails to validate ownership of feedback records in PUT and DELETE endpoints. Authenticated attackers can delete or modify other users' feedback by … | Aug 28, 2026 |
| CVE-2026-82289 | HIGH | 7.4 | Gitingest through 0.3.1 fails to properly validate hostnames in _validate_host, accepting any host with a git., gitlab., or github. prefix regardless of known-hosts list membership. … | Aug 28, 2026 |
| CVE-2026-82288 | HIGH | 7.5 | Stable Diffusion WebUI through 1.10.1 contains a credential disclosure vulnerability in the /sdapi/v1/cmd-flags endpoint that returns parsed command-line arguments including gradio_auth and api_auth values in … | Aug 28, 2026 |
| CVE-2026-82287 | HIGH | 8.1 | Rybbit before 2.7.0 contains a CORS misconfiguration vulnerability that allows attackers to bypass origin restrictions by reflecting any request origin in Access-Control-Allow-Origin responses while credentials … | Aug 28, 2026 |
| CVE-2026-82286 | HIGH | 8.6 | gpt-crawler through 1.5.1 fails to validate the outputFileName parameter in the POST /crawl endpoint, allowing unauthenticated attackers to write arbitrary files to any filesystem path. … | Aug 28, 2026 |
| CVE-2026-82285 | HIGH | 8.2 | bisheng through 2.6.0-fix2 contains a server-side request forgery vulnerability in the POST /api/v1/workflow/report/callback endpoint that lacks authentication and applies no URL scheme restrictions or host … | Aug 28, 2026 |