Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

41921
Total
3420
Critical
12394
High
12304
Medium
CVE ID Severity Score Description Published
CVE-2026-18567 MEDIUM 4.4 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable … Sep 04, 2026
CVE-2022-35499 HIGH 7.1 In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL. Sep 04, 2026
CVE-2022-35497 UNKNOWN In Trimble TM4WEB 21.4.0.4 due to security misconfiguration with session identifiers, it is possible to recover valid session cookies via reflected cross-site scripting affecting the … Sep 04, 2026
CVE-2026-9186 MEDIUM 6.5 IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 header, enabling arbitrary writes to … Sep 04, 2026
CVE-2026-9138 MEDIUM 6.5 IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in … Sep 04, 2026
CVE-2026-8447 MEDIUM 6.1 IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface. Sep 04, 2026
CVE-2026-85700 MEDIUM 6.5 Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers with … Sep 04, 2026
CVE-2026-85699 HIGH 7.5 jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect hops. … Sep 04, 2026
CVE-2026-85698 MEDIUM 5.5 Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds validation. Attackers can craft … Sep 04, 2026
CVE-2026-85697 MEDIUM 6.5 Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted … Sep 04, 2026
CVE-2026-85696 CRITICAL 9.8 SadTalker contains an OS command injection vulnerability in the video muxing process where uploaded audio filenames are interpolated into ffmpeg commands without proper escaping. Attackers … Sep 04, 2026
CVE-2026-85695 CRITICAL 9.4 FastChat contains an authentication bypass vulnerability in the /register_worker endpoint that allows unauthenticated attackers to register arbitrary worker addresses and perform server-side request forgery. Attackers … Sep 04, 2026
CVE-2026-85694 HIGH 8.1 LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from web page content. Attackers can inject malicious … Sep 04, 2026
CVE-2026-85693 MEDIUM 6.5 Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other users by … Sep 04, 2026
CVE-2026-85692 MEDIUM 6.5 Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vulnerability in the isPublicIP function in aiagent/tools/http.go, the SSRF guard … Sep 04, 2026
CVE-2026-85691 HIGH 7.5 MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers can supply internal service URLs … Sep 04, 2026
CVE-2026-85690 HIGH 7.8 Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory. Attackers can influence model … Sep 04, 2026
CVE-2026-85689 MEDIUM 6.5 llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolated into SQL WHERE clauses without … Sep 04, 2026
CVE-2026-85688 CRITICAL 9.8 TEN Framework 0.11.71 contains unauthenticated arbitrary file read and write vulnerabilities in the TMAN Designer file-content API endpoints. Attackers can submit POST and PUT requests … Sep 04, 2026
CVE-2026-85687 HIGH 7.5 surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. Attackers can … Sep 04, 2026
CVE-2026-85686 HIGH 7.5 ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redirect filtering. Unauthenticated … Sep 04, 2026
CVE-2026-85685 HIGH 7.5 AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an unconfined source path parameter. … Sep 04, 2026
CVE-2026-85684 CRITICAL 9.1 marker through 2.0.0 contains a path traversal vulnerability in the FastAPI /marker/upload handler that fails to sanitize the file.filename parameter. Unauthenticated attackers can supply filenames … Sep 04, 2026
CVE-2026-85676 MEDIUM 4.3 Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attackers … Sep 04, 2026
CVE-2026-85675 HIGH 7.5 OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, host, or IP filtering. Attackers can … Sep 04, 2026