Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49645
Total
4014
Critical
14740
High
14481
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-9130 | HIGH | 7.1 | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users … | Aug 05, 2026 |
| CVE-2026-8478 | HIGH | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user … | Aug 05, 2026 |
| CVE-2026-8470 | HIGH | 7.4 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption … | Aug 05, 2026 |
| CVE-2026-8183 | HIGH | 7.7 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a … | Aug 05, 2026 |
| CVE-2026-8182 | HIGH | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP … | Aug 05, 2026 |
| CVE-2026-7869 | MEDIUM | 5.4 | IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names … | Aug 05, 2026 |
| CVE-2026-7658 | MEDIUM | 6.5 | IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This … | Aug 05, 2026 |
| CVE-2026-70612 | MEDIUM | 5.4 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external … | Aug 05, 2026 |
| CVE-2026-63457 | MEDIUM | 6.5 | A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78. | Aug 05, 2026 |
| CVE-2026-48168 | CRITICAL | 10.0 | PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds … | Aug 05, 2026 |
| CVE-2026-18485 | HIGH | 7.8 | There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a local, authenticated user to escalate privileges and … | Aug 05, 2026 |
| CVE-2026-17633 | HIGH | 8.5 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection. | Aug 05, 2026 |
| CVE-2026-17632 | HIGH | 8.8 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based … | Aug 05, 2026 |
| CVE-2026-17624 | HIGH | 8.5 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 … | Aug 05, 2026 |
| CVE-2026-10547 | MEDIUM | 5.9 | IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph … | Aug 05, 2026 |
| CVE-2026-9081 | HIGH | 7.1 | IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. … | Aug 05, 2026 |
| CVE-2026-7657 | MEDIUM | 6.5 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement. | Aug 05, 2026 |
| CVE-2026-70611 | MEDIUM | 6.9 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in … | Aug 05, 2026 |
| CVE-2026-70610 | MEDIUM | 5.4 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the … | Aug 05, 2026 |
| CVE-2026-70609 | MEDIUM | 5.7 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of … | Aug 05, 2026 |
| CVE-2026-70608 | HIGH | 7.2 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the … | Aug 05, 2026 |
| CVE-2026-70448 | HIGH | 7.1 | Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files. | Aug 05, 2026 |
| CVE-2026-70447 | MEDIUM | 4.3 | Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | Aug 05, 2026 |
| CVE-2026-70446 | MEDIUM | 4.3 | Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | Aug 05, 2026 |
| CVE-2026-70445 | MEDIUM | 4.3 | Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. | Aug 05, 2026 |