Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49645
Total
4014
Critical
14740
High
14481
Medium
CVE ID Severity Score Description Published
CVE-2026-9130 HIGH 7.1 IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users … Aug 05, 2026
CVE-2026-8478 HIGH 8.8 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user … Aug 05, 2026
CVE-2026-8470 HIGH 7.4 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption … Aug 05, 2026
CVE-2026-8183 HIGH 7.7 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a … Aug 05, 2026
CVE-2026-8182 HIGH 8.8 IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP … Aug 05, 2026
CVE-2026-7869 MEDIUM 5.4 IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names … Aug 05, 2026
CVE-2026-7658 MEDIUM 6.5 IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This … Aug 05, 2026
CVE-2026-70612 MEDIUM 5.4 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external … Aug 05, 2026
CVE-2026-63457 MEDIUM 6.5 A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78. Aug 05, 2026
CVE-2026-48168 CRITICAL 10.0 PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds … Aug 05, 2026
CVE-2026-18485 HIGH 7.8 There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a local, authenticated user to escalate privileges and … Aug 05, 2026
CVE-2026-17633 HIGH 8.5 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection. Aug 05, 2026
CVE-2026-17632 HIGH 8.8 IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based … Aug 05, 2026
CVE-2026-17624 HIGH 8.5 IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 … Aug 05, 2026
CVE-2026-10547 MEDIUM 5.9 IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph … Aug 05, 2026
CVE-2026-9081 HIGH 7.1 IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. … Aug 05, 2026
CVE-2026-7657 MEDIUM 6.5 IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement. Aug 05, 2026
CVE-2026-70611 MEDIUM 6.9 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in … Aug 05, 2026
CVE-2026-70610 MEDIUM 5.4 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the … Aug 05, 2026
CVE-2026-70609 MEDIUM 5.7 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of … Aug 05, 2026
CVE-2026-70608 HIGH 7.2 Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the … Aug 05, 2026
CVE-2026-70448 HIGH 7.1 Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files. Aug 05, 2026
CVE-2026-70447 MEDIUM 4.3 Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. Aug 05, 2026
CVE-2026-70446 MEDIUM 4.3 Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. Aug 05, 2026
CVE-2026-70445 MEDIUM 4.3 Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins. Aug 05, 2026