Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

4,856 CVEs · High severity

CVEs (4,856, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 226–250 of 4,856 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-19298 HIGH 8.8 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to execute arbitrary code due to an authorization bypass in the flow build process.
CVE-2026-19283 HIGH 7.7 2026-09-04 IBM Observability with Instana (Agent) Build 1.0.303 through 1.0.323 IBM Instana Agent Operator could allow an authenticated remote attacker to obtain sensitive information…
CVE-2026-18905 HIGH 7.7 2026-09-04 IBM ContextForge MCP Gateway (`mcp-contextforge-gateway`) <= v1.0.6 MCP Context Forge could allow a remote authenticated attacker to obtain sensitive information due to a D&hellip;
CVE-2022-35499 HIGH 7.1 2026-09-04 In Trimble TM4WEB 21.4.0.4, the external bill viewer endpoint is vulnerable to reflected cross-site scripting via injection in a arbitrary parameter appended to the URL.
CVE-2026-85699 HIGH 7.5 2026-09-04 jina-ai reader contains a server-side request forgery vulnerability where URL validation is performed only on the initial request but not re-applied to subsequent redirect &hellip;
CVE-2026-85694 HIGH 8.1 2026-09-04 LaVague 0.2.35 contains a remote code execution vulnerability in PythonFromMarkdownExtractor.extract_as_object that evaluates untrusted language model output derived from w&hellip;
CVE-2026-85691 HIGH 7.5 2026-09-04 MegaParse 0.0.55 contains an unauthenticated server-side request forgery vulnerability in the POST /v1/url endpoint that fetches caller-supplied URLs server-side. Attackers&hellip;
CVE-2026-85690 HIGH 7.8 2026-09-04 Plandex 2.2.1 contains a path traversal vulnerability in the ApplyFiles function that allows attackers to write files outside the project directory. Attackers can influence&hellip;
CVE-2026-85687 HIGH 7.5 2026-09-04 surya 0.22.1 screenshot server contains an unauthenticated arbitrary file read vulnerability in the /info, /page, and /process routes that accept raw file_path parameters. &hellip;
CVE-2026-85686 HIGH 7.5 2026-09-04 ms-swift 4.5.2 contains a server-side request forgery vulnerability in the swift deploy OpenAI-compatible API that fetches multimodal media URLs without validation or redir&hellip;
CVE-2026-85685 HIGH 7.5 2026-09-04 AgentScope through 2.0.7.post1 contains a path traversal vulnerability in LocalWorkspace.add_skill that copies arbitrary server directories into the agent workspace via an &hellip;
CVE-2026-85675 HIGH 7.5 2026-09-04 OWL's DocumentProcessingToolkit contains a server-side request forgery vulnerability in the extract_document_content tool that fetches caller-supplied URLs with no scheme, &hellip;
CVE-2026-85674 HIGH 7.8 2026-09-04 aider (aider-chat) automatically loads a .aider.conf.yml configuration file from the root of the git repository it is launched in. A crafted repository can set test-cmd (ex&hellip;
CVE-2026-85673 HIGH 7.5 2026-09-04 LLaMA-Factory contains a server-side request forgery vulnerability in the OpenAI-compatible API multimodal media URL handler that allows unauthenticated attackers to bypass&hellip;
CVE-2026-85671 HIGH 7.5 2026-09-04 QAnything 2.0.0 contains an authentication bypass vulnerability in the /api/local_doc_qa/get_file_base64 and /api/local_doc_qa/get_doc endpoints that allows unauthenticated&hellip;
CVE-2026-85668 HIGH 7.5 2026-09-04 Xinference (affected commit 4a94832, v3.x) contains an unauthenticated arbitrary-path file read vulnerability in the POST /v1/models/llm/auto-register endpoint, which accep&hellip;
CVE-2026-85666 HIGH 7.5 2026-09-04 OGX (formerly Llama Stack, affected at commit fbe8e0f) contains an unauthenticated server-side request forgery vulnerability in the OpenAI-compatible POST /v1/responses end&hellip;
CVE-2026-85664 HIGH 7.5 2026-09-04 Chroma 1.5.9 fails to validate maximum bounds on HNSW index parameters max_neighbors, ef_construction, and ef_search in collection-create requests. Unauthenticated attacker&hellip;
CVE-2026-85660 HIGH 8.1 2026-09-04 cli-mcp-server 0.2.5 contains a command allowlist bypass vulnerability in the _validate_command_with_operators function when ALLOW_SHELL_OPERATORS is enabled. Attackers can&hellip;
CVE-2026-85651 HIGH Patched 8.5 2026-09-04 Trigger.dev versions before 4.5.2 fail to validate environment membership during run replay operations, allowing authenticated attackers to inject task runs into arbitrary &hellip;
CVE-2026-85626 HIGH 7.5 2026-09-04 git-mcp-server 2.15.1 contains an argument injection vulnerability in the ref and object parameters of git_log, git_diff, and git_show tools that lack leading-dash validati&hellip;
CVE-2026-85625 HIGH 8.1 2026-09-04 sift (sift.js) 17.1.3 enumerates query keys with for...in, which walks the object prototype chain, and dispatches any matched operator key including $where. The $where oper&hellip;
CVE-2026-85623 HIGH 8.8 2026-09-04 goose 1.37.0 executes arbitrary commands from recipe stdio extensions and retry.checks without security inspection. Attackers can distribute malicious recipes that execute &hellip;
CVE-2026-85620 HIGH 8.6 2026-09-04 Postgres MCP Pro 0.3.0 contains a restricted-mode bypass vulnerability where function-name validation is not applied to RangeFunction nodes in FROM clauses. Attackers can e&hellip;
CVE-2026-85619 HIGH 7.5 2026-09-04 AppFlowy-Cloud 0.9.64 fails to verify that requested collab objects belong to the workspace in authorization checks, allowing attackers to access documents and database row&hellip;