Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

163,528 CVEs · Medium severity

CVEs (163,528, showing first 500)

Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.

Showing 326–350 of 163,528 (capped at 500)

CVE ID Severity Patch CVSS Published Description
CVE-2026-19299 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal.
CVE-2026-19301 MEDIUM 5.0 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery.
CVE-2026-18887 MEDIUM 6.5 2026-09-04 IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access informati…
CVE-2026-18567 MEDIUM 4.4 2026-09-04 IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world…
CVE-2026-9138 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFi…
CVE-2026-9186 MEDIUM 6.5 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 h…
CVE-2026-85700 MEDIUM 6.5 2026-09-04 Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers …
CVE-2026-8447 MEDIUM 6.1 2026-09-04 IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface.
CVE-2026-85697 MEDIUM 6.5 2026-09-04 Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can…
CVE-2026-85698 MEDIUM 5.5 2026-09-04 Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds valida…
CVE-2026-85692 MEDIUM 6.5 2026-09-04 Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vulnerability in the isPublicIP function in aiagent/tool…
CVE-2026-85693 MEDIUM 6.5 2026-09-04 Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other us…
CVE-2026-85689 MEDIUM 6.5 2026-09-04 llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolate…
CVE-2026-85676 MEDIUM 4.3 2026-09-04 Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attack…
CVE-2026-85665 MEDIUM 6.5 2026-09-04 Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal …
CVE-2026-85669 MEDIUM 6.5 2026-09-04 potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary fil…
CVE-2026-85670 MEDIUM 6.5 2026-09-04 tokenizers (Hugging Face) is affected by an out-of-bounds buffer access in BpeBuilder::build (tokenizers/src/models/bpe/model.rs). When loading a tokenizer.json via Tokeniz…
CVE-2026-85650 MEDIUM Patched 5.4 2026-09-04 Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection.…
CVE-2026-85662 MEDIUM 5.3 2026-09-04 Marqo 2.26.0 contains a server-side request forgery vulnerability in the add_documents endpoint that allows unauthenticated attackers to trigger requests to arbitrary URLs …
CVE-2026-85621 MEDIUM 6.5 2026-09-04 LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters. The webhook route (/api/agent/webhooks/:platform) …
CVE-2026-85622 MEDIUM 5.3 2026-09-04 AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing authenticat…
CVE-2026-85624 MEDIUM 6.5 2026-09-04 Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identif…
CVE-2026-85605 MEDIUM Patched 5.3 2026-09-04 Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/c…
CVE-2026-85618 MEDIUM 6.5 2026-09-04 ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input dir…
CVE-2026-81859 MEDIUM 6.2 2026-09-04 CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken or risky cryptographic algorithm.