Search
3,702 CVEs · Medium severity
CVEs (3,702, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 326–350 of 3,702 (capped at 500)
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-19301 | MEDIUM | 5.0 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to server-side request forgery. | |
| CVE-2026-19299 | MEDIUM | 6.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 could allow a remote authenticated attacker to obtain sensitive information due to path traversal. | |
| CVE-2026-18887 | MEDIUM | 6.5 | 2026-09-04 | IBM i 7.6, 7.5, 7.4, and 7.3 could allow an authenticated attacker to obtain sensitive information in PASE. An attacker could exploit this vulnerability to access informati… | |
| CVE-2026-18567 | MEDIUM | 4.4 | 2026-09-04 | IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attacker to obtain information due to a race condition involving a predictable Unix domain socket path in a world… | |
| CVE-2026-9186 | MEDIUM | 6.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated attackers to bypass localhost-only MCP configuration installation by spoofing X-Forwarded-For: 127.0.0.1 h… | |
| CVE-2026-9138 | MEDIUM | 6.5 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 Langflow could allow an authenticated attacker to write arbitrary files to the server due to improper input validation in the SaveToFi… | |
| CVE-2026-8447 | MEDIUM | 6.1 | 2026-09-04 | IBM Langflow OSS 1.0.0 through 1.11.2 suffer from a stored cross-site scripting vulnerability in the Playground chat interface. | |
| CVE-2026-85700 | MEDIUM | 6.5 | 2026-09-04 | Onyx 4.6.6 fails to properly restrict access to custom tool credentials stored in custom_headers, allowing any authenticated user to read admin-defined API keys. Attackers … | |
| CVE-2026-85698 | MEDIUM | 5.5 | 2026-09-04 | Turso through 0.8.0-pre.8 contains an out-of-bounds read vulnerability in the table-leaf page reader that uses an attacker-controlled cell-count field without bounds valida… | |
| CVE-2026-85697 | MEDIUM | 6.5 | 2026-09-04 | Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can… | |
| CVE-2026-85693 | MEDIUM | 6.5 | 2026-09-04 | Chatbot UI contains an authorization bypass vulnerability in the retrieval endpoint that allows authenticated attackers to access private file content belonging to other us… | |
| CVE-2026-85692 | MEDIUM | 6.5 | 2026-09-04 | Nightingale (n9e), as of commit 8362cbe (main branch, confirmed 2026-08-27), contains a server-side request forgery vulnerability in the isPublicIP function in aiagent/tool… | |
| CVE-2026-85689 | MEDIUM | 6.5 | 2026-09-04 | llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolate… | |
| CVE-2026-85676 | MEDIUM | 4.3 | 2026-09-04 | Dub contains an open redirect vulnerability in the redir_url query parameter that is accepted on every short link without validation or domain allowlist enforcement. Attack… | |
| CVE-2026-85670 | MEDIUM | 6.5 | 2026-09-04 | tokenizers (Hugging Face) is affected by an out-of-bounds buffer access in BpeBuilder::build (tokenizers/src/models/bpe/model.rs). When loading a tokenizer.json via Tokeniz… | |
| CVE-2026-85669 | MEDIUM | 6.5 | 2026-09-04 | potpie through 2.0.0 fails to verify user ownership on the POST /conversations/{conversation_id}/code-changes/sync endpoint. Authenticated attackers can write arbitrary fil… | |
| CVE-2026-85665 | MEDIUM | 6.5 | 2026-09-04 | Bruno versions through 4.1.0 fail to validate file paths in request body declarations, allowing attackers to read arbitrary local files by using parent-directory traversal … | |
| CVE-2026-85662 | MEDIUM | 5.3 | 2026-09-04 | Marqo 2.26.0 contains a server-side request forgery vulnerability in the add_documents endpoint that allows unauthenticated attackers to trigger requests to arbitrary URLs … | |
| CVE-2026-85650 | MEDIUM | Patched | 5.4 | 2026-09-04 | Trigger.dev before 4.5.2 contains a server-side request forgery vulnerability in webhook alert channel delivery URLs that are fetched without validation or SSRF protection.… |
| CVE-2026-85624 | MEDIUM | 6.5 | 2026-09-04 | Blinko 1.8.7 contains a cross-user private note disclosure vulnerability in the noteReferenceList procedure that performs no ownership verification on supplied note identif… | |
| CVE-2026-85622 | MEDIUM | 5.3 | 2026-09-04 | AppFlowy-Cloud through 0.9.64 fails to validate workspace membership when establishing WebSocket connections in the establish_ws_connection_v2 handler, allowing authenticat… | |
| CVE-2026-85621 | MEDIUM | 6.5 | 2026-09-04 | LobeChat (LobeHub) 2.2.1 does not properly verify inbound chat-platform webhook signatures in the QQ and Feishu adapters. The webhook route (/api/agent/webhooks/:platform) … | |
| CVE-2026-85618 | MEDIUM | 6.5 | 2026-09-04 | ConvertX 0.17.0 contains an arbitrary file read vulnerability in the xelatex converter that allows authenticated users to read files by uploading LaTeX files with input dir… | |
| CVE-2026-85605 | MEDIUM | Patched | 5.3 | 2026-09-04 | Slink before 1.12.3 fails to properly authorize access to image comment endpoints, allowing unauthenticated attackers to read comment threads via GET /api/image/{imageId}/c… |
| CVE-2026-81859 | MEDIUM | 6.2 | 2026-09-04 | CP4BA - IBM Enterprise Records could allow a local attacker to obtain sensitive information due to the use of a broken or risky cryptographic algorithm. |