Search
9,841 CVEs
CVEs (9,841, showing first 500)
Only the first 500 CVEs (by current sort) are shown when searching without a keyword. Add a search term above to narrow the results.
Showing 126–150 of 9,841 (capped at 500)
| CVE ID | Severity | Patch | CVSS ↓ | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-64879 | CRITICAL | 9.9 | 2026-07-21 | A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achi… | |
| CVE-2026-47392 | CRITICAL | 9.9 | 2026-07-21 | PraisonAI is a multi-agent teams system. Prior to version 4.6.40 of PraisonAI, corresponding to version 1.6.40 of praisonaiagents, `execute_code()` in `praisonaiagents/tool… | |
| CVE-2026-54051 | CRITICAL | Patched | 9.9 | 2026-07-20 | Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to version 5.9.1, the agent sandbox gates shell commands behind an allowlist (`SandboxPolicy.isCommandAll… |
| CVE-2026-51027 | CRITICAL | 9.9 | 2026-07-20 | An issue in FileThingie v.2.5.7 allows a remote attacker to obtain sensitive information via the ft2.php component. | |
| CVE-2026-8635 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system command… |
| CVE-2026-8859 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest c… |
| CVE-2026-8476 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's uns… |
| CVE-2026-8481 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint ac… |
| CVE-2026-9135 | CRITICAL | Patched | 9.9 | 2026-07-17 | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies… |
| CVE-2026-46512 | CRITICAL | Patched | 9.9 | 2026-07-16 | Frogman provides headless PBX control through MCP and HTTP API. Prior to 1.6.2, fm_dialplan_apply accepted template parameters including greeting, dest, url, extension, cod… |
| CVE-2026-52891 | CRITICAL | Patched | 9.9 | 2026-07-15 | Wekan is open source kanban built with Meteor. Prior to 9.07, Wekan avatar upload functionality embeds user-supplied filenames into paths later passed to child_process.exec… |
| CVE-2026-54052 | CRITICAL | Patched | 9.9 | 2026-07-15 | n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.56.1, in HTTP mode with multi-tenancy enabled … |
| CVE-2026-44986 | CRITICAL | Patched | 9.9 | 2026-07-15 | Penpot is an open-source design tool for design and code collaboration. Prior to 2.14.5, Penpot exposed teams_invitations.clj invitation tokens from create-team-invitations… |
| CVE-2026-48318 | CRITICAL | 9.9 | 2026-07-14 | ColdFusion is affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An … | |
| CVE-2026-57092 | CRITICAL | Patched | 9.9 | 2026-07-14 | Use after free in Windows VMSwitch allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-44747 | CRITICAL | 9.9 | 2026-07-14 | SAP NetWeaver Application Server ABAP allows an authenticated attacker to leverage logical errors in memory management to cause a memory corruption that could lead to unaut… | |
| CVE-2026-57710 | CRITICAL | 9.9 | 2026-07-13 | Unrestricted Upload of File with Dangerous Type vulnerability in quantumcloud WoowBot Pro Max woowbot-pro-max allows Using Malicious Files.This issue affects WoowBot Pro Ma… | |
| CVE-2026-57401 | CRITICAL | 9.9 | 2026-07-13 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Brainstorm Force SureDash suredash allows Path Traversal.This issue affects … | |
| CVE-2026-61445 | CRITICAL | Patched | 9.9 | 2026-07-11 | PraisonAI before 4.6.78 contains arbitrary file write and command execution vulnerabilities in the AICoder component due to missing path validation and command sanitization… |
| CVE-2026-14480 | CRITICAL | 9.9 | 2026-07-10 | OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied … | |
| CVE-2026-55500 | CRITICAL | Patched | 9.9 | 2026-07-10 | 9Router is an AI router & token saver. Prior to 0.4.80, the /api/settings/database endpoint allows full database export (containing all credentials, API keys, OAuth tokens,… |
| CVE-2026-0284 | CRITICAL | Patched | 9.9 | 2026-07-09 | An XML injection vulnerability in the Large Scale VPN (LSVPN) functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access t… |
| CVE-2026-59827 | CRITICAL | Patched | 9.9 | 2026-07-09 | Metabase is an open-source business intelligence and embedded analytics tool. Prior to 1.58.15, 1.59.12, 1.60.6.3, and 1.61.1.4, Metabase instances with an H2 database conn… |
| CVE-2026-56843 | CRITICAL | Patched | 9.9 | 2026-07-08 | Incorrect authorization in the XML-RPC API of WebPros Plesk before 18.0.78.4 allows a low-privileged authenticated customer to look up domains they do not own, because owne… |
| CVE-2026-34037 | CRITICAL | Patched | 9.9 | 2026-07-07 | Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.464, the cloneTo() Livewire action in ResourceOperat… |