Search

Published: All 7d 30d 90d 12m
Severity: All Critical High Medium Low

478 CVEs · Critical severity

CVEs (478)

Showing 1–25 of 478

CVE ID Severity Patch CVSS Published Description
CVE-2026-9810 CRITICAL Patched 9.8 2026-07-17 The AI Copilot WordPress plugin before 1.5.4 does not bind OAuth access tokens to a WordPress user, and accepts any valid token as an administrator session, allowing unaut…
CVE-2026-9202 CRITICAL 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Langflow instance; when NEW_USER_IS_ACTIVE=true (documented …
CVE-2026-9198 CRITICAL 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code…
CVE-2026-9135 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies…
CVE-2026-9103 CRITICAL Patched 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The…
CVE-2026-8859 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locations due to improper input validation in the APIRequest c…
CVE-2026-8635 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly manipulating the database, execute arbitrary system command…
CVE-2026-8505 CRITICAL Patched 9.8 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The …
CVE-2026-8481 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint ac…
CVE-2026-8476 CRITICAL Patched 9.9 2026-07-17 IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's uns…
CVE-2026-8297 CRITICAL 9.8 2026-07-17 Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Gis Informatics Engineering Consulting Laboratory R&D and Software Ser…
CVE-2026-65907 CRITICAL Patched 9.1 2026-07-23 In JetBrains TeamCity before 2026.1.2, 2025.11.6 code execution in Git VCS roots was possible
CVE-2026-65701 CRITICAL 9.1 2026-07-23 SoftVC VITS Singing Voice Conversion through commit 730930d contains a path traversal vulnerability in the full-song inference server that allows unauthenticated remote att…
CVE-2026-65700 CRITICAL 9.8 2026-07-23 h2oGPT through 0.2.1 contains a path traversal vulnerability in the OpenAI-compatible files API that allows unauthenticated remote attackers to read, write, and delete arbi…
CVE-2026-65689 CRITICAL Patched 9.8 2026-07-23 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its database download feature that allows unauthenticated att…
CVE-2026-65688 CRITICAL Patched 9.8 2026-07-23 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its font processing feature that allows unauthenticated attac…
CVE-2026-65687 CRITICAL Patched 9.8 2026-07-23 Bold Reports Standalone Report Designer before 14.1.12 contains a missing filepath validation vulnerability in its SVG processing feature that allows unauthenticated attack…
CVE-2026-65606 CRITICAL 9.6 2026-07-23 SiYuan before v3.7.2 contains a cross-site scripting vulnerability in the siyuan:// protocol handler. When a siyuan://plugins/<name> link references a name that is not an i&hellip;
CVE-2026-65605 CRITICAL 9.6 2026-07-23 SiYuan before v3.7.2 contains a stored cross-site scripting vulnerability in Attribute View (database) cell rendering. A Template column value is rendered as HTML via text/&hellip;
CVE-2026-65471 CRITICAL 9.6 2026-07-23 Unauthenticated Cross Site Request Forgery (CSRF) in Avada Core <= 5.15.6 versions.
CVE-2026-65461 CRITICAL 9.1 2026-07-23 Administrator Arbitrary File Upload in Really Simple CSV Importer <= 1.3 versions.
CVE-2026-65455 CRITICAL 9.1 2026-07-23 Administrator Arbitrary File Upload in MapSVG <= 8.14.0 versions.
CVE-2026-6516 CRITICAL Patched 10.0 2026-07-23 Zohocorp ManageEngine ADAudit Plus versions before 8606 are affected by Unauthenticated Remote code execution due to the vulnerable agent API.
CVE-2026-65057 CRITICAL 9.3 2026-07-21 Keep (commit 91c75e0) contains a server-side request forgery vulnerability that allows unauthenticated attackers to make the backend issue arbitrary HTTP requests by supply&hellip;
CVE-2026-65049 CRITICAL 9.3 2026-07-21 Ninja Forms plugin version 3.14.8 and prior for WordPress Multisite contains an incorrect authorization vulnerability that allows a subsite Administrator to trigger network&hellip;