Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-18959 |
|
Path Traversal in path-traversal (CVE-2026-18959)
path traversal in path-traversal (CVE-2026-18959). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18958 |
|
Vulnerability in sqli (CVE-2026-18958)
vulnerability in sqli (CVE-2026-18958). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-9205 |
|
Vulnerability in langflow (CVE-2026-9205)
vulnerability in langflow (CVE-2026-9205). Confidential information can be exposed externally.
|
| CVE-2026-9201 |
|
Vulnerability in langflow (CVE-2026-9201)
vulnerability in langflow (CVE-2026-9201). Successful exploitation can lead to full system takeover.
|
| CVE-2026-9196 |
|
Code Injection in langflow (CVE-2026-9196)
code injection in langflow (CVE-2026-9196). Confidential information can be exposed externally.
|
| CVE-2026-9130 |
|
Vulnerability in langflow (CVE-2026-9130)
vulnerability in langflow (CVE-2026-9130). Confidential information can be exposed externally.
|
| CVE-2026-8478 |
|
Code Injection in langflow (CVE-2026-8478)
code injection in langflow (CVE-2026-8478). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8470 |
|
Vulnerability in langflow (CVE-2026-8470)
vulnerability in langflow (CVE-2026-8470). Data can be tampered with by attackers.
|
| CVE-2026-8182 |
|
Code Injection in langflow (CVE-2026-8182)
code injection in langflow (CVE-2026-8182). Successful exploitation can lead to full system takeover.
|
| CVE-2026-8183 |
|
Path Traversal in langflow (CVE-2026-8183)
path traversal in langflow (CVE-2026-8183). Confidential information can be exposed externally.
|
| CVE-2026-7869 |
|
Path Traversal in path-traversal (CVE-2026-7869)
path traversal in path-traversal (CVE-2026-7869). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/knowledge_bases`.
|
| CVE-2026-7658 |
|
Path Traversal in path-traversal (CVE-2026-7658)
path traversal in path-traversal (CVE-2026-7658). Data can be tampered with by attackers.
|
| CVE-2026-17633 |
|
Code Injection in langflow (CVE-2026-17633)
code injection in langflow (CVE-2026-17633). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17632 |
|
Code Injection in langflow (CVE-2026-17632)
code injection in langflow (CVE-2026-17632). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17624 |
|
Code Injection in langflow (CVE-2026-17624)
code injection in langflow (CVE-2026-17624). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10547 |
|
Vulnerability in dos (CVE-2026-10547)
vulnerability in dos (CVE-2026-10547). Data can be tampered with by attackers. Exploitable via `POST /api/v1/build/{flow_id}/vertices`.
|
| CVE-2026-9081 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-9081)
SSRF in ssrf (CVE-2026-9081). Confidential information can be exposed externally.
|
| CVE-2026-7657 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-7657)
SSRF in ssrf (CVE-2026-7657). Confidential information can be exposed externally.
|
| CVE-2026-17625 |
|
OS Command Injection in langflow (CVE-2026-17625)
OS command injection in langflow (CVE-2026-17625). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10128 |
|
Information Disclosure in c (CVE-2026-10128)
vulnerability in c (CVE-2026-10128). Confidential information can be exposed externally.
|
| CVE-2026-7646 |
|
Path Traversal in path-traversal (CVE-2026-7646)
path traversal in path-traversal (CVE-2026-7646). Confidential information can be exposed externally.
|
| CVE-2026-9077 |
|
Vulnerability in langflow (CVE-2026-9077)
vulnerability in langflow (CVE-2026-9077). Data can be tampered with by attackers.
|
| CVE-2026-17623 |
|
OS Command Injection in langflow (CVE-2026-17623)
OS command injection in langflow (CVE-2026-17623). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17630 |
|
Vulnerability in langflow (CVE-2026-17630)
vulnerability in langflow (CVE-2026-17630). Successful exploitation can lead to full system takeover.
|
| CVE-2026-17626 |
|
Vulnerability in langflow (CVE-2026-17626)
vulnerability in langflow (CVE-2026-17626). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18927 |
|
Vulnerability in CVE-2026-18927 (CVE-2026-18927)
vulnerability in CVE-2026-18927 (CVE-2026-18927). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-8446 |
|
Vulnerability in langflow (CVE-2026-8446)
vulnerability in langflow (CVE-2026-8446). Confidential information can be exposed externally.
|
| CVE-2026-60053 |
|
Vulnerability in apache (CVE-2026-60053)
vulnerability in apache (CVE-2026-60053). Confidential information can be exposed externally.
|
| CVE-2026-60023 |
|
Information Disclosure in apache (CVE-2026-60023)
vulnerability in apache (CVE-2026-60023). Confidential information can be exposed externally.
|
| CVE-2026-50749 |
|
Authorization Flaw in apache (CVE-2026-50749)
vulnerability in apache (CVE-2026-50749). Data can be tampered with by attackers.
|
| CVE-2026-48912 |
|
Vulnerability in apache (CVE-2026-48912)
vulnerability in apache (CVE-2026-48912). Data can be tampered with by attackers.
|
| CVE-2026-48911 |
|
Vulnerability in apache (CVE-2026-48911)
vulnerability in apache (CVE-2026-48911). Data can be tampered with by attackers.
|
| CVE-2026-53992 |
|
Cross-Site Scripting (XSS) in CVE-2026-53992 (CVE-2026-53992)
cross-site scripting in CVE-2026-53992 (CVE-2026-53992). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-48834 |
|
Vulnerability in apache (CVE-2026-48834)
vulnerability in apache (CVE-2026-48834). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67623 |
|
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
Mistral Vibe before 2.23.3 contains a remote code execution vulnerability that allows attackers...
|
| CVE-2026-15979 |
|
Path Traversal in wordpress (CVE-2026-15979)
path traversal in wordpress (CVE-2026-15979). Data can be tampered with by attackers.
|
| CVE-2026-71294 |
|
Unsafe Deserialization in CVE-2026-71294 (CVE-2026-71294)
vulnerability in CVE-2026-71294 (CVE-2026-71294). Confidential information can be exposed externally. Exploitable via ``allowed_classes``.
|
| CVE-2026-71293 |
|
Information Disclosure in CVE-2026-71293 (CVE-2026-71293)
vulnerability in CVE-2026-71293 (CVE-2026-71293). Confidential information can be exposed externally. Exploitable via ``two_factor_recovery_codes``.
|
| CVE-2026-71292 |
|
SQL Injection in CVE-2026-71292 (CVE-2026-71292)
SQL injection in CVE-2026-71292 (CVE-2026-71292). Successful exploitation can lead to full system takeover. Exploitable via ``dir``.
|
| CVE-2026-71291 |
|
Bolt CMS renders content field values through Twig's full application-level Environment with no...
Bolt CMS renders content field values through Twig's full application-level Environment with no...
|
| CVE-2026-71287 |
|
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
Cacti's sanitize_sql_column() (lib/functions.php) sanitizes user-supplied ORDER BY column names...
|
| CVE-2026-71251 |
|
Vulnerability in CVE-2026-71251 (CVE-2026-71251)
vulnerability in CVE-2026-71251 (CVE-2026-71251). Confidential information can be exposed externally.
|
| CVE-2026-71252 |
|
Vulnerability in CVE-2026-71252 (CVE-2026-71252)
vulnerability in CVE-2026-71252 (CVE-2026-71252). Data can be tampered with by attackers.
|
| CVE-2026-18933 |
|
Unrestricted File Upload in wordpress (CVE-2026-18933)
vulnerability in wordpress (CVE-2026-18933). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71249 |
|
Cross-Site Scripting (XSS) in CVE-2026-71249 (CVE-2026-71249)
cross-site scripting in CVE-2026-71249 (CVE-2026-71249). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71248 |
|
SQL Injection in sqli (CVE-2026-71248)
SQL injection in sqli (CVE-2026-71248). Successful exploitation can lead to full system takeover.
|
| CVE-2026-71250 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-71250)
SSRF in ssrf (CVE-2026-71250). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71245 |
|
SQL Injection in CVE-2026-71245 (CVE-2026-71245)
SQL injection in CVE-2026-71245 (CVE-2026-71245). Confidential information can be exposed externally.
|
| CVE-2026-71233 |
|
Cross-Site Scripting (XSS) in laravel (CVE-2026-71233)
cross-site scripting in laravel (CVE-2026-71233). Confidential information can be exposed externally. Exploitable via `PUT /api/v1/invoices/{id}`.
|
| CVE-2026-71236 |
|
Cross-Site Scripting (XSS) in CVE-2026-71236 (CVE-2026-71236)
cross-site scripting in CVE-2026-71236 (CVE-2026-71236). Confidential information can be exposed externally.
|