Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Unclassified HIGH 7.5
CVE-2026-69111

Milvus through 2.6.22 and 3.0.0 contains an unauthenticated denial of service vulnerability that allows remote attackers to terminate service compone…

Patch available
Fix from $1,950 2026-08-05
Livebook HIGH 8.8
CVE-2026-68746

Not Failing Securely ('Failing Open') vulnerability in livebook-dev livebook allows an unauthenticated network client to obtain full access to a Live…

Fix: 0.19.9+
Fix from $1,950 2026-08-05
Livebook MEDIUM 6.5
CVE-2026-66885

Cross-Site Request Forgery (CSRF) vulnerability in livebook-dev livebook allows an attacker to authenticate a victim's browser session under the atta…

Fix: 0.18.7 / 0.19.9+
Fix from $1,600 2026-08-05
Livebook HIGH 8.1
CVE-2026-66881

Relative Path Traversal vulnerability in livebook-dev livebook allows an attacker-authored notebook to write a file with attacker-controlled content …

Fix: 0.18.7 / 0.19.9+
Fix from $1,950 2026-08-05
Livebook HIGH 8.8
CVE-2026-66298

Origin Validation Error vulnerability in livebook-dev livebook allows untrusted notebook output JavaScript to trigger session-wide keyboard shortcuts…

Fix: 0.18.7 / 0.19.9+
Fix from $1,950 2026-08-05
Livebook HIGH 8.0
CVE-2026-66297

Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev livebook allows command inject…

Fix: 0.18.7 / 0.19.9+
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-55524

PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on the initially supplied URL, …

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.7
CVE-2026-55523

PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.web_crawl() function is vulner…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 7.8
CVE-2026-55522

PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 5.4
CVE-2026-21766

The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials.  Under certain very specific …

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 7.3
CVE-2026-18958

A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bc…

No fix yet
Fix from $1,950 2026-08-05
Documentdb Mcp Server MEDIUM 5.5
CVE-2026-18954

Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might allow an authenticated MCP clie…

Fix: 1.0.12+
Fix from $1,600 2026-08-05
Aws Transform Mcp Server HIGH 8.8
CVE-2026-18953

Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp-server 0.1.0 through 0.1.4 m…

Fix: 0.1.5+
Fix from $1,950 2026-08-05
Enterprise Server CRITICAL 9.1
CVE-2026-17556

A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and dire…

Fix: 3.17.19 / 3.18.13+
Fix from $2,300 2026-08-05
Langflow CRITICAL 9.8
CVE-2026-9205

IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.

Fix: 1.11.0+
Fix from $2,300 2026-08-05
Langflow HIGH 8.8
CVE-2026-9201

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom c…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-9196

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to imp…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 7.1
CVE-2026-9130

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access …

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-8478

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow CRITICAL 9.1
CVE-2026-8470

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random mod…

Fix: 1.11.0+
Fix from $2,300 2026-08-05
Langflow HIGH 7.7
CVE-2026-8183

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-8182

IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via …

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow MEDIUM 5.4
CVE-2026-7869

IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs becaus…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Langflow MEDIUM 6.5
CVE-2026-7658

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.4
CVE-2026-70612

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b…

Patch available
Fix from $1,600 2026-08-05
Integrated Lights Out 6 Firmware MEDIUM 6.5
CVE-2026-63457

A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.

Fix: 1.78+
Fix from $1,600 2026-08-05
Unclassified CRITICAL 10.0
CVE-2026-48168

PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection b…

Patch available
Fix from $2,300 2026-08-05
Unclassified HIGH 7.8
CVE-2026-18485

There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to e…

No fix yet
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-17633

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.8
CVE-2026-17632

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code…

Fix: 1.11.0+
Fix from $1,950 2026-08-05