Vulnerability index

Browse CVEs

10,000+ matching
Filters
Severity

Filters apply as you choose them.

Langflow HIGH 8.8
CVE-2026-17624

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, …

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 8.1
CVE-2026-10547

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 7.1
CVE-2026-9081

IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_pro…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow MEDIUM 6.5
CVE-2026-7657

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enfor…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.9
CVE-2026-70611

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-b…

Patch available
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.4
CVE-2026-70610

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-b…

Patch available
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.7
CVE-2026-70609

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-b…

Patch available
Fix from $1,600 2026-08-05
Unclassified HIGH 7.2
CVE-2026-70608

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sand…

Patch available
Fix from $1,950 2026-08-05
Unclassified HIGH 7.1
CVE-2026-70448

Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report f…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 5.4
CVE-2026-70441

Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cro…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.4
CVE-2026-70440

Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resultin…

No fix yet
Fix from $1,600 2026-08-05
Unclassified MEDIUM 6.5
CVE-2026-70439

Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke…

No fix yet
Fix from $1,600 2026-08-05
Unclassified HIGH 8.1
CVE-2026-70429

Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able t…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-70432

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary co…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-70431

Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowin…

No fix yet
Fix from $1,950 2026-08-05
Unclassified CRITICAL 9.0
CVE-2026-70426

In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-2…

No fix yet
Fix from $2,300 2026-08-05
Unclassified MEDIUM 5.5
CVE-2026-44605

A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially…

No fix yet
Fix from $1,600 2026-08-05
Langflow HIGH 8.8
CVE-2026-17625

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, …

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Unclassified HIGH 7.5
CVE-2026-10716

Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled…

No fix yet
Fix from $1,950 2026-08-05
Langflow MEDIUM 6.5
CVE-2026-10128

IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment varia…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Langflow HIGH 8.5
CVE-2026-9077

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP se…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow HIGH 7.5
CVE-2026-8446

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_c…

Fix: 1.11.0+
Fix from $1,950 2026-08-05
Langflow MEDIUM 6.5
CVE-2026-7646

IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the…

Fix: 1.11.0+
Fix from $1,600 2026-08-05
Unclassified MEDIUM 5.3
CVE-2026-70607

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-b…

Patch available
Fix from $1,600 2026-08-05
Unclassified HIGH 7.7
CVE-2026-20313

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…

No fix yet
Fix from $1,950 2026-08-05
Unclassified HIGH 8.8
CVE-2026-20312

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…

No fix yet
Fix from $1,950 2026-08-05
Unclassified MEDIUM 6.3
CVE-2026-20311

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to c…

No fix yet
Fix from $1,600 2026-08-05
Unclassified CRITICAL 9.1
CVE-2026-20310

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-20304

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…

No fix yet
Fix from $2,300 2026-08-05
Unclassified CRITICAL 9.9
CVE-2026-20303

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehen…

No fix yet
Fix from $2,300 2026-08-05