Total
404108 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-16392 | 1 Mozilla | 2 Firefox, Thunderbird | 2026-08-06 | N/A | 9.1 CRITICAL |
| JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 153 and Thunderbird 153. | |||||
| CVE-2026-62534 | 1 Oracle | 1 Applications Framework | 2026-08-06 | N/A | 8.8 HIGH |
| Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.11-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Applications Framework. Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 8.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). | |||||
| CVE-2026-62546 | 1 Oracle | 1 Applications Framework | 2026-08-06 | N/A | 9.1 CRITICAL |
| Vulnerability in the Oracle Applications Framework product of Oracle E-Business Suite (component: Web Utilities). Supported versions that are affected are 12.2.8-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Applications Framework. While the vulnerability is in Oracle Applications Framework, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Applications Framework. CVSS 3.1 Base Score 9.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H). | |||||
| CVE-2026-17623 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 8.8 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in MCP server configurations. | |||||
| CVE-2026-17626 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 8.8 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due to incomplete filtering of dangerous Docker volume-mount and device-mapping arguments. | |||||
| CVE-2026-10547 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 5.9 MEDIUM |
| IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache pollution, unauthorized workflow execution, or denial of service. | |||||
| CVE-2026-17632 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 8.8 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning. | |||||
| CVE-2026-17624 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 8.5 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of module imports. | |||||
| CVE-2026-17633 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 8.5 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection. | |||||
| CVE-2026-7646 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 6.5 MEDIUM |
| IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, the SQLite database, and process environment variables, by sending a crafted MCP `resources/read` request with a URL-encoded path traversal sequence in the filename. | |||||
| CVE-2026-8446 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 7.5 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are configured with auth_type=oauth . | |||||
| CVE-2026-17625 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 7.2 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | |||||
| CVE-2026-9077 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 8.5 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files on the host system. | |||||
| CVE-2026-7658 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 6.5 MEDIUM |
| IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to session invalidation. | |||||
| CVE-2026-10128 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 6.5 MEDIUM |
| IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite security controls intended to disable custom components. | |||||
| CVE-2026-7869 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 5.4 MEDIUM |
| IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this flaw to create directories and write files anywhere on the server's filesystem. | |||||
| CVE-2026-8182 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 8.8 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests. | |||||
| CVE-2026-8183 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 7.7 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to v i ew arbitrary files on the system. | |||||
| CVE-2026-8470 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 7.4 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds, allowing attackers to reproduce encryption keys and decrypt stored API keys and authentication tokens. | |||||
| CVE-2026-8478 | 1 Langflow | 1 Langflow | 2026-08-06 | N/A | 8.8 HIGH |
| IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code. | |||||
