Total
397461 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-18891 | 1 Langflow | 1 Langflow | 2026-08-31 | N/A | 8.2 HIGH |
| IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication. | |||||
| CVE-2026-18904 | 1 Langflow | 1 Langflow | 2026-08-31 | N/A | 8.2 HIGH |
| IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers. | |||||
| CVE-2026-19294 | 1 Langflow | 1 Langflow | 2026-08-31 | N/A | 6.4 MEDIUM |
| IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute and read any user's private flow due to improper authorization. | |||||
| CVE-2026-80179 | 2026-08-31 | N/A | 5.9 MEDIUM | ||
| A flaw was found in jwcrypto. A remote attacker can send a specially crafted JSON Web Encryption (JWE) token containing numerous period delimiters. This malformed token can force the JWE.deserialize() function to allocate excessive memory, leading to a MemoryError. This issue results in a denial of service (DoS) for services that process untrusted JWE values. | |||||
| CVE-2026-52473 | 2026-08-31 | N/A | 4.3 MEDIUM | ||
| An issue in Wgcloud 3.6.4 allows a remote attacker to escalate privileges via the content parameter is directly concatenated to the ProcessBuilder. | |||||
| CVE-2026-39275 | 2026-08-31 | N/A | 6.1 MEDIUM | ||
| Cross Site Scripting vulnerability in Cockpit CMS v.2.13.5 and before allows a remote attacker to execute arbitrary code via the item.php, field-select.js and tags.js components | |||||
| CVE-2026-30068 | 2026-08-31 | N/A | 7.5 HIGH | ||
| Improper input validation in the HandleUpdate function (/sbi/parameter_provision.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |||||
| CVE-2026-30059 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in the NAS decoder component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted Registration Request message. | |||||
| CVE-2026-51681 | 2026-08-31 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the setRemoteCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to expose WAN-side administration via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-30045 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An integer overflow in the /nnrf-disc/v1/nf-instances component of open5gs v2.7.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted HTTP/2 GET request. | |||||
| CVE-2026-30069 | 2026-08-31 | N/A | 7.5 HIGH | ||
| A NULL pointer dereference in the UDMC registration handler component of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via supplying crafted payload. | |||||
| CVE-2026-30064 | 2026-08-31 | N/A | 7.5 HIGH | ||
| Improper input validation in the buildFilter function (processor/processor.go) of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |||||
| CVE-2026-51730 | 2026-08-31 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the delWiFiAclRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove Wi-Fi ACL rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-30070 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in the HandleGetSharedData function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |||||
| CVE-2026-51368 | 2026-08-31 | N/A | 9.8 CRITICAL | ||
| An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring HttpInovkerServiceExporter component allows a remote attacker to execute arbitrary code via a crafted request to the console/heimdall endpoint | |||||
| CVE-2026-30058 | 2026-08-31 | N/A | 7.5 HIGH | ||
| Improper Input Validation in the HTTPModifySubscription handler of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |||||
| CVE-2026-30071 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in the RechargePut function of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |||||
| CVE-2026-51720 | 2026-08-31 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the delIpPortFilterRules function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to remove firewall filter rules via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-51679 | 2026-08-31 | N/A | 9.1 CRITICAL | ||
| Incorrect access control in the setPasswordCfg function of TOTOLINK T6 4.1.5cu.748_B20211015 allows unauthenticated attackers to change the administrator account via sending a crafted POST request to /cgi-bin/cstecgi.cgi. | |||||
| CVE-2026-30067 | 2026-08-31 | N/A | 7.5 HIGH | ||
| An issue in the complexQueryFilterSubprocess function in the NRF Discovery service of free5gc v4.0.1 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |||||
