CVE Search

Cari CVE dari dbcve.org — keyword, vendor, severity, KEV, dan rentang waktu.

Advanced Filter
Reset
Active filters: Severity: High
10,000 result(s) · page 470 of 500
CVE-2026-9130
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via...

CVSS 7.1 Langflow langflow 2026-08-05
CVE-2026-8478
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.

CVSS 8.8 Langflow langflow 2026-08-05
CVE-2026-8183
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacke...

CVSS 7.7 Langflow langflow 2026-08-05
CVE-2026-8182
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.

CVSS 8.8 Langflow langflow 2026-08-05
CVE-2026-18485
HIGH

There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to escalate privileges and execute ...

CVSS 7.8 2026-08-05
CVE-2026-17633
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.

CVSS 8.8 Langflow langflow 2026-08-05
CVE-2026-17632
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scan...

CVSS 8.8 Langflow langflow 2026-08-05
CVE-2026-17624
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could ...

CVSS 8.8 Langflow langflow 2026-08-05
CVE-2026-10547
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to injec...

CVSS 8.1 Langflow langflow 2026-08-05
CVE-2026-9081
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ol...

CVSS 7.1 Langflow langflow 2026-08-05
CVE-2026-70608
HIGH

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-...

CVSS 7.2 2026-08-05
CVE-2026-70448
HIGH

Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.

CVSS 7.1 2026-08-05
CVE-2026-70432
HIGH

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkin...

CVSS 8.8 2026-08-05
CVE-2026-70431
HIGH

Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or...

CVSS 8.8 2026-08-05
CVE-2026-17625
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could ...

CVSS 8.8 Langflow langflow 2026-08-05
CVE-2026-10716
HIGH

Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses PostgreSQL with PostGIS enabled. An administrator can create a...

CVSS 7.5 2026-08-05
CVE-2026-9077
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE conf...

CVSS 8.5 Langflow langflow 2026-08-05
CVE-2026-8446
HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) ...

CVSS 7.5 Langflow langflow 2026-08-05
CVE-2026-20313
HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. ...

CVSS 7.7 2026-08-05
CVE-2026-20312
HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. ...

CVSS 8.8 2026-08-05
1 468 469 470 471 472 500
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.