2026 CVE Vulnerabilities
43,273 CVEs published in 2026.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-9201 | HIGH | 8.8 | 0.2% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptogra... |
| CVE-2026-9196 | HIGH | 8.8 | 0.2% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic As... |
| CVE-2026-9130 | HIGH | 7.1 | 0.2% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows a... |
| CVE-2026-8478 | HIGH | 8.8 | 0.4% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the i... |
| CVE-2026-8183 | HIGH | 7.7 | 0.4% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1... |
| CVE-2026-8182 | HIGH | 8.8 | 0.4% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server... |
| CVE-2026-18485 | HIGH | 8.5 | — | Aug 5, 2026 | There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a l... |
| CVE-2026-17633 | HIGH | 8.8 | 0.4% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code ... |
| CVE-2026-17632 | HIGH | 8.8 | 0.4% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to impro... |
| CVE-2026-17624 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1... |
| CVE-2026-10547 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id... |
| CVE-2026-9081 | HIGH | 7.1 | 0.2% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerabil... |
| CVE-2026-70608 | HIGH | 7.2 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10... |
| CVE-2026-70448 | HIGH | 7.1 | — | Aug 5, 2026 | Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks... |
| CVE-2026-70432 | HIGH | 8.8 | — | Aug 5, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows atta... |
| CVE-2026-70431 | HIGH | 8.8 | — | Aug 5, 2026 | Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Sc... |
| CVE-2026-70429 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistent... |
| CVE-2026-17625 | HIGH | 8.8 | 0.8% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1... |
| CVE-2026-10716 | HIGH | 7.5 | — | Aug 5, 2026 | Directus contains an authenticated SQL injection vulnerability in the collection creation flow when the instance uses Po... |
| CVE-2026-9077 | HIGH | 8.5 | 0.3% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictio... |
| CVE-2026-8446 | HIGH | 7.5 | 0.3% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP)... |
| CVE-2026-20313 | HIGH | 7.7 | 0.2% | Aug 5, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t... |
| CVE-2026-20312 | HIGH | 8.8 | 0.2% | Aug 5, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering t... |
| CVE-2026-20301 | HIGH | 8.6 | 0.3% | Aug 5, 2026 | A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of... |
| CVE-2026-20273 | HIGH | 8.6 | 0.3% | Aug 5, 2026 | As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering t... |
Check if your code is affected by 2026 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now