CVE Vulnerability Database

Search and browse 390,334 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-10564HIGH8.2IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss...
CVE-2026-10560CRITICAL9.1IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoi...
CVE-2026-10546MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( ...
CVE-2026-10140CRITICAL9.6IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API client...
CVE-2026-10134CRITICAL10IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and...
CVE-2026-10129HIGH8.5IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in th...
CVE-2026-10109CRITICAL9.8IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth...
CVE-2025-36372MEDIUM6.5IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could...
CVE-2026-58138CRITICAL9.8Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote...
CVE-2026-10513HIGH7.2The Webmention plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 5.8.0 v...
CVE-2026-9263HIGH8.1The Zephyr Bluetooth controller ISO Adaptation Layer (subsys/bluetooth/controller/ll_sw/isoal.c) fails to validate the l...
CVE-2026-8864HIGH7.3The HP Fan Control App might allow local escalation of privileges. An updated version of HP Fan Control App has been rel...
CVE-2026-58377HIGH8.6JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to ...
CVE-2026-58376HIGH7.6Dolibarr through 23.0.3, fixed in commit 14db36e, contains a sql injection vulnerability that allows authenticated API u...
CVE-2026-58375HIGH8.7JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotate...
CVE-2026-58373MEDIUM5.3CVAT before 2.69.0 contains an improper authorization vulnerability in QualityReportViewSet.get_queryset that allows aut...
CVE-2026-58372HIGH8.1SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows...
CVE-2026-58371LOW3.1SeaweedFS before 4.30 reflects the callback query parameter verbatim into responses served with Content-Type application...
CVE-2026-58370CRITICAL9.2Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driv...
CVE-2026-58369MEDIUM6.9Woodpecker before 3.15.0 registers the /api/orgs/lookup/*org_full_name endpoint without authentication middleware, and t...
CVE-2026-58176HIGH7.1RuoYi-Vue-Plus through 5.6.2, fixed in commit 88d03d9, exposes workflow task management endpoints under /workflow/task (...
CVE-2026-58174MEDIUM6.5Hermes WebUI before 0.51.521 validates the workspace of an imported session under the active named profile but construct...
CVE-2026-58173MEDIUM6.5Vibe-Trading before 0.1.10 contains a path traversal vulnerability that allows attackers to write files outside the inte...
CVE-2026-58172CRITICAL9.3Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clie...
CVE-2026-58171MEDIUM4.2Vibe-Trading before 0.1.10 constructs the swarm run directory by joining a caller-supplied run identifier onto the runs ...