CVE Vulnerability Database
Search and browse 392,327 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-7871 | CRITICAL | 9.8 | 0.4% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full application pri... |
| CVE-2026-7803 | CRITICAL | 9.8 | 0.4% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes with... |
| CVE-2026-7663 | CRITICAL | 9.8 | 0.2% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resources and... |
| CVE-2026-3602 | MEDIUM | 5.5 | 0.2% | Jun 30, 2026 | IBM App Connect Enterprise 13.0.1.0 through 13.0.7.2, and 12.0.1.0 through 12.0.12.26 and IBM Integration Bus for z/OS 1... |
| CVE-2026-13773 | CRITICAL | 10 | 3.0% | Jun 30, 2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 Approximately 50 generated CORBA stub classes in WebSphere eXtreme S... |
| CVE-2026-13772 | CRITICAL | 9.9 | 0.3% | Jun 30, 2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 's Object Query Language engine resolves attacker-supplied class nam... |
| CVE-2026-13759 | HIGH | 8.8 | 0.3% | Jun 30, 2026 | IBM WebSphere Extreme Scale 8.6.1.0 through 8.6.1.6 ships three ObjectInputStream subclasses (WsObjectInputStream, Objec... |
| CVE-2026-13449 | CRITICAL | 9.1 | 0.4% | Jun 30, 2026 | IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE... |
| CVE-2026-12086 | MEDIUM | 5.5 | 0.1% | Jun 30, 2026 | IBM UCD - IBM UrbanCode Deploy 7.2 through 7.2.3.23, and 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 throug... |
| CVE-2026-12085 | MEDIUM | 6.5 | 0.2% | Jun 30, 2026 | IBM UCD - IBM UrbanCode Deploy 7.3 through 7.3.2.18 and IBM UCD - IBM DevOps Deploy 8.0 through 8.0.1.13, 8.1 through 8.... |
| CVE-2026-12084 | HIGH | 7.5 | 0.1% | Jun 30, 2026 | IBM UCD - IBM DevOps Deploy 8.1 through 8.1.2.6, and 8.2 through 8.2.1.0 uses Cross-Origin Resource Sharing (CORS) which... |
| CVE-2026-11906 | MEDIUM | 6.5 | 0.4% | Jun 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could... |
| CVE-2026-11806 | HIGH | 7.5 | 0.5% | Jun 30, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 is affected by an arbitrary file read vulnerability... |
| CVE-2026-11714 | CRITICAL | 9.8 | 0.2% | Jun 30, 2026 | IBM WebSphere Application Server Liberty is affected by a server-side request forgery vulnerability with the apiDiscover... |
| CVE-2026-11712 | CRITICAL | 9.3 | 0.2% | Jun 30, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative ... |
| CVE-2026-11708 | CRITICAL | 9.3 | 0.2% | Jun 30, 2026 | IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative ... |
| CVE-2026-11595 | HIGH | 7.5 | 0.3% | Jun 30, 2026 | IBM WebSphere Application Server 9.0, and 8.5 could allow a remote attacker to obtain sensitive information from the adm... |
| CVE-2026-11546 | CRITICAL | 9.8 | 0.2% | Jun 30, 2026 | IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.7 is affected by a server-side request forgery vulner... |
| CVE-2026-10564 | HIGH | 8.2 | 0.2% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). The legacy RSSReaderComponent in rss... |
| CVE-2026-10560 | CRITICAL | 9.1 | 0.3% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ endpoi... |
| CVE-2026-10546 | MEDIUM | 6.5 | 0.1% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL component ( ... |
| CVE-2026-10140 | CRITICAL | 9.6 | 0.2% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API client... |
| CVE-2026-10134 | CRITICAL | 10 | 0.3% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and... |
| CVE-2026-10129 | HIGH | 8.5 | 0.2% | Jun 30, 2026 | IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in th... |
| CVE-2026-10109 | CRITICAL | 9.8 | 0.9% | Jun 30, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth... |
