CVE Vulnerability Database

Search and browse 394,439 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-44790HIGH8.8n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe...
CVE-2026-44789CRITICAL9.9n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with pe...
CVE-2026-42867MEDIUM6.5Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to...
CVE-2026-34917MEDIUM4.3Low‑privileged session IDs generated for the web admin console could be reused in the XML‑RPC API, whose authentication ...
CVE-2026-34916HIGH8.8A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a l...
CVE-2026-34915MEDIUM6.1A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a l...
CVE-2026-34914HIGH8.3A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileg...
CVE-2026-34913MEDIUM4.3A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Ads...
CVE-2026-34912MEDIUM4.3A missing access control check when linking banners or campaigns to a zone through the zone-include.php script of Revive...
CVE-2026-33760HIGH8.8Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monito...
CVE-2026-13007HIGH7.5Tenable Identity Exposure contains multiple unauthenticated API endpoints under /w/api/* that expose sensitive applicati...
CVE-2026-12958HIGH8.5Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust ...
CVE-2026-12957HIGH8.5Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may all...
CVE-2026-11940HIGH7.8tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink reference...
CVE-2025-61028HIGH7.5An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Ser...
CVE-2025-61027HIGH7.5An issue in the t_set_push component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi...
CVE-2025-61025HIGH7.5An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Ser...
CVE-2025-61023HIGH7.5An issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Servi...
CVE-2025-61022HIGH7.5An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial o...
CVE-2025-61021HIGH7.5An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Den...
CVE-2025-61020HIGH7.5An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial ...
CVE-2025-61019HIGH7.5An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial ...
CVE-2025-61018HIGH7.5An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial o...
CVE-2025-13162MEDIUM4.4Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affect...
CVE-2026-56696MEDIUM5.4OpenHarness /issue and /pr_comments slash commands lack remote_invocable=False protection, allowing remote channel sende...