CVE Vulnerability Database
Search and browse 377,706 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-66297 | HIGH | 8 | 1.3% | Aug 5, 2026 | Improper Neutralization of Special Elements used in an OS Command (OS Command Injection) vulnerability in livebook-dev l... |
| CVE-2026-55524 | HIGH | 7.5 | 0.2% | Aug 5, 2026 | PraisonAI is a multi-agent teams system. In versions prior to 1.6.58, the web_crawl tool performs its SSRF check only on... |
| CVE-2026-55523 | HIGH | 7.7 | 0.3% | Aug 5, 2026 | PraisonAI is a multi-agent teams system. In versions 1.5.128 through 1.6.57, the praisonaiagents.tools.web_crawl_tools.w... |
| CVE-2026-55522 | HIGH | 7.8 | 0.2% | Aug 5, 2026 | PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of p... |
| CVE-2026-21766 | MEDIUM | 5.4 | — | Aug 5, 2026 | The default login portlet in HCL Digital Experience and Digital Experience Compose insufficiently protects credentials. ... |
| CVE-2026-18958 | HIGH | 7.3 | 0.3% | Aug 5, 2026 | A vulnerability was detected in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a... |
| CVE-2026-18954 | MEDIUM | 5.7 | 0.1% | Aug 5, 2026 | Incorrect authorization in the aggregation pipeline tool in Amazon AWS Labs DocumentDB MCP Server before 1.0.12 might al... |
| CVE-2026-18953 | HIGH | 8.8 | 0.1% | Aug 5, 2026 | Improper limitation of a pathname to a restricted directory in the get_resource tool in Amazon awslabs.aws-transform-mcp... |
| CVE-2026-17556 | HIGH | 8.8 | — | Aug 5, 2026 | A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to de... |
| CVE-2026-9205 | CRITICAL | 9.8 | 0.2% | Aug 5, 2026 | IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. |
| CVE-2026-9201 | HIGH | 8.8 | 0.2% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptogra... |
| CVE-2026-9196 | HIGH | 8.8 | 0.2% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic As... |
| CVE-2026-9130 | HIGH | 7.1 | 0.2% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows a... |
| CVE-2026-8478 | HIGH | 8.8 | 0.4% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the i... |
| CVE-2026-8470 | CRITICAL | 9.1 | 0.1% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's... |
| CVE-2026-8183 | HIGH | 7.7 | 0.4% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1... |
| CVE-2026-8182 | HIGH | 8.8 | 0.4% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server... |
| CVE-2026-7869 | MEDIUM | 5.4 | 0.2% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledg... |
| CVE-2026-7658 | MEDIUM | 6.5 | 0.3% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path t... |
| CVE-2026-70612 | MEDIUM | 5.4 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8,... |
| CVE-2026-63457 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78. |
| CVE-2026-48168 | CRITICAL | 10 | — | Aug 5, 2026 | PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vuln... |
| CVE-2026-18485 | HIGH | 8.5 | — | Aug 5, 2026 | There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver. This may allow a l... |
| CVE-2026-17633 | HIGH | 8.8 | 0.4% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code ... |
| CVE-2026-17632 | HIGH | 8.8 | 0.4% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to impro... |
