CVE Vulnerability Database
Search and browse 377,706 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-17624 | HIGH | 8.8 | 0.3% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1... |
| CVE-2026-10547 | HIGH | 8.1 | 0.2% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id... |
| CVE-2026-9081 | HIGH | 7.1 | 0.2% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerabil... |
| CVE-2026-7657 | MEDIUM | 6.5 | 0.2% | Aug 5, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and inef... |
| CVE-2026-70611 | MEDIUM | 6.9 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,... |
| CVE-2026-70610 | MEDIUM | 5.4 | 0.4% | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9,... |
| CVE-2026-70609 | MEDIUM | 5.7 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7,... |
| CVE-2026-70608 | HIGH | 7.2 | — | Aug 5, 2026 | Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10... |
| CVE-2026-70448 | HIGH | 7.1 | — | Aug 5, 2026 | Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks... |
| CVE-2026-70447 | MEDIUM | 4.3 | — | Aug 5, 2026 | Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission ... |
| CVE-2026-70446 | MEDIUM | 4.3 | — | Aug 5, 2026 | Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to ... |
| CVE-2026-70445 | MEDIUM | 4.3 | 0.1% | Aug 5, 2026 | Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permissio... |
| CVE-2026-70444 | MEDIUM | 4.3 | — | Aug 5, 2026 | A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overa... |
| CVE-2026-70443 | MEDIUM | 4.3 | — | Aug 5, 2026 | Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials looku... |
| CVE-2026-70442 | MEDIUM | 4.3 | — | Aug 5, 2026 | Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credenti... |
| CVE-2026-70441 | MEDIUM | 5.4 | — | Aug 5, 2026 | Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pag... |
| CVE-2026-70440 | MEDIUM | 5.4 | — | Aug 5, 2026 | Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a... |
| CVE-2026-70439 | MEDIUM | 6.5 | — | Aug 5, 2026 | Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appr... |
| CVE-2026-70438 | MEDIUM | 4.3 | 0.1% | Aug 5, 2026 | A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overal... |
| CVE-2026-70437 | LOW | 3.7 | 0.1% | Aug 5, 2026 | Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison... |
| CVE-2026-70436 | MEDIUM | 4.3 | 0.1% | Aug 5, 2026 | Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or p... |
| CVE-2026-70435 | MEDIUM | 4.2 | 0.1% | Aug 5, 2026 | A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permissio... |
| CVE-2026-70434 | MEDIUM | 4.2 | 0.1% | Aug 5, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to c... |
| CVE-2026-70433 | MEDIUM | 4.3 | 0.1% | Aug 5, 2026 | Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission t... |
| CVE-2026-70432 | HIGH | 8.8 | — | Aug 5, 2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows atta... |
