CVE Vulnerability Database

Search and browse 381,206 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-48499CRITICAL9.3Activepieces is an open source AI workflow automation platform. Prior to 0.84.0, an unsanitized path segment in the Code...
CVE-2026-18245HIGH8.8Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authentic...
CVE-2026-18140HIGH8.7Uncontrolled recursion in the unknown-key skip path of the aws-smithy-json runtime crate before 0.62.7, which the smithy...
CVE-2026-15978HIGH7.5SGLang contains a model weight exfiltration vulnerability when no API keys are configured, as SGLang will expose two end...
CVE-2026-15977HIGH7.5SGLang contains a credential leakage vulnerability in the /server_info endpoint, which will return API keys and SSL keyf...
CVE-2026-15976CRITICAL9.8SGLang contains a RCE vulnerability when attempting to load model weights from a HuggingFace repository, specifically wi...
CVE-2026-15974MEDIUM6.5SGLang contains an SSRF and local file read in the multimodal generation endpoint /v1/chat/completions due to unsanitize...
CVE-2026-15971CRITICAL9.8SGLang contains an RCE vulnerability when the optional dumper subsystem is enabled, allowing for a sandbox escape when D...
CVE-2026-15969CRITICAL9.8SGLang contains an unauthenticated RCE in /load_lora_adapter_from_tensors via bypass of SafeUnpickler’s incomplete denyl...
CVE-2026-14227MEDIUM6.9An API session‑management flaw in products with the MikroTik RouterOS API enabled are vulnerable to a Insufficient Sessi...
CVE-2026-13444HIGH8.1IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creatin...
CVE-2026-13435CRITICAL9.9IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox impl...
CVE-2026-12943CRITICAL9.8IBM HMC V10.3.1050.0 through 10.3.1064.0 and IBM HMC V11.1.1110.0 through 11.1.1112.0 Management systems in IBM Power en...
CVE-2026-12942HIGH7.5IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker c...
CVE-2026-12733HIGH7.5IBM DataPower Gateway could allow a remote attacker to cause a denial of service due to improper resource limitations.
CVE-2026-12118CRITICAL9.8IBM webMethods Integration (on prem) 10.15, 10.11 could allow an unauthenticated remote attacker to execute arbitrary co...
CVE-2026-11904MEDIUM5.3IBM Verify Identity Access 11.0 through 11.0.2 and IBM Security Verify Access 10.0 through 10.0.9.1 and IBM Verify Ident...
CVE-2026-10700MEDIUM6.5IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API th...
CVE-2026-10695MEDIUM5.5IBM Db2 12.1.0 through 12.1.4 federated server is vulnerable to a denial of service when running non fenced federated qu...
CVE-2026-10545HIGH7.5IBM Planning Analytics Local 2.1.0 through 2.1.21 is vulnerable to an open redirect that allows an attacker to redirect ...
CVE-2026-10535HIGH7.8IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to buffer overflow in setgid helper db2flacc.
CVE-2025-36374MEDIUM5.5IBM DataPower Gateway is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A privile...
CVE-2025-0152MEDIUM6.1IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1...
CVE-2024-40683MEDIUM6.3IBM Operations Analytics - Log Analysis 1.3.5.0, 1.3.5.1, 1.3.5.2, 1.3.5.3, 1.3.6.0, 1.3.6.1, 1.3.7.0, 1.3.7.1, 1.3.7.2,...
CVE-2024-25039HIGH7.5IBM Engineering Requirements Management DOORS and DOORS Web Access 9.7.2.1 through 9.7.2.11, and 9.6.1.1 through 9.6.1.1...