| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-78130 | Hig | 0.42 | 7.5 | 0.00 | Sep 11, 2026 | strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser. | ||
| CVE-2026-78129 | Med | 0.31 | 5.9 | 0.00 | Sep 11, 2026 | strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption. | ||
| CVE-2026-78127 | Low | 0.17 | 3.7 | 0.00 | Sep 11, 2026 | libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser. | ||
| CVE-2026-78126 | Med | 0.31 | 5.9 | 0.00 | Sep 11, 2026 | strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin. | ||
| CVE-2026-78124 | Low | 0.17 | 3.7 | 0.00 | Sep 11, 2026 | strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime. | ||
| CVE-2026-78123 | Med | 0.31 | 5.9 | 0.00 | Sep 11, 2026 | strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin. | ||
| CVE-2026-84941 | Med | 0.45 | — | 0.00 | Sep 11, 2026 | An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful… | ||
| CVE-2026-81906 | Med | 0.34 | — | 0.00 | Sep 11, 2026 | Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that… | ||
| CVE-2026-81905 | Med | 0.34 | — | 0.00 | Sep 11, 2026 | Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alone and does not verify its type. As a… | ||
| CVE-2026-77807 | Hig | 0.42 | 7.5 | 0.01 | Sep 11, 2026 | The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated… | ||
| CVE-2026-18121 | Med | 0.34 | — | 0.00 | Sep 11, 2026 | Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calendar that owns the requested event… | ||
| CVE-2026-17176 | Hig | 0.50 | — | 0.04 | Sep 11, 2026 | An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise, including… | ||
| CVE-2026-16174 | Hig | 0.57 | — | 0.00 | Sep 10, 2026 | Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to… | ||
| CVE-2026-16172 | Med | 0.39 | — | 0.00 | Sep 10, 2026 | Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver… | ||
| CVE-2026-9768 | — | 0.00 | — | — | Sep 10, 2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | ||
| CVE-2026-87958 | Hig | 0.53 | 8.1 | 0.00 | Sep 10, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions. | ||
| CVE-2026-86093 | Hig | 0.49 | 7.5 | 0.00 | Sep 10, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a… | ||
| CVE-2026-86087 | Med | 0.28 | 4.3 | 0.00 | Sep 10, 2026 | IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system. | ||
| CVE-2026-84889 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory. | ||
| CVE-2026-82107 | Cri | 0.62 | 9.6 | 0.00 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication. | ||
| CVE-2026-82100 | Cri | 0.62 | 9.6 | 0.00 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability. | ||
| CVE-2026-82099 | Hig | 0.57 | 8.8 | 0.00 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | ||
| CVE-2026-82098 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command. | ||
| CVE-2026-82097 | Hig | 0.57 | 8.8 | 0.00 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability. | ||
| CVE-2026-82095 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | ||
| CVE-2026-82092 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. | ||
| CVE-2026-81941 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local… | ||
| CVE-2026-81940 | Hig | 0.50 | 8.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names. | ||
| CVE-2026-81554 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability. | ||
| CVE-2026-81551 | Hig | 0.57 | 8.8 | 0.00 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability. | ||
| CVE-2026-81550 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | ||
| CVE-2026-81540 | Hig | 0.55 | 8.5 | 0.00 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability. | ||
| CVE-2026-81268 | Hig | 0.46 | 8.1 | 0.00 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation. | ||
| CVE-2026-81265 | Hig | 0.49 | 7.5 | 0.00 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5. | ||
| CVE-2026-81213 | Hig | 0.56 | 8.6 | 0.00 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs. | ||
| CVE-2026-81211 | Hig | 0.57 | 8.8 | 0.00 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows. | ||
| CVE-2026-81210 | Hig | 0.50 | 7.7 | 0.00 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but… | ||
| CVE-2026-81207 | Hig | 0.55 | 8.5 | 0.00 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller.… | ||
| CVE-2026-81204 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction. | ||
| CVE-2026-80436 | Hig | 0.55 | 8.5 | 0.00 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization. | ||
| CVE-2026-80434 | Hig | 0.48 | 7.4 | 0.00 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference. | ||
| CVE-2026-80424 | Cri | 0.59 | 9.1 | 0.00 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction. | ||
| CVE-2026-80380 | Hig | 0.46 | 7.1 | 0.00 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery. | ||
| CVE-2026-80378 | Hig | 0.55 | 8.5 | 0.00 | Sep 10, 2026 | IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization. | ||
| CVE-2026-79742 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist. | ||
| CVE-2026-79725 | Med | 0.42 | 6.5 | 0.00 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control. | ||
| CVE-2026-79724 | Cri | 0.64 | 9.8 | 0.00 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command. | ||
| CVE-2026-79723 | Med | 0.33 | 5.0 | 0.00 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints. | ||
| CVE-2026-79590 | Med | 0.35 | 6.5 | 0.00 | Sep 10, 2026 | A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting in undefined behavior and… | ||
| CVE-2026-78575 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2026 | IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration. |
- risk 0.42cvss 7.5epss 0.00
strongSwan 4.2.0 through 6.0.7 has a NULL pointer dereference in the x509 plugin's attribute certificate parser.
- risk 0.31cvss 5.9epss 0.00
strongSwan 4.6.2 through 6.0.7 has an infinite loop in PKCS#5 decryption.
- risk 0.17cvss 3.7epss 0.00
libcharon in strongSwan 4.1.2 through 6.0.7 has a missing release of memory after its effective lifetime in the IKE message parser.
- risk 0.31cvss 5.9epss 0.00
strongSwan 4.1.10 through 6.0.7 allows a NULL pointer dereference in the eap-aka plugin.
- risk 0.17cvss 3.7epss 0.00
strongSwan 5.0.2 through 6.0.7 allows PKCS#7 certificate enumeration in the openssl plugin that leads to a lack of release of memory after its effective lifetime.
- risk 0.31cvss 5.9epss 0.00
strongSwan 5.0.2 through 6.0.7 has an Expired Pointer Dereference in PKCS#7 parsing in the openssl plugin.
- risk 0.45cvss —epss 0.00
An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful…
- risk 0.34cvss —epss 0.00
Concrete CMS OAuth callback login path prior to version 9.5.3 did not check whether an account was active or email-validated before establishing a session. A deactivated or unvalidated user with an existing OAuth binding could complete authentication and receive a session that…
- risk 0.34cvss —epss 0.00
Concrete CMS below 9.5.3 stores user validation hashes for multiple purposes (email/registration validation, password reset, and persistent login) in a single table with a type column, but the redemption path resolves a hash by value alone and does not verify its type. As a…
- risk 0.42cvss 7.5epss 0.01
The AcyMailing – An Ultimate Newsletter Plugin and Marketing Automation Solution for WordPress plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 11.0.4 via the `user[name]` Parameter. This makes it possible for unauthenticated…
- risk 0.34cvss —epss 0.00
Concrete CMS 9.5.2 and below is vulnerable to an authorization bypass (IDOR) because the frontend calendar lightbox endpoint (/ccm/calendar/view_event/{bID}/{occurrence_id}) does not verify that the caller is permitted to view the calendar that owns the requested event…
- risk 0.50cvss —epss 0.04
An OS command injection vulnerability in the TDDP module of Deco BE11000 allows an adjacent network attacker to execute arbitrary commands with root privileges by sending a crafted UDP packet. Successful exploitation may lead to complete device compromise, including…
- risk 0.57cvss —epss 0.00
Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to…
- risk 0.39cvss —epss 0.00
Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver…
- CVE-2026-9768Sep 10, 2026risk 0.00cvss —epss —
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
- risk 0.53cvss 8.1epss 0.00
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is vulnerable to a denial of service where a specific functionality on a Db2 server can be disabled by a privileged user under certain conditions.
- risk 0.49cvss 7.5epss 0.00
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improperly copies user-controlled data into a…
- risk 0.28cvss 4.3epss 0.00
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an authenticated user to send a specially crafted request to write arbitrary files on the system.
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.
- risk 0.62cvss 9.6epss 0.00
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information and bypass security restrictions due to improper authentication.
- risk 0.62cvss 9.6epss 0.00
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to a path traversal vulnerability.
- risk 0.57cvss 8.8epss 0.00
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
- risk 0.57cvss 8.8epss 0.01
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS command.
- risk 0.57cvss 8.8epss 0.00
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to a Server-Side Request Forgery (SSRF) vulnerability.
- risk 0.57cvss 8.8epss 0.01
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
- risk 0.57cvss 8.8epss 0.01
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools component configured to use a local…
- risk 0.50cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.
- risk 0.57cvss 8.8epss 0.01
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to obtain sensitive information due to an absolute-path traversal vulnerability.
- risk 0.57cvss 8.8epss 0.00
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to arbitrarily write to or delete files on shared storage due to a path traversal vulnerability.
- risk 0.57cvss 8.8epss 0.01
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command.
- risk 0.55cvss 8.5epss 0.00
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to overwrite ruleset files belonging to other tenants due to a path traversal vulnerability.
- risk 0.46cvss 8.1epss 0.00
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.
- risk 0.49cvss 7.5epss 0.00
IBM Langflow OSS 1.0.0 through 1.11.5.
- risk 0.56cvss 8.6epss 0.00
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to obtain sensitive information from internal network resources due to improper validation of user-supplied URLs.
- risk 0.57cvss 8.8epss 0.00
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.
- risk 0.50cvss 7.7epss 0.00
IBM DataStage on Cloud Pak for Data 5.4.0.0 concatenates three caller-supplied strings into a String.format path on the shared /ds-storage RWX PVC and returns the file with no project ACL — pure IDOR plus traversal. Read is constrained to files named job.log/error.log, but…
- risk 0.55cvss 8.5epss 0.00
IBM DataStage on Cloud Pak for Data 5.4.0.0 allows any authenticated tenant — with no project membership or role — fully controls scheme/host/port/path of an outbound fetch originating from a shared-infrastructure pod, and the WSDL body is reflected verbatim to the caller.…
- risk 0.64cvss 9.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.
- risk 0.55cvss 8.5epss 0.00
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service by deleting arbitrary RabbitMQ queues or exchanges due to improper authorization.
- risk 0.48cvss 7.4epss 0.00
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to manipulate runtime caches and cause a denial of service due to an insecure direct object reference.
- risk 0.59cvss 9.1epss 0.00
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to create arbitrary files due to path traversal during archive extraction.
- risk 0.46cvss 7.1epss 0.00
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote attacker to perform unauthorized actions due to cross-site request forgery.
- risk 0.55cvss 8.5epss 0.00
IBM DataStage on Cloud Pak for Data 5.4.0.0 could allow a remote authenticated attacker to cause a denial of service due to improper authorization.
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.
- risk 0.42cvss 6.5epss 0.00
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to read arbitrary files due to improper access control.
- risk 0.64cvss 9.8epss 0.00
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.
- risk 0.33cvss 5.0epss 0.00
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to obtain sensitive information due to improper validation of user-controlled API endpoints.
- risk 0.35cvss 6.5epss 0.00
A NULL pointer dereference vulnerability exists in the Prism parser component of mruby 4.0.0. An attacker can provide a specially crafted Ruby source file that triggers the parser to pass a NULL pointer to nonnull string handling functions, resulting in undefined behavior and…
- risk 0.57cvss 8.8epss 0.01
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.