VYPR

CVEs

378,628 total · page 450 of 7,573

  • CVE-2026-17556CriAug 5, 2026
    risk 0.59cvss 9.1epss 0.01

    A path traversal vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to delete arbitrary files and directories on the instance, including the entire user storage directory containing Git LFS objects, release assets, attachments, and…

  • CVE-2026-9205HigAug 5, 2026
    risk 0.48cvss 7.4epss 0.00

    IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.

  • CVE-2026-9201HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is…

  • CVE-2026-9196HigAug 5, 2026
    risk 0.53cvss 8.1epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during…

  • CVE-2026-9130HigAug 5, 2026
    risk 0.46cvss 7.1epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_messages and store_message methods filter on…

  • CVE-2026-8478HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.

  • CVE-2026-8470HigAug 5, 2026
    risk 0.48cvss 7.4epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces…

  • CVE-2026-8183HigAug 5, 2026
    risk 0.50cvss 7.7epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request…

  • CVE-2026-8182HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.

  • CVE-2026-7869MedAug 5, 2026
    risk 0.35cvss 5.4epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An…

  • CVE-2026-7658MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction,…

  • CVE-2026-70612MedAug 5, 2026
    risk 0.28cvss 5.4epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, requests to open external protocol URLs from web content did not take iframe sandbox restrictions into account, so a…

  • CVE-2026-63457MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    A potential denial of service vulnerability exists in HPE Integrated Lights-Out 6 (iLO 6) prior to v1.78.

  • CVE-2026-48168CriAug 5, 2026
    risk 0.65cvss 10.0epss 0.01

    PraisonAI is a multi-agent teams system. In versions prior to 4.6.40, the bundled Claude GitHub Actions workflow is vulnerable to command injection because it embeds an attacker-controlled pull request branch name into a Bash run: block without quoting or validation.…

  • CVE-2026-18485HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to escalate privileges and execute arbitrary code.  This vulnerability affects NI-PAL 26.3.1 and prior versions running on…

  • CVE-2026-17633HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.

  • CVE-2026-17632HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.01

    IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.

  • CVE-2026-17624HigAug 5, 2026
    risk 0.55cvss 8.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of…

  • CVE-2026-10547MedAug 5, 2026
    risk 0.38cvss 5.9epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache…

  • CVE-2026-9081HigAug 5, 2026
    risk 0.46cvss 7.1epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. The function accepts a user-supplied OLLAMA_BASE_URL parameter and passes it…

  • CVE-2026-7657MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement.

  • CVE-2026-70611MedAug 5, 2026
    risk 0.38cvss 6.9epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.1, and 42.0.0-beta.3, the DevTools reveal in file manager action could launch the target file rather than reveal it. An attacker with a separate…

  • CVE-2026-70610MedAug 5, 2026
    risk 0.28cvss 5.4epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.9, 40.9.2, 41.2.2, and 42.0.0-beta.4, objects copied across the contextBridge boundary from untrusted content could carry an attacker-influenced prototype,…

  • CVE-2026-70609MedAug 5, 2026
    risk 0.30cvss 5.7epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.7, 40.9.0, 41.2.0, and 42.0.0-beta.1, the mode option of webContents.openDevTools() was not sanitized before use by the DevTools frontend. If an attacker can…

  • CVE-2026-70608HigAug 5, 2026
    risk 0.40cvss 7.2epss 0.00

    Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 41.10.3, and 42.0.1, a sandboxed iframe without the allow-popups keyword could still open a new window or trigger setWindowOpenHandler with no user…

  • CVE-2026-70448HigAug 5, 2026
    risk 0.46cvss 7.1epss 0.00

    Jenkins Ivy Report Plugin 1.2 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks when processing Ivy report files.

  • CVE-2026-70447MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing permission checks in Jenkins AWS CodeBuild Plugin 0.59 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-70446MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing permission checks in Jenkins CodeSonar Plugin 3.6.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-70445MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing permission checks in Jenkins Sauce OnDemand Plugin 2.2.0 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-70444MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins Violation Comments to GitLab Plugin 2.62.0 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-70443MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins Horreum Plugin 0.16.162.v33b_4a_a_b_5f828 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to have Jenkins send credentials they are not entitled to use to the administrator-configured Horreum URL.

  • CVE-2026-70442MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins Google Chat Notification Plugin 166.ve6b_de280f2e8 and earlier does not set the appropriate context for credentials lookup, allowing attackers with Item/Configure permission to access and capture credentials they are not entitled to use.

  • CVE-2026-70441MedAug 5, 2026
    risk 0.35cvss 5.4epss 0.00

    Jenkins Summary Display Plugin 1.15 and earlier does not escape the job name in a JavaScript context in build report pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Create or Item/Configure permission.

  • CVE-2026-70440MedAug 5, 2026
    risk 0.35cvss 5.4epss 0.00

    Jenkins Qualys Container Scanning Connector Plugin 1.8.0.5 and earlier does not escape user-controlled field values in a JavaScript context, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.

  • CVE-2026-70439MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Jenkins XML Job to Job DSL Plugin 0.1.13 and earlier does not perform permission checks, allowing attackers lacking appropriate permissions to invoke the conversion functionality.

  • CVE-2026-70438MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    A missing permission check in Jenkins Parameterized Remote Trigger Plugin 3.2.2 and earlier allows attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-70437LowAug 5, 2026
    risk 0.24cvss 3.7epss 0.00

    Jenkins Webhook Secret Credentials Provider Plugin 16.v0cfa_f0215cf5 and earlier does not use a constant-time comparison function when checking whether the provided and expected webhook bearer token are equal, potentially allowing attackers to use statistical methods to obtain a…

  • CVE-2026-70436MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins External Workspace Manager Plugin 1.4.1 and earlier does not perform a permission check (1.4.0 and earlier) or performs an improper permission check (1.4.1) when providing access to externally-managed workspaces through the workspace browser, allowing attackers with…

  • CVE-2026-70435MedAug 5, 2026
    risk 0.27cvss 4.2epss 0.00

    A missing permission check in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2026-70434MedAug 5, 2026
    risk 0.27cvss 4.2epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins SCM-Manager Plugin 1.11.1 and earlier allows attackers to connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

  • CVE-2026-70433MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing permission checks in Jenkins HCL AppScan Plugin 1.8.3 and earlier allow attackers with Overall/Read permission to enumerate credentials IDs of credentials stored in Jenkins.

  • CVE-2026-70432HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier allows attackers to execute arbitrary code in the context of the Jenkins controller JVM.

  • CVE-2026-70431HigAug 5, 2026
    risk 0.57cvss 8.8epss 0.00

    Jenkins Multijob Plugin 669.v9d96a_d9c71b_0 and earlier provides Groovy scripting features that do not integrate with Script Security Plugin, allowing attackers with Item/Create or Item/Configure permission to execute arbitrary code in the context of the Jenkins controller JVM.

  • CVE-2026-70430LowAug 5, 2026
    risk 0.18cvss 2.7epss 0.00

    Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not restrict the types of objects that can be instantiated as part of the project naming strategy configuration, allowing attackers with Overall/Manage permission to instantiate arbitrary types related to configuration,…

  • CVE-2026-70429MedAug 5, 2026
    risk 0.42cvss 6.5epss 0.00

    Jenkins 2.575 and earlier, LTS 2.568.1 and earlier handles case-insensitivity in user names and group names inconsistently, allowing attackers able to create new users or groups with names that case-insensitively match other characters to impersonate other users or be granted…

  • CVE-2026-70428MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins 2.575 and earlier, LTS 2.568.1 and earlier improperly identifies file paths attempting path traversal in file parameter names, allowing attackers with Item/Configure and Item/Build permission to write files to arbitrary locations on the controller file system.

  • CVE-2026-70427MedAug 5, 2026
    risk 0.28cvss 4.3epss 0.00

    Jenkins 2.575 and earlier, LTS 2.568.1 and earlier does not safely handle symbolic links with effectively empty names during the extraction of `.tar` and `.tar.gz` archives, allowing attackers able to control agent processes to provide crafted archives to the controller to write…

  • CVE-2026-70426CriAug 5, 2026
    risk 0.59cvss 9.0epss 0.00

    In Remoting 3384.v60d89463d9e0 and earlier, except 3355.3357.v931d3c992987, included in Jenkins 2.575 and earlier, LTS 2.568.1 and earlier, the JEP-200 class filter is not applied to classes resolved via a fallback path in the Remoting deserialization implementation, allowing…

  • CVE-2026-44605MedAug 5, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the RPM Package Manager (RPM). A local user could be affected by a heap buffer overflow vulnerability when processing a specially crafted NDB database file. This issue arises from an error in how RPM handles certain calculations during file parsing, leading…

  • CVE-2026-17625HigAug 5, 2026
    risk 0.47cvss 7.2epss 0.01

    IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization…