CVE Database

133011+ vulnerabilities with CVSS scores, EPSS exploit predictions, and CISA KEV status. Updated daily.

Filter: All CRITICAL HIGH MEDIUM LOW CISA KEV
Sort: Newest CVSS EPSS
CVE-2026-10128
6.5 MEDIUM

IBM Langflow OSS 1.0.0 through 1.10.3 allows authenticated users can exploit a built-in Langflow component to read arbitrary server environment variables, exposing sensitive secrets despite …

Aug 5, 2026
CVE-2026-9077
8.5 HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restrictions and write arbitrary MCP server configurations to IDE configuration files …

Aug 5, 2026
CVE-2026-8446
7.5 HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol (MCP) composer endpoint when mcp_composer_enabled=true (default) and projects are …

Aug 5, 2026
CVE-2026-7646
6.5 MEDIUM

IBM Langflow OSS 1.0.0 through 1.10.3 allows users to read arbitrary files from the server filesystem, including other users' uploaded documents, the JWT signing secret, …

Aug 5, 2026
CVE-2026-70607
5.3 MEDIUM

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, some window options supplied …

Aug 5, 2026
CVE-2026-20313
7.7 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. …

Aug 5, 2026
CVE-2026-20312
8.8 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. …

Aug 5, 2026
CVE-2026-20311
6.3 MEDIUM

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to cause a denial …

Aug 5, 2026
CVE-2026-20310
9.1 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. …

Aug 5, 2026
CVE-2026-20308
4.3 MEDIUM

A vulnerability in the web-based management interface of Cisco IOS XE Software could allow an authenticated, remote attacker with low privileges to perform a denial …

Aug 5, 2026
CVE-2026-20304
9.9 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. …

Aug 5, 2026
CVE-2026-20303
9.9 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Catalyst SD-WAN engineering team has conducted a comprehensive internal security review. …

Aug 5, 2026
CVE-2026-20301
8.6 HIGH

A vulnerability in the Extensible Messaging Client Protocol (XMCP), also referred to as the External Client protocol, of Cisco IOS Software and Cisco IOS XE …

Aug 5, 2026
CVE-2026-20294
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco Catalyst SD-WAN Manager could allow an authenticated, remote attacker to view sensitive information in clear text …

Aug 5, 2026
CVE-2026-20289
5.7 MEDIUM

A vulnerability in the logging subsystem of Cisco RoomOS could allow an authenticated, local attacker with low privileges to access sensitive information. This vulnerability is …

Aug 5, 2026
CVE-2026-20288
6.5 MEDIUM

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with Admin privileges to execute arbitrary commands on the underlying …

Aug 5, 2026
CVE-2026-20273
8.6 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security …

Aug 5, 2026
CVE-2026-20272
9.8 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security …

Aug 5, 2026
CVE-2026-20271
8.6 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security …

Aug 5, 2026
CVE-2026-20270
8.6 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security …

Aug 5, 2026
CVE-2026-20269
8.6 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security …

Aug 5, 2026
CVE-2026-20268
8.6 HIGH

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security …

Aug 5, 2026
CVE-2026-20267
9.0 CRITICAL

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security …

Aug 5, 2026
CVE-2026-20263
8.6 HIGH

A vulnerability in the Blocks Extensible Exchange Protocol (BEEP) feature of Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial …

Aug 5, 2026
CVE-2026-20200
8.8 HIGH

A vulnerability in the web-based management interface of Cisco IMC could allow an authenticated, remote attacker with low privileges to execute arbitrary commands on the …

Aug 5, 2026
CVE-2026-20198
4.8 MEDIUM

A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) …

Aug 5, 2026
CVE-2026-20124
7.7 HIGH

A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE Software could allow an authenticated, remote attacker to cause an affected …

Aug 5, 2026
CVE-2026-20028
5.0 MEDIUM

A vulnerability in the network driver of Cisco Terminal Service (TS) Agent could allow an authenticated, remote attacker to bypass firewall rules that are associated …

Aug 5, 2026
CVE-2026-18927
6.3 MEDIUM

A vulnerability was determined in imranrisal-dev Student-Management-System 18ea7904c339e0c7b0234724a79c939ce6191def/a8d43a29aaf267e7ca97171d6dbb44057bcd7f8c. This affects the function storeProfileImage of the file student_profile_pic.php of the component Shared Upload Helper. Executing a …

Aug 5, 2026
CVE-2026-17630
7.2 HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper validation of configuration parameters.

Aug 5, 2026
CVE-2026-17626
8.8 HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose sensitive host files via Docker-based MCP servers due …

Aug 5, 2026
CVE-2026-17623
8.8 HIGH

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of the command field in …

Aug 5, 2026
CVE-2026-17617
8.5 HIGH

IBM Application Gateway Operator 22.2 through 26.06 is vulnerable to Server-Side Request Forgery (SSRF) due to insufficient validation of URLs specified in custom resources.

Aug 5, 2026
CVE-2026-14587

Neo4j's Bolt modern handshake decoder treats an overlong capability bit mask the same way it treats a truncated bit mask. When an unauthenticated client sends …

Aug 5, 2026
CVE-2026-9203
8.5 HIGH

A server-side request forgery vulnerability in Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with low-privileged roles to bypass protections for cloud …

Aug 5, 2026
CVE-2026-9195
9.3 CRITICAL

A cross-site scripting vulnerability in the Query Console of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator …

Aug 5, 2026
CVE-2026-9193
9.9 CRITICAL

An improper privilege management vulnerability in the Hadoop integration of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged Hadoop …

Aug 5, 2026
CVE-2026-9192
9.8 CRITICAL

An authentication bypass vulnerability in the ODBC App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker to bypass password …

Aug 5, 2026
CVE-2026-9190
9.1 CRITICAL

An HTTP request smuggling vulnerability in the HTTP App Server of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker to bypass authentication …

Aug 5, 2026
CVE-2026-8709
9.9 CRITICAL

An improper privilege management vulnerability in the REST API document patch operation of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with …

Aug 5, 2026
CVE-2026-8400
8.1 HIGH

IBM WebSphere Application Server 8.5, and 9.0 and IBM WebSphere Application Server - Liberty Continuous delivery has a flaw in the ORB component in IBM …

Aug 5, 2026
CVE-2026-7557
9.1 CRITICAL

An improper verification of cryptographic signature vulnerability in the SAML authentication module of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an unauthenticated remote attacker …

Aug 5, 2026
CVE-2026-7329
9.9 CRITICAL

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated …

Aug 5, 2026
CVE-2026-7327
8.1 HIGH

An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with …

Aug 5, 2026
CVE-2026-7326
7.5 HIGH

A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated …

Aug 5, 2026
CVE-2026-70606
5.9 MEDIUM

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 40.10.6, 41.9.1, 42.5.1, and 43.0.0, when a custom protocol …

Aug 5, 2026
CVE-2026-70605
5.9 MEDIUM

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, when following HTTP redirects, …

Aug 5, 2026
CVE-2026-70604
7.4 HIGH

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.10, 40.9.3, 41.4.0, and 42.0.0, a custom scheme registered …

Aug 5, 2026
CVE-2026-70603
6.0 MEDIUM

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.6, 40.9.0, 41.1.1, and 42.0.0-beta.1, shell.openPath() did not reject …

Aug 5, 2026
CVE-2026-70602
6.6 MEDIUM

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.8, 40.9.0, 41.2.1, and 42.0.0-beta.3, extension tab and scripting …

Aug 5, 2026

Scan your infrastructure for known CVEs

Free website and port scanning — find vulnerabilities before attackers do.