Export limit exceeded: 402751 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (402751 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-70357 | 1 Gitea | 1 Gitea | 2026-10-07 | N/A |
| Gitea validates a repository migration hostname against its network allow and block lists before invoking Git, but the Git subprocess independently resolves the hostname when connecting. An attacker who can start a migration and control the destination's DNS can change the address between validation and connection to reach a blocked internal address. The affected path is the Git clone operation; validation in the migration HTTP client's dialer does not protect the independently connecting Git subprocess. | ||||
| CVE-2026-73278 | 1 Gitea | 1 Gitea | 2026-10-07 | N/A |
| Gitea's OAuth2 and OpenID Connect sign-in paths do not require a WebAuthn challenge when WebAuthn is the account's only configured second factor. A party able to authenticate through the affected external identity flow can obtain a full session without the passkey verification enforced during password login. One affected path can also persist an external identity link, extending the compromise beyond the initial session; accounts with TOTP configured are outside the reported WebAuthn-only scenario. | ||||
| CVE-2026-88962 | 1 Ibm | 1 Langflow Oss | 2026-10-07 | 8.8 High |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation. | ||||
| CVE-2026-93443 | 1 Ibm | 1 Langflow Oss | 2026-10-07 | 7.5 High |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in code. | ||||
| CVE-2026-93448 | 1 Ibm | 1 Langflow Oss | 2026-10-07 | 6.5 Medium |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory. | ||||
| CVE-2026-93449 | 1 Ibm | 1 Langflow Oss | 2026-10-07 | 8.5 High |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of code generation. | ||||
| CVE-2026-93445 | 1 Ibm | 1 Langflow Oss | 2026-10-07 | 8.1 High |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code. | ||||
| CVE-2026-93447 | 1 Ibm | 1 Langflow Oss | 2026-10-07 | 7.5 High |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow an attacker with access to the server secret and Redis write access to submit a malicious serialized cache value. When the value was retrieved, deserialization could have executed attacker-controlled code with the privileges of the service process. | ||||
| CVE-2026-93675 | 1 Ibm | 1 Langflow Oss | 2026-10-07 | 8.8 High |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to an expected dependency confusion. | ||||
| CVE-2026-93677 | 1 Ibm | 1 Langflow Oss | 2026-10-07 | 7.7 High |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to exposure of sensitive information to an unauthorized actor. | ||||
| CVE-2026-93678 | 1 Ibm | 1 Langflow Oss | 2026-10-07 | 7.6 High |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to improper authorization. | ||||
| CVE-2026-93679 | 1 Ibm | 1 Langflow Oss | 2026-10-07 | 4.3 Medium |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to cause a denial of service due to uncontrolled resource consumption during ZIP file extraction. | ||||
| CVE-2026-93674 | 1 Ibm | 1 Langflow Oss | 2026-10-07 | 9.8 Critical |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | ||||
| CVE-2026-97671 | 1 Ibm | 1 Langflow Oss | 2026-10-07 | 6.5 Medium |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information due to a path traversal vulnerability. | ||||
| CVE-2026-97673 | 1 Ibm | 1 Langflow Oss | 2026-10-07 | 8.8 High |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation. | ||||
| CVE-2026-106292 | 1 Google | 1 Chrome | 2026-10-07 | 8.3 High |
| Buffer overflow in Fonts in Google Chrome prior to 155.0.8059.39 allowed a remote attacker who had compromised the renderer process to potentially execute arbitrary code outside the sandbox via a crafted HTML page. (Chromium security severity: Medium) | ||||
| CVE-2026-97674 | 1 Ibm | 1 Langflow Oss | 2026-10-06 | 8.1 High |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command ('Code Injection'), aka improper control of code generation. | ||||
| CVE-2026-97678 | 1 Ibm | 1 Langflow Oss | 2026-10-06 | 8.8 High |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper input validation. | ||||
| CVE-2026-97679 | 1 Ibm | 1 Langflow Oss | 2026-10-06 | 8.8 High |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command ('Code Injection') related to improper input validation. | ||||
| CVE-2026-97680 | 1 Ibm | 1 Langflow Oss | 2026-10-06 | 8.3 High |
| IBM Langflow OSS 1.0.0 through 1.12.2 could allow a remote authenticated attacker to obtain sensitive information or inject malicious data due to improper access control in the vertex result caching subsystem. | ||||
