Vulnerabilities

  

CVE-2026-70448 | Jenkins Project Ivy Report Plugin up to 1.2 xml external entity reference (EUVD-2026-53542)

A vulnerability labeled as critical has been found in Jenkins Project Ivy Report Plugin up to 1.2. Affected by this

  

CVE-2026-8470 | IBM Langflow OSS up to 1.10.3 entropy

A vulnerability marked as problematic has been reported in IBM Langflow OSS up to 1.10.3. This affects an unknown part.

  

CVE-2026-8183 | IBM Langflow OSS up to 1.10.3 URL path traversal

A vulnerability described as problematic has been identified in IBM Langflow OSS up to 1.10.3. This vulnerability affects unknown code

  

CVE-2026-9130 | IBM Langflow OSS up to 1.10.3 MemoryComponent session_id authorization

A vulnerability classified as problematic has been found in IBM Langflow OSS up to 1.10.3. This issue affects the function

  

CVE-2026-18990 | letta-ai LettaBot 0.2.0 API Status Route src/api/server.ts missing authentication

A vulnerability classified as critical was found in letta-ai LettaBot 0.2.0. Impacted is an unknown function of the file src/api/server.ts

  

CVE-2026-10547 | IBM Langflow OSS up to 1.10.3 vertices improper authorization

A vulnerability, which was classified as critical, has been found in IBM Langflow OSS up to 1.10.3. The affected element

  

CVE-2026-7658 | IBM Langflow OSS up to 1.10.3 Username path traversal

A vulnerability, which was classified as critical, was found in IBM Langflow OSS up to 1.10.3. The impacted element is

  

CVE-2026-7869 | IBM Langflow OSS up to 1.10.3 Knowledge Bases API /api/v1/knowledge_bases path traversal

A vulnerability has been found in IBM Langflow OSS up to 1.10.3 and classified as critical. This affects an unknown

  

CVE-2026-8478 | IBM Langflow OSS up to 1.10.3 code injection

A vulnerability was found in IBM Langflow OSS up to 1.10.3 and classified as critical. This impacts an unknown function.

  

CVE-2026-9205 | IBM Langflow OSS up to 1.10.3 ensure_fernet_key risky encryption

A vulnerability was found in IBM Langflow OSS up to 1.10.3. It has been classified as problematic. Affected is the

  

CVE-2026-70612 | Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2 iFrame Sandbox setPermissionRequestHandler sandbox

A vulnerability was found in Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2. It has been declared as critical. Affected by this vulnerability is

  

CVE-2026-63457 | HPE Integrated Lights-Out up to 1.77 denial of service

A vulnerability was found in HPE Integrated Lights-Out up to 1.77. It has been rated as critical. Affected by this

  

CVE-2026-18991 | NanoClawnanocoai NanoClaw up to 2.0.64 send_file core.ts path traversal (Issue 2760)

A vulnerability categorized as critical has been discovered in NanoClawnanocoai NanoClaw up to 2.0.64. This affects an unknown part of

  

CVE-2026-18992 | zhayujie CowAgent up to 2.1.1 Self-Evolution Review Agent executor.py _select_tools authorization (Issue 2904)

A vulnerability identified as critical has been detected in zhayujie CowAgent up to 2.1.1. This vulnerability affects the function _select_tools

  

CVE-2026-18485 | NI NI-PAL up to 26.3.1 NI-PAL kernel driver privileges management

A vulnerability labeled as very critical has been found in NI NI-PAL up to 26.3.1. This issue affects some unknown

  

CVE-2026-17632 | IBM Langflow OSS up to 1.10.3 AST code injection

A vulnerability marked as critical has been reported in IBM Langflow OSS up to 1.10.3. Impacted is an unknown function

  

CVE-2026-9196 | IBM Langflow OSS up to 1.10.3 Agentic Assistant Validation code injection

A vulnerability described as critical has been identified in IBM Langflow OSS up to 1.10.3. The affected element is an

  

CVE-2026-9201 | IBM Langflow OSS up to 1.10.3 Custom Component Validation weak hash

A vulnerability classified as critical has been found in IBM Langflow OSS up to 1.10.3. The impacted element is an

  

CVE-2026-17624 | IBM Langflow OSS up to 1.10.3 code injection

A vulnerability classified as critical was found in IBM Langflow OSS up to 1.10.3. This affects an unknown function. Such

  

CVE-2026-17633 | IBM Langflow OSS up to 1.10.3 code injection

A vulnerability, which was classified as critical, has been found in IBM Langflow OSS up to 1.10.3. This impacts an

  

CVE-2026-8182 | IBM Langflow OSS up to 1.10.3 code injection

A vulnerability, which was classified as critical, was found in IBM Langflow OSS up to 1.10.3. Affected is an unknown

  

CVE-2026-48168 | MervinPraison PraisonAI up to 4.6.39 Claude GitHub Actions Workflow command injection

A vulnerability has been found in MervinPraison PraisonAI up to 4.6.39 and classified as critical. Affected by this vulnerability is

  

CVE-2026-18993 | NousResearch hermes-agent up to 0.16.0 Memory Toolset model_tools.py access control (46171/46348/48181)

A vulnerability was found in NousResearch hermes-agent up to 0.16.0 and classified as critical. Affected by this issue is some

  

CVE-2026-18995 | netease-youdao LobsterAI 2026.6.10 MEDIA Path artifactParser.ts parseMediaTokensFromText information disclosure (Issue 2176)

A vulnerability was found in netease-youdao LobsterAI 2026.6.10. It has been classified as problematic. This affects the function parseMediaTokensFromText of

  

CVE-2026-12730 | IBM Business Automation Workflow certificate validation

A vulnerability was found in IBM Business Automation Workflow. It has been declared as problematic. Affected by this issue is

  

CVE-2026-13477 | IBM QRadar up to 7.6.0.1/7.5.0 UP 15 Interim Fix 005 input validation

A vulnerability was found in IBM QRadar up to 7.6.0.1/7.5.0 UP 15 Interim Fix 005. It has been rated as

  

CVE-2026-15656 | IBM Maximo Application Suite 9.0/9.1/9.2 missing secure attribute

A vulnerability categorized as problematic has been discovered in IBM Maximo Application Suite 9.0/9.1/9.2. This vulnerability affects unknown code. The

  

CVE-2026-10025 | IBM QRadar up to 7.6.0.1/7.5.0 UP 15 Interim Fix 005 Event Processing Pipeline q1labs_core.jar parseXmlPayload xml external entity reference

A vulnerability identified as critical has been detected in IBM QRadar up to 7.6.0.1/7.5.0 UP 15 Interim Fix 005. This

  

CVE-2026-12762 | IBM Cloud Pak for Business Automation 24.0.0/24.0.1/25.0.0/26.0.0 information disclosure

A vulnerability labeled as problematic has been found in IBM Cloud Pak for Business Automation 24.0.0/24.0.1/25.0.0/26.0.0. Impacted is an unknown

  

CVE-2026-18531 | IBM Maximo Application Suite 9.0/9.1/9.2 risky encryption

A vulnerability marked as problematic has been reported in IBM Maximo Application Suite 9.0/9.1/9.2. The affected element is an unknown

  

CVE-2026-70604 | Electron up to 39.8.9/40.9.2/41.3.9 Custom Scheme cross-domain policy

A vulnerability described as problematic has been identified in Electron up to 39.8.9/40.9.2/41.3.9. The impacted element is an unknown function

  

CVE-2026-70598 | Electron up to 39.8.9/40.8.x/41.2.0/42.0.0-beta.2 out-of-bounds

A vulnerability classified as problematic has been found in Electron up to 39.8.9/40.8.x/41.2.0/42.0.0-beta.2. This affects an unknown function. The manipulation

  

CVE-2026-70606 | Electron up to 40.10.5/41.9.0/42.5.0 Custom Protocol information disclosure

A vulnerability classified as problematic was found in Electron up to 40.10.5/41.9.0/42.5.0. This impacts an unknown function of the component

  

CVE-2026-7327 | Progress MarkLogic Server up to 11.3.5/12.0.2 REST API privileges management

A vulnerability, which was classified as very critical, has been found in Progress MarkLogic Server up to 11.3.5/12.0.2. Affected is

  

CVE-2026-7329 | Progress MarkLogic Server up to 11.3.5/12.0.2 SQL/SPARQL/Optic REST query interfaces privileges management

A vulnerability, which was classified as critical, was found in Progress MarkLogic Server up to 11.3.5/12.0.2. Affected by this vulnerability

  

CVE-2026-7557 | Progress MarkLogic Server up to 11.3.5/12.0.2 SAML Authentication signature verification

A vulnerability has been found in Progress MarkLogic Server up to 11.3.5/12.0.2 and classified as critical. Affected by this issue

  

CVE-2026-70599 | Electron up to 39.8.6/40.8.x/41.1.x/42.0.0-beta.0 Permission Check cross-domain policy

A vulnerability was found in Electron up to 39.8.6/40.8.x/41.1.x/42.0.0-beta.0 and classified as problematic. This affects an unknown part of the

  

CVE-2026-70600 | Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2 Autofill Popup clickjacking

A vulnerability was found in Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2. It has been classified as problematic. This vulnerability affects unknown code

  

CVE-2026-70601 | Electron up to 39.8.8/40.9.1/41.2.1/42.0.0-beta.4 contextBridge isolation

A vulnerability was found in Electron up to 39.8.8/40.9.1/41.2.1/42.0.0-beta.4. It has been declared as critical. This issue affects some unknown

  

CVE-2026-70603 | Electron up to 39.8.5/40.8.x/41.1.0/42.0.0-beta.0 Shell shell.openPath input validation

A vulnerability was found in Electron up to 39.8.5/40.8.x/41.1.0/42.0.0-beta.0. It has been rated as critical. Impacted is the function shell.openPath

  

CVE-2026-7326 | Progress MarkLogic Server up to 11.3.5/12.0.2 Admin UI cross-site request forgery

A vulnerability categorized as problematic has been discovered in Progress MarkLogic Server up to 11.3.5/12.0.2. The affected element is an

  

CVE-2026-70605 | Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2 Redirect net.fetch/net.request redirect

A vulnerability identified as problematic has been detected in Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2. The impacted element is the function net.fetch/net.request

  

CVE-2026-70602 | Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2 Extension Tab/Scripting APIs information disclosure

A vulnerability labeled as problematic has been found in Electron up to 39.8.7/40.8.x/41.2.0/42.0.0-beta.2. This affects an unknown function of the

  

CVE-2026-8709 | Progress MarkLogic Server up to 11.3.5/12.0.2 REST API privileges management

A vulnerability marked as very critical has been reported in Progress MarkLogic Server up to 11.3.5/12.0.2. This impacts an unknown

  

CVE-2026-9193 | Progress MarkLogic Server up to 11.3.5/12.0.2 Hadoop integration privileges management

A vulnerability described as very critical has been identified in Progress MarkLogic Server up to 11.3.5/12.0.2. Affected is an unknown

  

CVE-2026-9203 | Progress MarkLogic Server up to 11.3.5/12.0.2 server-side request forgery

A vulnerability classified as problematic has been found in Progress MarkLogic Server up to 11.3.5/12.0.2. Affected by this vulnerability is

  

CVE-2026-9190 | Progress MarkLogic Server up to 11.3.5/12.0.2 HTTP App Server request smuggling

A vulnerability classified as problematic was found in Progress MarkLogic Server up to 11.3.5/12.0.2. Affected by this issue is some

  

CVE-2026-9192 | Progress MarkLogic Server up to 11.3.5/12.0.2 ODBC App Server improper authentication

A vulnerability, which was classified as very critical, has been found in Progress MarkLogic Server up to 11.3.5/12.0.2. This affects

  

CVE-2026-9195 | Progress MarkLogic Server up to 11.3.5/12.0.2 Query Console cross site scripting

A vulnerability, which was classified as problematic, was found in Progress MarkLogic Server up to 11.3.5/12.0.2. This vulnerability affects unknown

  

CVE-2026-20200 | Cisco Unified Computing System up to 6.0(1.250194) Web-based Management Interface code injection

A vulnerability has been found in Cisco Unified Computing System and classified as very critical. This issue affects some unknown

  

CVE-2026-20288 | Cisco Unified Computing System Web-based Management Interface code injection

A vulnerability was found in Cisco Unified Computing System and Unified Computing System E-Series Software and classified as very critical.

  

CVE-2026-20268 | Cisco IOS XE Software up to 26.1.1a memory corruption

A vulnerability was found in Cisco IOS XE Software. It has been classified as very critical. The affected element is

  

CVE-2026-20269 | Cisco IOS XE Software up to 26.1.1a resource control

A vulnerability was found in Cisco IOS XE Software. It has been declared as very critical. The impacted element is

  

CVE-2026-20124 | Cisco IOS XE Software up to 17.18.2 SNMP Subsystem denial of service

A vulnerability was found in Cisco IOS XE Software. It has been rated as critical. This affects an unknown function

  

CVE-2026-20263 | Cisco IOS XE Software up to 26.2.1ea BEEP denial of service

A vulnerability categorized as critical has been discovered in Cisco IOS XE Software. This impacts an unknown function of the

  

CVE-2026-20267 | Cisco IOS XE Software up to 26.1.1a access control

A vulnerability identified as very critical has been detected in Cisco IOS XE Software. Affected is an unknown function. The

  

CVE-2026-20270 | Cisco IOS XE Software up to 26.1.1a calculation

A vulnerability labeled as very critical has been found in Cisco IOS XE Software. Affected by this vulnerability is an

  

CVE-2026-20271 | Cisco IOS XE Software up to 26.1.1a insufficient control flow management

A vulnerability marked as very critical has been reported in Cisco IOS XE Software. Affected by this issue is some

  

CVE-2026-20272 | Cisco IOS XE Software up to 26.1.1a injection

A vulnerability described as very critical has been identified in Cisco IOS XE Software. This affects an unknown part. Such

  

CVE-2026-20028 | Cisco Terminal Services Agent up to TSAgent-1.4.2 Network Driver privileges management

A vulnerability classified as very critical has been found in Cisco Terminal Services Agent up to TSAgent-1.4.2. This vulnerability affects

  

CVE-2026-20273 | Cisco IOS XE Software up to 26.1.1a input validation

A vulnerability classified as very critical was found in Cisco IOS XE Software. This issue affects some unknown processing. Executing

  

CVE-2026-17623 | IBM Langflow OSS up to 1.10.3 MCP Server Configuration command code injection

A vulnerability, which was classified as critical, has been found in IBM Langflow OSS up to 1.10.3. Impacted is an

  

CVE-2026-17626 | IBM Langflow up to 1.10.3 information disclosure

A vulnerability, which was classified as problematic, was found in IBM Langflow up to 1.10.3. The affected element is an

  

CVE-2026-20289 | Cisco RoomOS up to 26.5.2.0 Logging Subsystem information disclosure

A vulnerability has been found in Cisco RoomOS and classified as problematic. The impacted element is an unknown function of

  

CVE-2026-20198 | Cisco Enterprise NFV Infrastructure Software Web-based Management Interface cross site scripting

A vulnerability was found in Cisco Enterprise NFV Infrastructure Software, Unified Computing System and Unified Computing System E-Series Software and

  

CVE-2026-17630 | IBM Langflow OSS up to 1.10.3 input validation

A vulnerability was found in IBM Langflow OSS up to 1.10.3. It has been classified as critical. This impacts an

  

CVE-2026-17617 | IBM Application Gateway Operator up to 26.06 server-side request forgery

A vulnerability was found in IBM Application Gateway Operator up to 26.06. It has been declared as critical. Affected is

  

CVE-2026-14587 | Neo4j Enterprise Edition/Community Edition up to 5.26.28/2026.6 Bolt Modern Handshake Decoder resource consumption

A vulnerability was found in Neo4j Enterprise Edition and Community Edition up to 5.26.28/2026.6. It has been rated as problematic.

  

CVE-2026-20301 | Cisco IOS XE Software/IOS XMCP denial of service

A vulnerability categorized as critical has been discovered in Cisco IOS XE Software and IOS. Affected by this issue is

  

CVE-2026-20308 | Cisco IOS XE Software up to 26.2.1ea Web-based Management Interface input validation

A vulnerability identified as critical has been detected in Cisco IOS XE Software. This affects an unknown part of the

  

CVE-2026-20311 | Cisco IOS XE Software up to 26.2.1ea Web-based Management Interface certificate validation

A vulnerability labeled as problematic has been found in Cisco IOS XE Software. This vulnerability affects unknown code of the

  

CVE-2026-20303 | Cisco Catalyst SD-WAN Controller/Catalyst SD-WAN Manager input validation

A vulnerability marked as very critical has been reported in Cisco Catalyst SD-WAN Controller and Catalyst SD-WAN Manager. This issue

  

CVE-2026-20304 | Cisco Catalyst SD-WAN Controller/Catalyst SD-WAN Manager access control

A vulnerability described as very critical has been identified in Cisco Catalyst SD-WAN Controller and Catalyst SD-WAN Manager. Impacted is

  

CVE-2026-20310 | Cisco SD-WAN Controller/SD-WAN Manager link following

A vulnerability classified as very critical has been found in Cisco SD-WAN Controller and SD-WAN Manager. The affected element is

  

CVE-2026-16100 | Red Hat Keycloak User-Event Metrics Recording resource consumption

A vulnerability has been found in Red Hat Keycloak and classified as problematic. This vulnerability affects unknown code of the

  

CVE-2026-54876 | OpenSSL up to 3.6.3/4.0.1 OCSP Response Checking OCSP_response_get1_basic certs memory leak

A vulnerability was found in OpenSSL up to 3.6.3/4.0.1 and classified as problematic. This issue affects the function OCSP_response_get1_basic of

  

CVE-2026-16102 | Red Hat Keycloak Dynamic Client Registration privileges management

A vulnerability was found in Red Hat Keycloak. It has been classified as critical. Impacted is an unknown function of

  

CVE-2026-15573 | Red Hat Keycloak PathMatcher improper authorization

A vulnerability was found in Red Hat Keycloak. It has been declared as critical. The affected element is an unknown

  

CVE-2026-17613 | Penpot up to 2.17.0 Import import-binfile file-id authorization

A vulnerability was found in Penpot up to 2.17.0. It has been rated as critical. The impacted element is the

  

CVE-2026-16071 | Red Hat Keycloak LDAP storage provider access control

A vulnerability categorized as problematic has been discovered in Red Hat Keycloak. This affects an unknown function of the component

  

CVE-2026-12410 | Gen Digital CCleaner 6.36.11508 Uninstaller symlink

A vulnerability identified as problematic has been detected in Gen Digital CCleaner 6.36.11508. This impacts an unknown function of the

  

CVE-2026-16022 | oblique-bit cli up to 15.4.1 Project Creation execSync project-name os command injection

A vulnerability marked as problematic has been reported in oblique-bit cli up to 15.4.1. Affected is the function execSync of

  

CVE-2026-0516 | SonicWall SonicOS HTTP Header Processing neutralization

A vulnerability described as critical has been identified in SonicWall SonicOS. Affected by this vulnerability is an unknown functionality of

  

CVE-2026-71259 | ESPHome up to 2026.7.0 URL Validator config_validation.py cv.url input validation

A vulnerability classified as problematic has been found in ESPHome up to 2026.7.0. Affected by this issue is the function

  

CVE-2026-71276 | absmach Magistrala Message Readers transport.go fmt.Sprintf format sql injection

A vulnerability classified as critical was found in absmach Magistrala. This affects the function fmt.Sprintf of the file readers/api/http/transport.go of

  

CVE-2026-71268 | thiagoralves OpenPLC Structured Text File webserver/openplc.py compile_program file_path path traversal

A vulnerability, which was classified as very critical, has been found in thiagoralves OpenPLC. This vulnerability affects the function compile_program

  

CVE-2026-71226 | Red Hat Enterprise Linux/Kernel libkcapi memory corruption

A vulnerability, which was classified as very critical, was found in Red Hat Enterprise Linux and Kernel. This issue affects

  

CVE-2026-71262 | IoTSharp BlobStorageController BlobStorageController.cs _blob.WriteFileAsync formFile path traversal

A vulnerability has been found in IoTSharp and classified as critical. Impacted is the function _blob.WriteFileAsync of the file BlobStorageController.cs

  

CVE-2026-71263 | cwalter-at FreeModbus TCP Port porttcp.c xMBPortTCPPool Length off-by-one

A vulnerability was found in cwalter-at FreeModbus and classified as critical. The affected element is the function xMBPortTCPPool of the

  

CVE-2026-71264 | Aircoookie WLED JSON Configuration Endpoint wled00/wled_server.cpp serveJson improper authentication

A vulnerability was found in Aircoookie WLED. It has been classified as critical. The impacted element is the function serveJson

  

CVE-2026-71271 | usememos Memos up to 0.29.1 Webhook URL Validation validate.go isReservedIP redirect

A vulnerability was found in usememos Memos up to 0.29.1. It has been declared as problematic. This affects the function

  

CVE-2026-71274 | openshwprojects OpenBK7231T_App MQTT Command src/cmnds/cmd_channels.c CHANNEL_SetLabel encoding error

A vulnerability was found in openshwprojects OpenBK7231T_App. It has been rated as very critical. This impacts the function CHANNEL_SetLabel of

  

CVE-2026-71275 | openshwprojects OpenBK7231T_App OTA Execution http_fns.c http_fn_ota_exec host cross site scripting

A vulnerability categorized as problematic has been discovered in openshwprojects OpenBK7231T_App. Affected is the function http_fn_ota_exec of the file src/httpserver/http_fns.c

  

CVE-2026-71261 | mackron dr_libs W64 CUE Chunk Metadata Parsing dr_wav.h drwav__metadata_process_chunk cuePointCount integer overflow

A vulnerability identified as critical has been detected in mackron dr_libs. Affected by this vulnerability is the function drwav__metadata_process_chunk of

  

CVE-2026-71270 | Stirling-Tools Stirling-PDF URL PDF Conversion Endpoint ConvertWebsiteToPDF.java server-side request forgery

A vulnerability labeled as critical has been found in Stirling-Tools Stirling-PDF. Affected by this issue is some unknown functionality of

  

CVE-2026-71266 | syoyo tinyobjloader-c tinyobj_loader_c.h tinyobj_parse_and_index_mtl_file stack-based overflow

A vulnerability marked as problematic has been reported in syoyo tinyobjloader-c. This affects the function tinyobj_parse_and_index_mtl_file of the file tinyobj_loader_c.h.

  

CVE-2026-71267 | rxi microtar src/microtar.c mtar_write_file_header/mtar_write_dir_header Name stack-based overflow

A vulnerability described as critical has been identified in rxi microtar. This vulnerability affects the function mtar_write_file_header/mtar_write_dir_header of the file

  

CVE-2026-71272 | usememos Memos up to 0.29.1 Webhook Dispatch webhook.go safeDialContext dns rebinding

A vulnerability classified as critical has been found in usememos Memos up to 0.29.1. This issue affects the function safeDialContext

  

CVE-2026-71269 | Node-RED Storage library.js getLibraryEntry/saveLibraryEntry path path traversal

A vulnerability classified as critical was found in Node-RED. Impacted is the function getLibraryEntry/saveLibraryEntry of the file packages/node_modules/@node-red/runtime/lib/storage/localfilesystem/library.js of the

  

CVE-2026-71273 | openshwprojects OpenBK7231T_App WiFi Configuration http_fns.c web_admin_password_enabled cross-site request forgery

A vulnerability, which was classified as problematic, has been found in openshwprojects OpenBK7231T_App. The affected element is an unknown function