Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

54243
Total
4300
Critical
16125
High
15819
Medium
CVE ID Severity Score Description Published
CVE-2026-51894 UNKNOWN — infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant identifier and reaches a data-access … Oct 01, 2026
CVE-2026-51893 UNKNOWN — infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a … Oct 01, 2026
CVE-2026-51892 UNKNOWN — infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>. Oct 01, 2026
CVE-2026-51888 UNKNOWN — langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component is: src/backend/base/langflow/api/v1/knowledge_bases.py:knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base. … Oct 01, 2026
CVE-2026-51886 UNKNOWN — langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: … Oct 01, 2026
CVE-2026-51884 UNKNOWN — The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to … Oct 01, 2026
CVE-2026-51883 UNKNOWN — The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as … Oct 01, 2026
CVE-2026-51882 UNKNOWN — The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the `openai_files` … Oct 01, 2026
CVE-2026-51881 UNKNOWN — deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to execute reviewer-chosen shell … Oct 01, 2026
CVE-2026-51880 UNKNOWN — deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to write … Oct 01, 2026
CVE-2026-51879 UNKNOWN — deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.write_bot_file. A remote caller can enumerate bot IDs and overwrite another bot's whitelisted … Oct 01, 2026
CVE-2026-51878 UNKNOWN — deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TurnRuntimeManager.regenerate_last_turn. A remote caller can enumerate or obtain a session_id and trigger regenerate … Oct 01, 2026
CVE-2026-51876 UNKNOWN — DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can reuse a publicly exposed book_id to submit … Oct 01, 2026
CVE-2026-51875 UNKNOWN — In Devika v1.0, the Feature Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace, potentially … Oct 01, 2026
CVE-2026-51874 UNKNOWN — In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace. Oct 01, 2026
CVE-2026-51873 UNKNOWN — Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside the intended project workspace. Oct 01, 2026
CVE-2026-34494 UNKNOWN — - On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before … Oct 01, 2026
CVE-2026-34493 UNKNOWN — - On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63. Oct 01, 2026
CVE-2026-27873 UNKNOWN — - Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52. Oct 01, 2026
CVE-2026-18397 UNKNOWN — This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the … Oct 01, 2026
CVE-2026-104356 MEDIUM 5.9 PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in … Oct 01, 2026
CVE-2026-104051 HIGH 8.2 PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint … Oct 01, 2026
CVE-2026-104002 MEDIUM 5.3 A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that … Oct 01, 2026
CVE-2026-96780 UNKNOWN — figlet.js is a FIG driver written in JavaScript that aims to implement the FIGfont specification. Prior to 1.11.3, text() and textSync() can enter an unbounded … Oct 01, 2026
CVE-2026-71451 UNKNOWN — - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63. Oct 01, 2026