Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
54243
Total
4300
Critical
16125
High
15819
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-51894 | UNKNOWN | — | infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant identifier and reaches a data-access … | Oct 01, 2026 |
| CVE-2026-51893 | UNKNOWN | — | infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object or tenant identifier and reaches a … | Oct 01, 2026 |
| CVE-2026-51892 | UNKNOWN | — | infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>. | Oct 01, 2026 |
| CVE-2026-51888 | UNKNOWN | — | langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component is: src/backend/base/langflow/api/v1/knowledge_bases.py:knowledge_bases-create_knowledge_base-a-live-http-post-to-create-knowledge-base. … | Oct 01, 2026 |
| CVE-2026-51886 | UNKNOWN | — | langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-a-real-authenticated-http-post-to-api-v1. The attack vector is: Attack surface: … | Oct 01, 2026 |
| CVE-2026-51884 | UNKNOWN | — | The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to … | Oct 01, 2026 |
| CVE-2026-51883 | UNKNOWN | — | The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as … | Oct 01, 2026 |
| CVE-2026-51882 | UNKNOWN | — | The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the `openai_files` … | Oct 01, 2026 |
| CVE-2026-51881 | UNKNOWN | — | deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to execute reviewer-chosen shell … | Oct 01, 2026 |
| CVE-2026-51880 | UNKNOWN | — | deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to write … | Oct 01, 2026 |
| CVE-2026-51879 | UNKNOWN | — | deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.write_bot_file. A remote caller can enumerate bot IDs and overwrite another bot's whitelisted … | Oct 01, 2026 |
| CVE-2026-51878 | UNKNOWN | — | deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TurnRuntimeManager.regenerate_last_turn. A remote caller can enumerate or obtain a session_id and trigger regenerate … | Oct 01, 2026 |
| CVE-2026-51876 | UNKNOWN | — | DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can reuse a publicly exposed book_id to submit … | Oct 01, 2026 |
| CVE-2026-51875 | UNKNOWN | — | In Devika v1.0, the Feature Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace, potentially … | Oct 01, 2026 |
| CVE-2026-51874 | UNKNOWN | — | In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace. | Oct 01, 2026 |
| CVE-2026-51873 | UNKNOWN | — | Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside the intended project workspace. | Oct 01, 2026 |
| CVE-2026-34494 | UNKNOWN | — | - On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before … | Oct 01, 2026 |
| CVE-2026-34493 | UNKNOWN | — | - On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63. | Oct 01, 2026 |
| CVE-2026-27873 | UNKNOWN | — | - Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52. | Oct 01, 2026 |
| CVE-2026-18397 | UNKNOWN | — | This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the … | Oct 01, 2026 |
| CVE-2026-104356 | MEDIUM | 5.9 | PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in … | Oct 01, 2026 |
| CVE-2026-104051 | HIGH | 8.2 | PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoint … | Oct 01, 2026 |
| CVE-2026-104002 | MEDIUM | 5.3 | A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that … | Oct 01, 2026 |
| CVE-2026-96780 | UNKNOWN | — | figlet.js is a FIG driver written in JavaScript that aims to implement the FIGfont specification. Prior to 1.11.3, text() and textSync() can enter an unbounded … | Oct 01, 2026 |
| CVE-2026-71451 | UNKNOWN | — | - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63. | Oct 01, 2026 |