The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2024-1310 - The WooCommerce WordPress plugin before 8.6 does not prevent users with at least the contributor role from leaking products they shouldn't have access to. (e.g. private, draft and trashed products)
Published: April 15, 2024; 1:15:14 AM -0400 -
CVE-2026-57968 - Buffer over-read in Windows Subsystem for Linux allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 2:18:35 PM -0400 -
CVE-2026-57973 - Time-of-check time-of-use (toctou) race condition in Windows Subsystem for Linux allows an authorized attacker to perform tampering locally.
Published: July 14, 2026; 2:18:35 PM -0400V3.1: 4.7 MEDIUM
-
CVE-2026-57982 - Use of uninitialized resource in Windows RDP allows an authorized attacker to disclose information over a network.
Published: July 14, 2026; 2:18:36 PM -0400 -
CVE-2026-58527 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Runtime allows an authorized attacker to elevate privileges locally.
Published: July 14, 2026; 2:18:39 PM -0400V3.1: 7.0 HIGH
-
CVE-2026-58528 - Out-of-bounds read in Windows USB Audio Class driver (usbaudio.sys) allows an unauthorized attacker to disclose information with a physical attack.
Published: July 14, 2026; 2:18:39 PM -0400V3.1: 4.6 MEDIUM
-
CVE-2026-58530 - Heap-based buffer overflow in Windows Resilient File System (ReFS) allows an unauthorized attacker to execute code locally.
Published: July 14, 2026; 2:18:39 PM -0400V3.1: 7.8 HIGH
-
CVE-2026-58531 - Concurrent execution using shared resource with improper synchronization ('race condition') in Windows SMB allows an authorized attacker to elevate privileges over a network.
Published: July 14, 2026; 2:18:39 PM -0400 -
CVE-2026-9103 - IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper authentication in the /api/v1/login/auto_login endpoint. The endpoint issues long-lived superuser bearer tokens without requiring authe... read CVE-2026-9103
Published: July 17, 2026; 3:17:19 PM -0400 -
CVE-2026-9135 - IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32d) contain a code injection vulnerability in the Policies component's ToolGuard integration that bypasses the allow_custom_component... read CVE-2026-9135
Published: July 17, 2026; 3:17:19 PM -0400 -
CVE-2026-13448 - IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability in the public flow build endpoint ( /api/v1/build_public_tmp/{flow_id}/flow ). The vulnerability stems from an incomplete denylist in... read CVE-2026-13448
Published: July 17, 2026; 4:17:14 PM -0400V3.1: 9.8 CRITICAL
-
CVE-2026-14499 - IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands with elevated privileges on the system due to improper validation of user supplied input in the Python Interpreter component.
Published: July 17, 2026; 4:17:14 PM -0400 -
CVE-2026-7667 - IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an attacker-controlled URL that returns a specially crafted Content-Disposition header (e.g., filename="../../../target/path" ), enabling... read CVE-2026-7667
Published: July 17, 2026; 4:17:29 PM -0400 -
CVE-2026-7754 - IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure default configuration and incomplete enforcement of the SSRF protection mechanism.
Published: July 17, 2026; 4:17:29 PM -0400V3.1: 6.5 MEDIUM
-
CVE-2026-7755 - IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enforcement on MCP server configuration files.
Published: July 17, 2026; 4:17:30 PM -0400 -
CVE-2026-8481 - IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation API endpoint. The POST /api/v1/validate/code endpoint accepts user-supplied Python code and executes it directly using Python's bui... read CVE-2026-8481
Published: July 17, 2026; 4:17:30 PM -0400V3.1: 9.9 CRITICAL
-
CVE-2026-7872 - IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT signing key and forge authentication tokens for any user.
Published: July 17, 2026; 4:17:30 PM -0400V3.1: 8.1 HIGH
-
CVE-2026-8056 - IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via the API. A critical security flaw exists in the parameter filtering mechanism within the `apply_tweaks()` function.
Published: July 17, 2026; 4:17:30 PM -0400 -
CVE-2026-8505 - IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthenticated users to trigger the execution of any flow. The system incorrectly bypasses API key validation when the WEBHOOK_AUTH_ENABLE... read CVE-2026-8505
Published: July 17, 2026; 4:17:31 PM -0400 -
CVE-2026-8476 - IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based caching mechanism. The AsyncDiskCache class uses Python's unsafe pickle.loads() function to deserialize cached objects from disk without... read CVE-2026-8476
Published: July 17, 2026; 4:17:30 PM -0400