The NVD is the U.S. government repository of standards based vulnerability management data represented using the Security Content Automation Protocol (SCAP). This data enables automation of vulnerability management, security measurement, and compliance. The NVD includes databases of security checklist references, security-related software flaws, product names, and impact metrics.
For information on how to cite the NVD, including the database's Digital Object Identifier (DOI), please consult NIST's Public Data Repository.
Legal Disclaimer:
Here is where you can read the NVD legal disclaimer.
-
CVE-2026-60580 - Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows unauthenticated attacker with access to ... read CVE-2026-60580
Published: 七月 21, 2026; 6:17:58 下午 -0400 -
CVE-2026-60581 - Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Difficult to exploit vulnerability allows unauthenticated attacker with access t... read CVE-2026-60581
Published: 七月 21, 2026; 6:17:58 下午 -0400 -
CVE-2026-60582 - Vulnerability in the Oracle Enterprise Command Center Framework product of Oracle E-Business Suite (component: Core). The supported version that is affected is V16. Easily exploitable vulnerability allows low privileged attacker with network acc... read CVE-2026-60582
Published: 七月 21, 2026; 6:17:58 下午 -0400 -
CVE-2026-12940 - IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment variable injection in the MCP (Model Context Protocol) stdio launcher. The vulnerability exists in src/lfx/src/lfx/base/mcp/util.py wher... read CVE-2026-12940
Published: 七月 30, 2026; 1:16:28 下午 -0400 -
CVE-2026-12945 - IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs through improper access control on log retrieval and unauthenticated build endpoints.
Published: 七月 30, 2026; 1:16:28 下午 -0400 -
CVE-2026-10700 - IBM Langflow OSS 1.0.0 through 1.8.4 contains multiple broken access control vulnerabilities in its file handling API that allow unauthorized access to user files.The /api/v1/files/images/{flow_id}/{file_name} endpoint does not enforce authenticat... read CVE-2026-10700
Published: 七月 30, 2026; 3:17:02 下午 -0400 -
CVE-2026-12942 - IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
Published: 七月 30, 2026; 3:17:05 下午 -0400V3.1: 7.5 HIGH
-
CVE-2026-13435 - IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implementation.
Published: 七月 30, 2026; 3:17:06 下午 -0400 -
CVE-2026-13444 - IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by creating their own flow with matching Chroma persist_directory and collection_name values. The attacker receives exact victim content ... read CVE-2026-13444
Published: 七月 30, 2026; 3:17:06 下午 -0400 -
CVE-2026-12946 - IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.
Published: 七月 30, 2026; 4:16:52 下午 -0400 -
CVE-2026-13442 - IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owner-only vector content and influence later query results. This causes cross-user information disclosure and limited integrity impact t... read CVE-2026-13442
Published: 七月 28, 2026; 5:17:25 下午 -0400 -
CVE-2026-34486 - Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.53, 9.0.116. Users are recommended to upgrade to... read CVE-2026-34486
Published: 四月 09, 2026; 4:16:25 下午 -0400 -
CVE-2026-9198 - IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow de... read CVE-2026-9198
Published: 七月 17, 2026; 2:17:17 下午 -0400 -
CVE-2026-18556 - Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
Published: 八月 01, 2026; 4:16:37 下午 -0400V3.1: 7.4 HIGH
-
CVE-2026-61055 - Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with logon to the ... read CVE-2026-61055
Published: 七月 21, 2026; 6:18:36 下午 -0400 -
CVE-2026-61056 - Vulnerability in the PeopleSoft Enterprise FIN Grants product of Oracle PeopleSoft (component: Grants). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network access via HTT... read CVE-2026-61056
Published: 七月 21, 2026; 6:18:36 下午 -0400 -
CVE-2026-61057 - Vulnerability in the PeopleSoft Enterprise FIN eSettlements product of Oracle PeopleSoft (component: eSettlements). The supported version that is affected is 9.2. Difficult to exploit vulnerability allows unauthenticated attacker with network ac... read CVE-2026-61057
Published: 七月 21, 2026; 6:18:36 下午 -0400 -
CVE-2026-61059 - Vulnerability in the PeopleSoft Enterprise SCM Order Management product of Oracle PeopleSoft (component: Security). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network acce... read CVE-2026-61059
Published: 七月 21, 2026; 6:18:36 下午 -0400 -
CVE-2026-61060 - Vulnerability in the Oracle E-Business Suite Secure Enterprise Search product of Oracle E-Business Suite (component: Search Integration Engine). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low ... read CVE-2026-61060
Published: 七月 21, 2026; 6:18:36 下午 -0400 -
CVE-2026-61061 - Vulnerability in the Oracle JDeveloper product of Oracle Fusion Middleware (component: Security Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Difficult to exploit vulnerability allows low privileged attacker wit... read CVE-2026-61061
Published: 七月 21, 2026; 6:18:36 下午 -0400