CVE search
401,046 resultsCVE-2026-93495HIGHImproper initialization in an ASUS certain motherboard allows an physically proximate user to read or write arbitrary memory by inserting a EPSS 0.2%CVE-2026-103532MEDIUMimmich-app Immich Shared Link Preview access.ts checkSharedLinkAccess improper authorizationEPSS 0.3%CVE-2026-103531MEDIUMOpenSC card-setcos.c setcos_construct_fci_44 stack-based overflowEPSS 0.2%CVE-2026-51876—DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can EPSS 0.2%CVE-2026-51892—infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>.EPSS 0.2%CVE-2026-51881—deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tEPSS 0.2%CVE-2026-51884—The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafEPSS 0.2%CVE-2026-51896—infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attackeEPSS 0.1%CVE-2026-51894—infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or teEPSS 0.1%CVE-2026-51888—langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storaEPSS 0.2%CVE-2026-51895MEDIUMRagflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, aEPSS 0.2%CVE-2026-51886—langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/baEPSS 0.2%CVE-2026-51873—Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside tEPSS 0.3%CVE-2026-51874—In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write filesEPSS 0.2%CVE-2026-51875—In Devika v1.0, the Feature Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write filesEPSS 0.1%CVE-2026-51882—The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write fiEPSS 0.1%CVE-2026-51883—The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker caEPSS 0.1%CVE-2026-51897—RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trEPSS 0.3%CVE-2026-51879—deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.write_bot_file. A remote calEPSS 0.2%CVE-2026-51878—deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TurnRuntimeManager.regenerate_last_turn. A rEPSS 0.2%