CVE search

401,054 results
CVE-2026-51873—Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside tEPSS 0.3%CVE-2026-51897—RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trEPSS 0.3%CVE-2026-51884—The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafEPSS 0.2%CVE-2026-51886—langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/baEPSS 0.2%CVE-2026-51874—In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write filesEPSS 0.2%CVE-2026-51875—In Devika v1.0, the Feature Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write filesEPSS 0.1%CVE-2026-51883—The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker caEPSS 0.1%CVE-2026-51888—langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storaEPSS 0.2%CVE-2026-51896—infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attackeEPSS 0.1%CVE-2026-51881—deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tEPSS 0.2%CVE-2026-103530MEDIUMdecolua 9Router Search Endpoint ssrfGuard.js fetch server-side request forgeryEPSS 0.3%CVE-2026-103592MEDIUMsimple-php-router through 5.4.1.7 IP restriction bypass via forwarding headersEPSS 0.2%CVE-2026-103591HIGHDeepWiki-Open through commit d92819a Unauthenticated Arbitrary File Read via /codemap/fileEPSS 0.4%CVE-2026-103590MEDIUMQloApps through 1.7.0 Reflected XSS via Length of Stay FieldsEPSS 0.2%CVE-2026-103589MEDIUMQloApps through 1.7.0 Reflected XSS via Room Type EditorEPSS 0.2%CVE-2026-103588MEDIUMQloApps through 1.7.0 Reflected XSS via exceptions fieldEPSS 0.2%CVE-2026-103587MEDIUMQloApps through 1.7.0 Reflected XSS via Book Now Search ParametersEPSS 0.2%CVE-2026-103585LOWattacker-controlled javascript license URL via XSSEPSS 0.3%CVE-2026-103584LOWattacker-controlled javascript license URL via XSSEPSS 0.3%CVE-2026-47096MEDIUMAJA HELO Plus < 2.1.7 Stored XSS via System Name ParameterEPSS 0.2%