Common Vulnerabilities and Exposures (CVE)

CVE-2026-19000

Aug 6, 2026 05:15:08 UTC

A vulnerability was identified in JeecgBoot up to 3.9.2. The affected element is an unknown function of the file /airag/chat/send of the component Anonymous Chat Attachment Parser. The manipulation leads to server-side request forgery. The ...

CVE-2026-18998

Aug 6, 2026 04:45:09 UTC

A vulnerability was determined in cosmicstack-labs mercury-agent up to 1.1.12. Impacted is the function SubAgent.run of the file src/core/sub-agent.ts of the component delegate_task Tool. Executing a manipulation can lead to improper author...

CVE-2026-18997

Aug 6, 2026 04:30:10 UTC

A vulnerability was found in cosmicstack-labs mercury-agent up to 1.1.12. This issue affects the function Agent.handleBgCommand of the file src/core/agent.ts of the component bg Command Handler. Performing a manipulation results in incorrec...

CVE-2026-15459

Aug 6, 2026 04:26:51 UTC

The WPMU DEV Dashboard plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 5.0.0. On sites not yet connected to the WPMU DEV Hub — the default state after installation — the site API key that ke...

CVE-2026-18996

Aug 6, 2026 04:15:09 UTC

A vulnerability has been found in cosmicstack-labs mercury-agent up to 1.1.12. This vulnerability affects the function PermissionManager.checkShellCommand of the file src/capabilities/permissions.ts of the component run_command Handler. Suc...

CVE-2026-18995

Aug 6, 2026 04:00:11 UTC

A flaw has been found in netease-youdao LobsterAI 2026.6.10. This affects the function parseMediaTokensFromText of the file src/renderer/services/artifactParser.ts of the component MEDIA Path Handler. This manipulation causes information di...

CVE-2026-17624

Aug 6, 2026 03:56:00 UTC

IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary c...

CVE-2026-17633

Aug 6, 2026 03:55:59 UTC

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection.

CVE-2026-17632

Aug 6, 2026 03:55:58 UTC

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning.

CVE-2026-9196

Aug 6, 2026 03:55:57 UTC

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python...

CVE-2026-8182

Aug 6, 2026 03:55:56 UTC

IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests.

CVE-2026-9201

Aug 6, 2026 03:55:54 UTC

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to...

CVE-2026-18485

Aug 6, 2026 03:55:53 UTC

There is a local privilege escalation vulnerability recently discovered in the NI-PAL kernel driver.  This may allow a local, authenticated user to escalate privileges and execute arbitrary code.  This vulnerability affects NI-PAL 26.3.1 an...

CVE-2026-8478

Aug 6, 2026 03:55:52 UTC

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code.

CVE-2026-9205

Aug 6, 2026 03:55:51 UTC

IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function.