Common Vulnerabilities and Exposures (CVE)

CVE-2026-72996

Sep 12, 2026 03:55:54 UTC

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-73007

Sep 12, 2026 03:55:53 UTC

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83985

Sep 12, 2026 03:55:52 UTC

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-9176

Sep 12, 2026 03:55:51 UTC

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected res...

CVE-2026-86093

Sep 12, 2026 03:55:50 UTC

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improp...

CVE-2026-84889

Sep 12, 2026 03:55:49 UTC

IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper limitation of a pathname to a restricted directory.

CVE-2026-81940

Sep 12, 2026 03:55:48 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

CVE-2026-81941

Sep 12, 2026 03:55:47 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools...

CVE-2026-81211

Sep 12, 2026 03:55:46 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.

CVE-2026-81204

Sep 12, 2026 03:55:45 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

CVE-2026-79742

Sep 12, 2026 03:55:44 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.

CVE-2026-79724

Sep 12, 2026 03:55:43 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary OS commands due to improper neutralization of special elements used in an OS command.

CVE-2026-70341

Sep 12, 2026 03:55:41 UTC

Use after free in Microsoft Edge (Chromium-based) allows an authorized attacker to execute code over a network.

CVE-2026-78575

Sep 12, 2026 03:55:40 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.

CVE-2026-78571

Sep 12, 2026 03:55:39 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.