Common Vulnerabilities and Exposures (CVE)

CVE-2026-73007

Sep 12, 2026 03:55:53 UTC

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-83985

Sep 12, 2026 03:55:52 UTC

Heap-based buffer overflow in Windows Biometric Service allows an authorized attacker to elevate privileges locally.

CVE-2026-9176

Sep 12, 2026 03:55:51 UTC

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to a security bypass due to improper authentication controls. A local attacker could exploit this vulnerability to escalate privileges and gain unauthorized access to protected res...

CVE-2026-86093

Sep 12, 2026 03:55:50 UTC

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 could allow an attacker with the ability to control or impersonate a DRDA server endpoint to execute arbitrary commands on Db2 clients due to a stack-based buffer overflow that improp...

CVE-2026-81940

Sep 12, 2026 03:55:48 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to improper neutralization of special characters in flow display names.

CVE-2026-81941

Sep 12, 2026 03:55:47 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 allows an authenticated non-administrative user could execute arbitrary operating system commands on the server at the privilege level of the application process by constructing a flow with an MCP Tools...

CVE-2026-81211

Sep 12, 2026 03:55:46 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary Python code due to improper authorization of custom components in stored flows.

CVE-2026-81204

Sep 12, 2026 03:55:45 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attacker to execute arbitrary code due to code injection during graph construction.

CVE-2026-79742

Sep 12, 2026 03:55:44 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an incomplete environment variable blocklist.

CVE-2026-78575

Sep 12, 2026 03:55:40 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.

CVE-2026-78571

Sep 12, 2026 03:55:39 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary code due to an unguarded eval() call on attacker-controlled input.

CVE-2026-4130

Sep 12, 2026 03:55:27 UTC

There is a storage of sensitive information in cleartext vulnerability in NI SystemLink. This vulnerability may allow an attacker with local access to obtain sensitive information stored by the system in the clear.  This vulnerability affec...

CVE-2026-4129

Sep 12, 2026 03:55:26 UTC

There is an improper access control vulnerability in NI SystemLink that may allow an authenticated user with limited privileges to access host operating system files and directories that should be restricted. This vulnerability affects NI S...

CVE-2026-85025

Sep 12, 2026 03:55:25 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 Langflow could allow an unauthenticated attacker to execute arbitrary code and access or modify chat sessions through publicly shared MCP project endpoints due to improper enforcement of public-flow sec...

CVE-2026-81268

Sep 12, 2026 03:55:23 UTC

IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute flows and obtain sensitive information due to insufficient session expiration of API keys after user deactivation.