Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-51888 — Langflow Directory Traversal Vulnerability

langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundary.. The component is: src/backend/base/langflow/a…

| Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51886 — Langflow Code Injection Vulnerability

langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflow/api/v1/validate.py:validate-post_validate_code-…

| Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51884 — Langchain Chatchat Path Traversal Vulnerability

The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malicious filenames, an attacker can write files to ar…

| Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51883 — Langchain-Chatchat Path Traversal

The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject path traversal sequences (such as `..\`) into the …

| Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51882 — Langchain-Chatchat Path Traversal Vulnerability

The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arbitrary locations outside the `openai_files` direc…

| Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51881 — Deeptutor Code Injection Vulnerability

deeptutor 1.4.0 contains code injection in ExecTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to execute reviewer-chosen shell commands in the …

| Injection
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51880 — DeepTutor Path Traversal Vulnerability

deeptutor 1.4.0 contains a path traversal issue in EditFileTool.execute. Through the live tutorbot WebSocket interface, a remote caller can induce the tool layer to write or edit absolute paths outsi…

| Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51879 — DeepTutor Authorization Bypass via Object Identifier Manipulation

deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TutorBotManager.write_bot_file. A remote caller can enumerate bot IDs and overwrite another bot's white…

| Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51878 — DeepTutor Authorization Bypass

deeptutor 1.4.0 contains an authorization bypass through a user-controlled object identifier in TurnRuntimeManager.regenerate_last_turn. A remote caller can enumerate or obtain a session_id and trigg…

| Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51876 — DeepTutor Authorization Bypass Vulnerability

DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can reuse a publicly exposed book_id to submit a confirm-propos…

| Authorization
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51875 — Devika Path Traversal Vulnerability

In Devika v1.0, the Feature Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace, potentially compro…

| Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51874 — Devika Path Traversal Vulnerability

In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside the intended project workspace.

| Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
0.0 NA
CVE-2026-51873 — Devika Directory Traversal Vulnerability

Devika v1.0 is vulnerable to Directory Traversal in the Coder.save_code_to_project function, which allows attackers to write files outside the intended project workspace.

| Path Traversal
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-34494 — Johnson Controls Neo Series MVP2 On-Chip Debug Interface Information Disclosure

- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63.

neo_series_mvp2 | Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
7.2 HIGH
CVE-2026-34493 — Johnson Controls EasyIO FS32 On-Chip Debug Interface Information Disclosure

- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63.

easyio_fs32 | Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
5.6 MEDIUM
CVE-2026-27873 — Johnson Controls EasyIO FG Hard-coded Credentials Vulnerability

- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.

easyio_fg | Authentication
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
9.4 CRITICAL
CVE-2026-18397 — SConnect: Native Host Unauthenticated Remote Code Execution Vulnerability

This vulnerability enables unauthenticated remote code execution (RCE) on a victim's machine by exploiting a combination of cryptographic weaknesses and memory management issues in the SConnect nativ…

Remote | Cryptography
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.2 HIGH
CVE-2026-104356 — PictShare < 3.7.1 Predictable Delete Code via rand()

PictShare before version 3.7.1 contains a weak randomness vulnerability where the getRandomString() function uses the non-cryptographic rand() PRNG to generate the delete_code authorization token in …

pictshare | Remote | Cryptography
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
8.8 HIGH
CVE-2026-104051 — PictShare < 3.7.1 Sensitive Information Disclosure via info API

PictShare before 3.7.1 contains an information disclosure vulnerability that allows unauthenticated attackers to obtain the secret delete_code and uploader metadata by calling the API::info() endpoin…

pictshare | Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
6.0 MEDIUM
CVE-2026-104002 — Fail-open error handling in the data masking utility in Powertools for AWS Lambda (Python)

A fail-open error handling issue within the data masking utility of Powertools for AWS Lambda (Python) might allow actors to read sensitive field values that the application intended to mask.  To …

Remote | Information Disclosure
Oct 01, 2026 Oct 01, 2026
Oct 01, 2026
Oct 01, 2026
Showing 20 of 14908 Results