2026-06-30
2026-06-30 20:17Z
CRIT

CVE-2026-10140 — IBM: Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10140

IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries. An authenticated attacker can manipulate cache state to cause requests from other users to be processed using incorrect upstream API credentials, leading to cross-tenant billing and accountability misattribution. CVSSv3.1 9.6 (CRITICAL)

CWECWE 639VNDIbmTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 20:17Z
CRIT

CVE-2026-10134 — IBM: Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10134

IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata endpoints, laterally move to other tenants on the same Langflow instance, and Establish persistence by modifying the public flow's `tool_code` so normal `/api/v1/build/...` calls by any user re-execute a CVSSv3.1 10.0 (CRITICAL)

CWECWE 94VNDIbmTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-30
2026-06-30 20:17Z
HIGH

CVE-2026-10129 — IBM: Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10129

IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in the API Request component. An authenticated attacker with low-level privileges (flow author role) can bypass SSRF protections by enabling the follow_redirects parameter and supplying a public URL that redirects to internal/localhost addresses. The vulnerability exists because the application validates only the initial URL but does not re-validate redirect dest CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDIbmTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-30
2026-06-30 20:17Z
CRIT

CVE-2026-10109 — IBM: Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-10109

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDIbmTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 19:35Z
HIGH

CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)

watchTowr Labs·labs.watchtowr.comCVE-2026-8451

watchTowr Labs disclosed CVE-2026-8451, a pre-authentication memory overread vulnerability in Citrix NetScaler affecting SAML IdP configurations. The flaw stems from improper XML attribute parsing that fails to correctly terminate unquoted values on newlines, allowing attackers to read arbitrary adjacent memory. This is the latest in a recurring class of memory disclosure vulnerabilities (CitrixBleed) affecting NetScaler appliances, with CVSS 8.8 and impact on versions 14.1 and 13.1 before specific patch levels.

TACTA0001SRFNetwork ApplianceSRFWebSWNetscalerVNDCitrixTYPResearchTYPVulnerabilitySTGInitial Access
82
Edit Score
2026-06-30
2026-06-30 19:17Z
CRIT

CVE-2026-58138 — Orkes: Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58138

Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API endpoint prior to authentication. Attackers can exploit unsandboxed GraalVM evaluators configured with HostAccess.ALL or allowAllAccess(true) through INLINE, LAMBDA, DO_WHILE, and SWITCH task types to CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDOrkesTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-30
2026-06-30 17:16Z
HIGH

CVE-2026-58377 — JeecgBoot: through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58377

JeecgBoot through 3.9.2 contains a broken access control vulnerability that allows authenticated low-privilege users to perform full create, read, update, and delete operations on OpenAPI credentials by accessing the OpenApiAuthController and OpenApiPermissionController endpoints which lack Shiro authorization annotations. Attackers can exploit the unenforced access controls to list, add, edit, and delete all AK/SK credential pairs, with the list endpoint returning secret key CVSSv3.1 8.1 (HIGH)

CWECWE 862VNDJeecgbootTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-30
2026-06-30 17:16Z
HIGH

CVE-2026-58372 — SeaweedFS: before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58372

SeaweedFS before 4.34 contains a path traversal vulnerability in the S3 gateway DeleteMultipleObjectsHandler that allows authenticated S3 principals with write access to a single bucket to delete arbitrary objects in other tenants' buckets by supplying object keys containing ../ sequences in the DeleteObjects XML request body. Attackers can bypass authorization controls through a confused deputy condition, as the validateRequestPath middleware only inspects URL-captured path CVSSv3.1 8.1 (HIGH)

CWECWE 22VNDSeaweedfsTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 17:16Z
HIGH

CVE-2026-58370 — Woodpecker: before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58370

Woodpecker before 3.15.0 matches the ApprovalAllowedUsers bypass list against pipeline.Author. For the GitLab forge driver, pipeline.Author is populated from the git commit author name (commit.author.name) carried in the webhook payload, which is attacker-controlled and not verified by GitLab. A user who can open a merge request from a fork can set the commit author name to match an entry in ApprovalAllowedUsers, causing needsApproval to return false so the pipeline runs with CVSSv3.1 8.1 (HIGH)

CWECWE 290VNDWoodpeckerTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-30
2026-06-30 17:16Z
CRIT

CVE-2026-58172 — Ocelot: through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58172

Ocelot through 24.1.0, fixed in commit f156fd4, contains a security control bypass vulnerability that allows denied clients to circumvent IP-based access restrictions by sending WebSocket upgrade requests. The WebSocket upgrade pipeline branch configured via MapWhen in OcelotPipelineExtensions.cs omits SecurityMiddleware, causing requests from blocked IP addresses to be proxied to downstream services without enforcement of the configured allow/block list. CVSSv3.1 9.1 (CRITICAL)

CWECWE 288VNDOcelotTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-30
2026-06-30 17:16Z
HIGH

CVE-2026-58170 — Vibe: A proposal identifier containing path traversal sequences causes the application to load an attacker-controlled

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58170

Vibe-Trading before 0.1.10 builds the proposal file path by joining a caller-supplied proposal identifier onto the broker proposals directory without sanitization (agent/src/live/mandate/commit.py). A proposal identifier containing path traversal sequences causes the application to load an attacker-controlled JSON file as an authoritative live trading mandate. Combined with the file upload endpoint, an admitted caller can write a JSON file to a known location and traverse to CVSSv3.1 8.3 (HIGH)

CWECWE 22VNDVibeTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-30
2026-06-30 17:16Z
HIGH

CVE-2026-58168 — DeepTutor: before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58168

DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools is omitted from a user's grant in deeptutor/multi_user/tool_access.py. Attackers or prompt-injected content acting within a user session can enumerate and invoke any configured MCP tool, including filesystem, shell, and browser servers, gain CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDDeeptutorTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 17:16Z
CRIT

CVE-2026-58166 — OpenBMB: ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58166

OpenBMB ChatDev through 2.2.0, fixed in commit 4fd4da6, contains a path traversal vulnerability that allows unauthenticated remote attackers to write or delete arbitrary files by supplying a malicious multipart filename in the file upload endpoint. Attackers can send a crafted filename containing path traversal sequences or an absolute path to the POST uploads session endpoint, which constructs the destination path without sanitization in save_upload_file, causing file write CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDOpenbmbTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-30
2026-06-30 17:16Z
HIGH

CVE-2026-58165 — OpenZiti: through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-58165

OpenZiti through 2.0.0, fixed in commit 3027fdf, contains a privilege escalation vulnerability that allows authenticated non-admin identities with fine-grained enrollment management permissions to create enrollments for any identity, including the default administrator, because the ApplyCreate function in controller/model/enrollment_manager.go verifies only that the target identity exists without performing authorization checks binding the caller to the target identity. Attac CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDOpenzitiTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 16:16Z
CRIT

CVE-2026-48315 — Adobe Coldfusion: versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48315

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed. CVSSv3.1 9.3 (CRITICAL)

CWECWE 20VNDAdobeVNDColdfusionTYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-30
2026-06-30 16:16Z
CRIT

CVE-2026-48313 — Adobe Coldfusion: versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48313

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read and limited write access. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 9.3 (CRITICAL) · EPSS 90th percentile

CWECWE 22VNDAdobeVNDColdfusionTYPVulnerability
9.3
CVSS v3.1
98
Edit Score
2026-06-30
2026-06-30 16:16Z
HIGH

CVE-2026-48307 — Adobe Coldfusion: versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48307

ColdFusion versions 2025.9, 2023.20 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially resulting in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious link. Scope is changed. CVSSv3.1 8.8 (HIGH)

CWECWE 79VNDAdobeVNDColdfusionTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-30
2026-06-30 16:16Z
CRIT

CVE-2026-48286 — Adobe Campaign: Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48286

Adobe Campaign Classic (ACC) versions 7.4.3 build 9396 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 863VNDAdobeTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-30
2026-06-30 16:16Z
HIGH

CVE-2026-48285 — Adobe Coldfusion: versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48285

ColdFusion versions 2025.9, 2023.20 and earlier are affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to bypass security measures and gain unauthorized read access. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 8.6 (HIGH) · EPSS 58th percentile

CWECWE 918VNDAdobeVNDColdfusionTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-30
2026-06-30 16:16Z
CRIT

CVE-2026-48283 — Adobe Coldfusion: versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48283

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 434VNDAdobeVNDColdfusionTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-30
2026-06-30 16:16Z
CRIT

CVE-2026-48282 — Adobe Coldfusion: versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48282

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 22VNDAdobeVNDColdfusionTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-30
2026-06-30 16:16Z
CRIT

CVE-2026-48281 — Adobe Coldfusion: versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48281

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 20VNDAdobeVNDColdfusionTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-30
2026-06-30 16:16Z
CRIT

CVE-2026-48277 — Adobe Coldfusion: versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48277

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 20VNDAdobeVNDColdfusionTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-30
2026-06-30 16:16Z
CRIT

CVE-2026-48276 — Adobe Coldfusion: versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48276

ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Unrestricted Upload of File with Dangerous Type vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction. Scope is changed. CVSSv3.1 10.0 (CRITICAL)

CWECWE 434VNDAdobeVNDColdfusionTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-30
2026-06-30 14:16Z
CRIT

CVE-2026-14241 — Mozilla Firefox: Some of these bugs showed evidence of memory corruption and we presume that with

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-14241

Memory safety bugs present in Firefox 152.0.3. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability was fixed in Firefox 152.0.4. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDMozillaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score