| CVE-2026-18729 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to | 8d ago |
| CVE-2026-9201 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryp | 31d ago |
| CVE-2026-8478 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to | 31d ago |
| CVE-2026-8182 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the s | 31d ago |
| CVE-2026-17632 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to | 31d ago |
| CVE-2026-17626 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose se | 31d ago |
| CVE-2026-17623 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands du | 31d ago |
| CVE-2026-8056 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via th | 50d ago |
| CVE-2026-7755 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enfor | 50d ago |
| CVE-2026-7667 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an at | 50d ago |
| CVE-2026-14499 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands wit | 50d ago |
| CVE-2026-33760 | 8.8 | high | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2026-33053 | 8.8 | high | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 169d ago |
| CVE-2026-17633 | 8.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to | 31d ago |
| CVE-2026-17624 | 8.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 thr | 31d ago |
| CVE-2026-9077 | 8.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restr | 31d ago |
| CVE-2026-10129 | 8.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability | 67d ago |
| CVE-2026-55255exploited | 8.4 | high | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2026-18904 | 8.2 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject una | 8d ago |
| CVE-2026-18891 | 8.2 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitiv | 8d ago |
| CVE-2026-10564 | 8.2 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). | 67d ago |
| CVE-2026-10560 | 8.2 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ | 67d ago |
| CVE-2026-9196 | 8.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agent | 31d ago |
| CVE-2026-13444 | 8.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by c | 37d ago |
| CVE-2026-13445 | 8.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to r | 50d ago |
| CVE-2026-13448 | 8.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability | 50d ago |
| CVE-2026-8183 | 7.7 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 thro | 31d ago |
| CVE-2026-7754 | 7.7 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow 1.9.0 could allow server-side request forgery (SSRF) due to insecure | 50d ago |
| CVE-2026-18899 | 7.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal. | 8d ago |
| CVE-2026-19875 | 7.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information a | 17d ago |
| CVE-2026-8446 | 7.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authentication bypass vulnerability in the Model Context Protocol | 31d ago |
| CVE-2026-12942 | 7.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 could allow a remote attacker to traverse directories on the system. | 37d ago |
| CVE-2026-7872 | 7.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to read arbitrary files including the JWT si | 50d ago |
| CVE-2026-55446 | 7.5 | high | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2026-7787 | 7.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by b | 86d ago |
| CVE-2026-33497 | 7.5 | high | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 165d ago |
| CVE-2026-33484 | 7.5 | high | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 165d ago |
| CVE-2026-9205 | 7.4 | high | langflow / langflow | IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. | 31d ago |
| CVE-2026-8470 | 7.4 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Pyt | 31d ago |
| CVE-2026-17625 | 7.2 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 thr | 31d ago |
| CVE-2026-17630 | 7.2 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to execute arbitrary code due to improper vali | 31d ago |
| CVE-2026-9130 | 7.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that all | 31d ago |
| CVE-2026-9081 | 7.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulne | 31d ago |
| CVE-2026-12945 | 7.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 allows authenticated users to access and manipulate other users' build jobs | 37d ago |
| CVE-2026-13442 | 7.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to reuse another user's FAISS namespace to access owne | 39d ago |
| CVE-2026-10546 | 7.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the URL compon | 67d ago |
| CVE-2026-7528 | 7.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption. | 101d ago |