| CVE-2026-10134 | 10 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, re | 67d ago |
| CVE-2026-10561 | 10 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combine | 75d ago |
| CVE-2026-19295 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 allows an authenticated attacker to execute arbitrary operating system comma | 8d ago |
| CVE-2026-12946 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to | 37d ago |
| CVE-2026-13435 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbo | 37d ago |
| CVE-2026-8859 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow an attacker to write arbitrary files to unintended locat | 50d ago |
| CVE-2026-8635 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to escalate privileges to superuser by directly ma | 50d ago |
| CVE-2026-8481 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the code validation | 50d ago |
| CVE-2026-8476 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 contain a critical remote code execution vulnerability in the disk-based cach | 50d ago |
| CVE-2026-9135 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow versions up to 1.9.2 (commit 94981c443d4918517b9e8163d70fc598dc33a32 | 50d ago |
| CVE-2026-7873 | 9.9 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sens | 67d ago |
| CVE-2026-33309 | 9.9 | critical | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 165d ago |
| CVE-2026-19286 | 9.8 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enfo | 8d ago |
| CVE-2026-12940 | 9.8 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 are vulnerable to unauthenticated remote code execution via environment vari | 37d ago |
| CVE-2026-13446 | 9.8 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 contains hard-coded credentials, such as a password or cryptographic key, wh | 50d ago |
| CVE-2026-8505 | 9.8 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 has a vulnerability in Langflow's webhook authentication logic allows unauthe | 50d ago |
| CVE-2026-9103 | 9.8 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to gain unauthorized access due to improper aut | 50d ago |
| CVE-2026-9202 | 9.8 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to create unlimited user accounts on any Lan | 50d ago |
| CVE-2026-9198exploited | 9.8 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER | 50d ago |
| CVE-2026-7871 | 9.8 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows users with Redis access to execute arbitrary code with full applicatio | 67d ago |
| CVE-2026-7803 | 9.8 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 could allow arbitrary code execution due to improper validation of flow nodes | 67d ago |
| CVE-2026-7664 | 9.8 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resource | 75d ago |
| CVE-2026-7524 | 9.8 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links | 101d ago |
| CVE-2026-33017exploited | 9.8 | critical | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 170d ago |
| CVE-2026-10140 | 9.6 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API | 67d ago |
| CVE-2026-55447 | 9.6 | critical | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2026-48519 | 9.6 | critical | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2026-42048 | 9.6 | critical | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 116d ago |
| CVE-2026-55450 | 9.3 | critical | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2026-19297 | 9.1 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts | 23d ago |
| CVE-2026-7874 | 9.1 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow disclosure of all stored credentials due to the use of a | 67d ago |
| CVE-2026-7663 | 9.1 | critical | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.6 could allow unauthenticated attackers to access protected MCP project resource | 67d ago |
| CVE-2026-33475 | 9.1 | critical | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 165d ago |
| CVE-2026-18729 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to | 8d ago |
| CVE-2026-9201 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryp | 31d ago |
| CVE-2026-8478 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to | 31d ago |
| CVE-2026-8182 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the s | 31d ago |
| CVE-2026-17632 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to | 31d ago |
| CVE-2026-17626 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow an authenticated attacker to read, modify, or expose se | 31d ago |
| CVE-2026-17623 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands du | 31d ago |
| CVE-2026-8056 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated users to override component parameters at runtime via th | 50d ago |
| CVE-2026-7755 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 Langflow could allow remote code execution due to incomplete validation enfor | 50d ago |
| CVE-2026-7667 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.0 allows an authenticated attacker to create a malicious flow pointing to an at | 50d ago |
| CVE-2026-14499 | 8.8 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 Langflow could allow an authenticated user to execute arbitrary commands wit | 50d ago |
| CVE-2026-33760 | 8.8 | high | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2026-33053 | 8.8 | high | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 169d ago |
| CVE-2026-17633 | 8.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to | 31d ago |
| CVE-2026-17624 | 8.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 thr | 31d ago |
| CVE-2026-9077 | 8.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow allows remote authenticated attackers to bypass localhost-only restr | 31d ago |
| CVE-2026-10129 | 8.5 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability | 67d ago |
| CVE-2026-55255exploited | 8.4 | high | langflow / langflow | Langflow is a tool for building and deploying AI-powered agents and workflows. | 74d ago |
| CVE-2026-18904 | 8.2 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject una | 8d ago |
| CVE-2026-18891 | 8.2 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitiv | 8d ago |
| CVE-2026-10564 | 8.2 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.6 contains a Server-Side Request Forgery (SSRF). | 67d ago |
| CVE-2026-10560 | 8.2 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.9.6 contains a missing authentication vulnerability in /api/v1/build_public_tmp/ | 67d ago |
| CVE-2026-9196 | 8.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agent | 31d ago |
| CVE-2026-13444 | 8.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an attacker to access another user's private vector documents by c | 37d ago |
| CVE-2026-13445 | 8.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 can allow an authenticated attacker to exploit the SaveToFile component to r | 50d ago |
| CVE-2026-13448 | 8.1 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.1 Lanflow OSS contains an unauthenticated remote code execution vulnerability | 50d ago |
| CVE-2026-8183 | 7.7 | high | langflow / langflow | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 thro | 31d ago |