Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.6 CVE-2026-10140

Cross-Tenant API Key Reuse and Billing Fraud in Langflow Voice Mode Subsystem_CVE-2026-10140

IBM Langflow OSS 1.0.0 through 1.10.0 voice mode contains improper shared-state handling that allows reuse of API clients across tenant boundaries....

IBM Langflow OSS 1.0.0 CVE
CRITICAL 10 CVE-2026-10134

Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows_CVE-2026-10134

IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, convers...

IBM Langflow OSS 1.0.0 CVE
HIGH 8.5 CVE-2026-10129

SSRF via HTTP Redirect Following in Langflow API Request Component_CVE-2026-10129

IBM Langflow OSS 1.0.0 through 1.9.3 contains a Server-Side Request Forgery (SSRF) protection bypass vulnerability in the API Request component. An...

IBM Langflow OSS 1.0.0-1.9.3 CVE
CRITICAL 9.8 CVE-2026-10109

IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling_CVE-2026-10109

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.

IBM Db2 11.5.0 CVE
MEDIUM 5.5 CVE-2025-36372

IBM® Db2® could disclose sensitive information to an authenticated user from the monitoring and event tables_CVE-2025-36372

IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 for Linux, UNIX and Windows (includes Db2 Connect Server) could disclose sensitive informa...

IBM Db2 11.5.0 CVE
MEDIUM 6 CVE-2026-9132

Missing authorization vulnerability in GitHub Enterprise Server allowed disclosure of private repository contents via the Copilot pull request diff summary endpoint_CVE-2026-9132

A missing authorization vulnerability was identified in GitHub Enterprise Server that allowed an authenticated user to read source code from privat...

GitHub Enterprise Server 3.17.0 CVE
MEDIUM 4.8 CVE-2026-9106

UI misrepresentation vulnerability in GitHub Enterprise Server allowed unauthorized organization runner management via undisclosed OAuth scope on consent screen_CVE-2026-9106

A UI misrepresentation vulnerability was identified in GitHub Enterprise Server that allowed an OAuth application to gain unintended access to an o...

GitHub Enterprise Server 3.16.0 CVE
HIGH 8.7 CVE-2026-44628

OFFIS DCMTK Toolkit Type Confusion_CVE-2026-44628

An unauthenticated attacker can crash the worklist server with a single crafted query when the server has a valid Called AE Title / storage directo...

OFFIS DICOM DCMTK Toolkit CVE
HIGH 8.7 CVE-2026-13207

Frangoteam FUXA SCADA/HMI Authentication Bypass by Spoofing_CVE-2026-13207

FUXA versions 1.3.1 and prior contain an authentication bypass vulnerability via dot-segment path normalization in the REST API. The API router fai...

Frangoteam FUXA SCADA/HMI 1.3.1 CVE
HIGH 8.5 CVE-2026-11594

IBM WebSphere Application Server is affected by multiple cross-site scripting vulnerabilities_CVE-2026-11594

IBM WebSphere Application Server 9.0, and 8.5 is affected by a cross-site scripting vulnerability in the administrative console.

IBM WebSphere Application Server 9.0 CVE