51 CVEs — updated 2026-08-04 · vulnfeed
| CVE / ID | Title | Severity | CVSS | EPSS | Source | Date |
|---|---|---|---|---|---|---|
| CVE-2026-64633 | A vulnerability allowing remote unauthenticated code execution on the agent host. | CRITICAL | 10.0 | — | NVD | 2026-08-04 |
| CVE-2026-13435 | IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox impl | CRITICAL | 9.9 | 21%ile | NVD | 2026-07-30 |
| CVE-2026-12946 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the i | CRITICAL | 9.9 | 27%ile | NVD | 2026-07-30 |
| CVE-2026-13423 | The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauth | CRITICAL | 9.8 | 42%ile | NVD | 2026-07-29 |
| CVE-2026-14900 | The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and i | CRITICAL | 9.8 | 49%ile | NVD | 2026-07-29 |
| CVE-2026-17561 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Cons | CRITICAL | 9.8 | 24%ile | NVD | 2026-07-31 |
| CVE-2026-51785 | An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted req | CRITICAL | 9.8 | 64%ile | NVD | 2026-07-31 |
| CVE-2024-3660 | Arbitrary code injection vulnerability in Keras framework < 2.13 | CRITICAL | 9.8 | 76%ile | Microsoft | 2024-04-09 |
| CVE-2026-69254 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScri | CRITICAL | 9.4 | — | NVD | 2026-08-04 |
| CVE-2026-69256 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent no | CRITICAL | 9.4 | — | NVD | 2026-08-04 |
| CVE-2026-69259 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Reco | CRITICAL | 9.4 | — | NVD | 2026-08-04 |
| CVE-2026-68770 | sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code e | CRITICAL | 9.3 | 41%ile | NVD | 2026-07-31 |
| CVE-2026-67340 | ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) b | CRITICAL | 9.3 | 42%ile | NVD | 2026-08-01 |
| CVE-2026-18667 | A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing an | CRITICAL | 9.3 | 29%ile | NVD | 2026-08-03 |
| CVE-2026-69255 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in | CRITICAL | 9.2 | — | NVD | 2026-08-04 |
| CVE-2026-14602 | The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, al | CRITICAL | 9.0 | 42%ile | NVD | 2026-07-30 |
| CVE-2026-69251 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record | CRITICAL | 9.0 | — | NVD | 2026-08-04 |
| CVE-2026-69253 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1 | CRITICAL | 9.0 | — | NVD | 2026-08-04 |
| CVE-2026-11393 | AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote Escaping | HIGH | 9.0 | 25%ile | GitHub | 2026-07-29 |
| CVE-2026-54653 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch | HIGH | 8.8 | 28%ile | NVD | 2026-07-28 |
| CVE-2026-17922 | Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute | HIGH | 8.8 | 33%ile | NVD | 2026-07-30 |
| CVE-2026-14380 | DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced Profile | HIGH | 8.8 | 39%ile | Microsoft | 2026-07-14 |
| CVE-2026-16881 | A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering component | HIGH | 8.7 | 18%ile | NVD | 2026-08-04 |
| CVE-2026-69100 | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability i | HIGH | 8.7 | — | NVD | 2026-08-04 |
| CVE-2026-69088 | Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprint | HIGH | 8.6 | 14%ile | NVD | 2026-08-03 |
| CVE-2026-61523 | WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticated | HIGH | 8.6 | 47%ile | NVD | 2026-08-03 |
| CVE-2026-58074 | A vulnerability allowing a high-privileged user to execute arbitrary code on the server. | HIGH | 8.6 | — | NVD | 2026-08-04 |
| CVE-2026-66065 | Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to | HIGH | 8.4 | 22%ile | NVD | 2026-08-03 |
| CVE-2026-54661 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templat | HIGH | 8.3 | 19%ile | NVD | 2026-07-29 |
| CVE-2026-54662 | swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code- | HIGH | 8.3 | 19%ile | NVD | 2026-07-29 |
| CVE-2026-54664 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch | HIGH | 8.3 | 19%ile | NVD | 2026-07-29 |
| CVE-2026-54666 | swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/sch | HIGH | 8.3 | 21%ile | NVD | 2026-07-29 |
| CVE-2026-53510 | Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDL | HIGH | 8.1 | 32%ile | NVD | 2026-07-31 |
| CVE-2026-16144 | The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in all | HIGH | 8.1 | 49%ile | NVD | 2026-08-01 |
| CVE-2026-18107 | A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process insid | HIGH | 7.8 | 2%ile | NVD | 2026-07-28 |
| CVE-2026-54621 | datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union descriptio | HIGH | 7.8 | 4%ile | NVD | 2026-07-28 |
| CVE-2026-54654 | datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-tem | HIGH | 7.8 | 4%ile | NVD | 2026-07-28 |
| CVE-2026-54655 | datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type v | HIGH | 7.8 | 4%ile | NVD | 2026-07-28 |
| CVE-2026-54656 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch | HIGH | 7.8 | 5%ile | NVD | 2026-07-28 |
| CVE-2026-55895 | Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filename | HIGH | 7.8 | 5%ile | Microsoft | 2026-06-09 |
| CVE-2026-66745 | Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability t | HIGH | 7.5 | 24%ile | NVD | 2026-07-28 |
| CVE-2026-55415 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Sch | HIGH | 7.5 | 20%ile | NVD | 2026-07-28 |
| CVE-2026-61536 | Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool J | HIGH | 7.5 | 22%ile | NVD | 2026-07-30 |
| CVE-2026-13392 | The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by a | HIGH | 7.2 | 30%ile | NVD | 2026-07-31 |
| CVE-2026-9198 | IBM Langflow Code Injection Vulnerability | HIGH | — | 78%ile | CISA-KEV | 2026-08-04 |
| CVE-2026-18245 | Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authentic | MEDIUM | 6.4 | 41%ile | NVD | 2026-07-30 |
| CVE-2026-65804 | Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized atta | MEDIUM | 6.1 | 35%ile | NVD | 2026-08-04 |
| CVE-2026-18770 | A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an un | MEDIUM | 5.5 | — | NVD | 2026-08-04 |
| CVE-2026-18682 | A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /api | LOW | 1.3 | 16%ile | NVD | 2026-08-03 |
| CVE-2026-47162 | Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name | UNKNOWN | — | 12%ile | Microsoft | 2026-06-09 |
| CVE-2026-47167 | Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex | UNKNOWN | — | 3%ile | Microsoft | 2026-06-09 |