CVE-2026-78575: Schwachstellen-Eintrag (NVD)
IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticated attacker to execute arbitrary commands due to improper validation of command-line arguments in the MCP stdio server configuration.
Zero-Day & Vulnerability Intelligence Hub
Echtzeit-Tracking mit EPSS Exploit-Wahrscheinlichkeiten, Angriffsvektor-Decodern und KI-Patch-Anleitungen.
📊 Historien-Charts — Criticals-Trend · Vendors · EPSS-Verteilung
| Tier | 2026-08-29 | 2026-09-13 |
|---|---|---|
| ≥90 % | 4 | 0 |
| ≥50 % | 4 | 0 |
| ≥10 % | 3 | 0 |
| <10 % | 304 | 300 |
CVE-2026-11573 | Qt up to 6.8.1 QDomDocument recursion
A vulnerability identified as problematic has been detected in Qt up to 6.8.1. Affected by this issue is some unknown functionality of the component QDomDocument. Performing a manipulation results in uncontrolled recursion. This vulnerabili
CVE-2026-77089 | Commvault Command Center up to 11.36.122/11.40.71/11.44.19/11.46.19 authentication spoofing
A vulnerability was found in Commvault Command Center up to 11.36.122/11.40.71/11.44.19/11.46.19. It has been declared as critical. This impacts an unknown function. The manipulation results in authentication bypass by spoofing. This vulner
CVE-2026-86305 | light0011 cms Upload.class.php Upload::upload unrestricted upload
A vulnerability, which was classified as critical, has been found in light0011 cms c774dce31c6df0055568a8d5c53d964d99be199d/f72cf46f601efb2a0618c3814cc2f61380b38930. Affected by this issue is the function Upload::upload of the file ThinkPHP
CVE-2026-77098 | Commvault Cloud up to 11.36.122/11.40.71/11.44.19/11.46.19 Database Operations sql injection
A vulnerability was found in Commvault Cloud up to 11.36.122/11.40.71/11.44.19/11.46.19 and classified as critical. The impacted element is an unknown function of the component Database Operations. Executing a manipulation can lead to sql i
CVE-2026-77091 | Commvault Cloud up to 11.36.122/11.40.71/11.44.19/11.46.19 Content Extractor/Index Store path traversal
A vulnerability has been found in Commvault Cloud up to 11.36.122/11.40.71/11.44.19/11.46.19 and classified as problematic. The affected element is an unknown function of the component Content Extractor/Index Store. Performing a manipulatio
CVE-2026-77106 | Commvault up to 11.36.122/11.40.71/11.44.19/11.46.19 Cvlaunchd authorization
A vulnerability, which was classified as very critical, has been found in Commvault up to 11.36.122/11.40.71/11.44.19/11.46.19. This issue affects some unknown processing of the component Cvlaunchd. This manipulation causes missing authoriz
CVE-2026-77092 | Commvault Content Extractor up to 11.36.122/11.40.71/11.44.19/11.46.19 deserialization
A vulnerability described as critical has been identified in Commvault Content Extractor up to 11.36.122/11.40.71/11.44.19/11.46.19. Affected by this issue is some unknown functionality. Executing a manipulation can lead to deserialization.
CVE-2026-77097 | Commvault Cloud up to 11.36.122/11.40.71/11.44.19/11.46.19 Metrics Upload missing authentication
A vulnerability classified as critical has been found in Commvault Cloud up to 11.36.122/11.40.71/11.44.19/11.46.19. This affects an unknown part of the component Metrics Upload. The manipulation leads to missing authentication. This vulner
CVE-2026-86514 | vgmstream up to r2117 txth-txtp src/meta/txth.c sscanf stack-based overflow (Issue 1972 / EUVD-2026-72615)
A vulnerability identified as critical has been detected in vgmstream up to r2117. This issue affects the function sscanf of the file src/meta/txth.c of the component txth-txtp. This manipulation causes stack-based buffer overflow. This vul
CVE-2026-86519 | code-projects Student Crud Operation 1.0 Backup File /card_activation.sql information disclosure (EUVD-2026-72642)
A vulnerability classified as problematic was found in code-projects Student Crud Operation 1.0. This impacts an unknown function of the file /card_activation.sql of the component Backup File Handler. The manipulation results in information
CVE-2026-86310 | itsourcecode Sales and Inventory System 1.0 /pages/cust_edit1.php ID sql injection
A vulnerability was found in itsourcecode Sales and Inventory System 1.0. It has been declared as critical. The affected element is an unknown function of the file /pages/cust_edit1.php. Such manipulation of the argument ID leads to sql inj
CVE-2026-86509 | D-Link DIR-895L A1_102b07 udhcpcd udhcpcd/serverpacket.c sendOffer/sendACK stack-based overflow
A vulnerability has been found in D-Link DIR-895L A1_102b07 and classified as very critical. This impacts the function sendOffer/sendACK of the file udhcpcd/serverpacket.c of the component udhcpcd. This manipulation causes stack-based buffe
CVE-2026-73558 | vllm-project vLLM up to 0.26.x Activation Kernels activation_kernels.cu act_and_mul_kernel integer overflow (WID-SEC-2026-2842)
A vulnerability classified as problematic was found in vllm-project vLLM up to 0.26.x. The affected element is the function act_and_mul_kernel of the file activation_kernels.cu of the component Activation Kernels. Such manipulation leads to
CVE-2026-73556 | vllm-project vLLM up to 0.25.x lm-format-enforcer backend backend_lm_format_enforcer.py structured_outputs.regex incorrect regex (WID-SEC-2026-2842)
A vulnerability described as problematic has been identified in vllm-project vLLM up to 0.25.x. This issue affects the function validate_structured_output_request_lm_format_enforcer of the file vllm/v1/structured_output/backend_lm_format_en
CVE-2026-73508 | Netty prior 4.1.136.Final/4.2.16.Final DNS Codec allocation of resources
A vulnerability marked as problematic has been reported in Netty. This vulnerability affects the function io.netty.handler.codec.dns.DefaultDnsRecordDecoder.decodeRecord/io.netty.handler.codec.dns.DnsCodecUtil.decompressDomainName of the co
CVE-2026-73507 | Netty prior 4.1.136.Final/4.2.16.Final XmlFrameDecoder io.netty.handler.codec.xml.XmlFrameDecoder.decode resource consumption
A vulnerability labeled as problematic has been found in Netty. This affects the function io.netty.handler.codec.xml.XmlFrameDecoder.decode of the component XmlFrameDecoder. Executing a manipulation can lead to resource consumption. The ide
CVE-2026-73505 | JanDeDobbeleer Oh My Posh up to 29.35.0 Path Segment src/segments/path.go setStyle code injection
A vulnerability categorized as problematic has been discovered in JanDeDobbeleer Oh My Posh up to 29.35.0. Affected by this vulnerability is the function setStyle of the file src/segments/path.go of the component Path Segment. Such manipula
CVE-2026-73506 | Jan De Dobbeleer Oh My Posh up to 29.35.0 Writer src/terminal/writer.go write s injection
A vulnerability identified as problematic has been detected in Jan De Dobbeleer Oh My Posh up to 29.35.0. Affected by this issue is the function write of the file src/terminal/writer.go of the component Writer. Performing a manipulation of
CVE-2026-73559 | vllm-project vLLM up to 0.25.x Completion Request online_renderer.py OnlineRenderer.preprocess_completion prompt resource consumption (WID-SEC-2026-2842)
A vulnerability was found in vllm-project vLLM up to 0.25.x. It has been rated as problematic. Affected by this issue is the function OnlineRenderer.preprocess_completion of the file vllm/renderers/online_renderer.py of the component Comple
CVE-2026-73555 | vllm-project vLLM up to 0.25.x OpenAI Entrypoints server_utils.py validation_exception_handler/sanitize_message information disclosure (WID-SEC-2026-2842)
A vulnerability was found in vllm-project vLLM up to 0.25.x. It has been declared as problematic. This impacts the function validation_exception_handler/sanitize_message of the file vllm/entrypoints/openai/server_utils.py of the component O
CVE-2026-49478 | Sigstore Fulcio up to 1.8.5 server-side request forgery
A vulnerability has been found in Sigstore Fulcio up to 1.8.5 and classified as critical. This affects an unknown function. The manipulation leads to server-side request forgery. This vulnerability is documented as CVE-2026-49478. The attac
CVE-2026-73557 | vllm-project vLLM up to 0.25.x Embed Utils embed_utils.py safe_load_prompt_embeds race condition (WID-SEC-2026-2842)
A vulnerability classified as problematic has been found in vllm-project vLLM up to 0.25.x. Impacted is the function safe_load_prompt_embeds of the file vllm/renderers/embed_utils.py of the component Embed Utils. This manipulation causes ra
CVE-2026-89541 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 SUNRPC gss_unwrap_resp_priv out-of-bounds (Nessus ID 345388)
A vulnerability has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as critical. Affected is the function gss_unwrap_resp_priv of the component SUNRPC. This manipulation causes out-of-bounds read. This vulnerability a
CVE-2026-89663 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 nfsd _free_cpntf_state_locked use after free (Nessus ID 345389)
A vulnerability, which was classified as very critical, has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected by this vulnerability is the function _free_cpntf_state_locked of the component nfsd. Performing a manipulation re
CVE-2026-89462 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 max17040 max17040_get_vcell/max17040_get_soc uninitialized variable (Nessus ID 345390)
A vulnerability identified as critical has been detected in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Impacted is the function max17040_get_vcell/max17040_get_soc of the component max17040. The manipulation leads to use of uninitialized va
CVE-2026-80976 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 seg6 ip6_protocol_deliver_rcu out-of-bounds (Nessus ID 345392)
A vulnerability has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3 and classified as problematic. This vulnerability affects the function ip6_protocol_deliver_rcu of the component seg6. The manipulation leads to out-of-bounds read.
CVE-2026-89439 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 ISST null pointer dereference (Nessus ID 345393)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been declared as very critical. This affects an unknown part of the component ISST. Such manipulation leads to null pointer dereference. This vulnerability is re
CVE-2026-86241 | liufee FeehiCMS up to 2.1.1 Cookie Validation main-local.php cookieValidationKey hard-coded key (Issue 96)
A vulnerability was found in liufee FeehiCMS up to 2.1.1. It has been classified as problematic. This impacts an unknown function of the file environments/prod/backend/config/main-local.php of the component Cookie Validation. This manipulat
CVE-2026-80135 | Dell Secure Connect Gateway exceptional condition
A vulnerability was found in Dell Secure Connect Gateway. It has been rated as critical. This vulnerability affects unknown code. Performing a manipulation results in handling of exceptional conditions. This vulnerability is reported as CVE
CVE-2026-80133 | Dell Secure Connect Gateway up to 5.36.00.00 path traversal
A vulnerability marked as very critical has been reported in Dell Secure Connect Gateway. This issue affects some unknown processing. The manipulation leads to path traversal. This vulnerability is uniquely identified as CVE-2026-80133. The
CVE-2026-79698 | Advantech WISE-6610-NB 1.2.1_20251110 Node-RED Library nodered_lib_apply act command injection
A vulnerability categorized as very critical has been discovered in Advantech WISE-6610-NB, WISE-6610-EB, WISE-6610-TB, WISE-6610-JB, WISE-6610-CB, WISE-6610-EL-NB, WISE-6610-EL-EB, WISE-6610-EL-TB, WISE-6610-EL-JB, WISE-6610-EL-CB, WISE-66
CVE-2026-86299 | Linksys RE7000 2.0.15 PingTest json.cgi?PingTest platform_event_pingTest pingTestIp/pingTestPktSize/pingTestTimes os command injection
A vulnerability classified as very critical was found in Linksys RE7000 2.0.15. This affects the function platform_event_pingTest of the file /cgi-bin/json.cgi?PingTest of the component PingTest Handler. The manipulation of the argument pin
CVE-2026-86294 | SourceCodester Simple Traffic Offense System 1.0 Settings Update Endpoint save-settings.php site_name/site_desc cross site scripting
A vulnerability was found in SourceCodester Simple Traffic Offense System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file save-settings.php of the component Settings Update Endpoint. T
CVE-2026-80178 | Dell Secure Connect Gateway privileges management
A vulnerability was found in Dell Secure Connect Gateway. It has been declared as problematic. Impacted is an unknown function. Executing a manipulation can lead to improper privilege management. This vulnerability is registered as CVE-2026
CVE-2026-89700 | Linux Kernel up to 6.18.49/7.2.3 nfsd nfsd_nl_listener_set_doit out-of-bounds (Nessus ID 345395)
A vulnerability classified as problematic was found in Linux Kernel up to 6.18.49/7.2.3. This affects the function nfsd_nl_listener_set_doit of the component nfsd. Such manipulation leads to out-of-bounds read. This vulnerability is uniquel
CVE-2026-89512 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 remoteproc/scp release of resource (Nessus ID 345396)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been rated as critical. This impacts an unknown function of the component remoteproc/scp. This manipulation causes missing release of resource. The identificatio
CVE-2026-89478 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 SCTP sctp_inq_push use after free (Nessus ID 345397)
A vulnerability classified as very critical has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This impacts the function sctp_inq_push of the component SCTP. Performing a manipulation results in use after free. This vulnerability
CVE-2026-89593 | Linux Kernel up to 6.18.49/7.2.3 hugetlb __unmap_hugepage_range integer overflow (Nessus ID 345398)
A vulnerability classified as very critical was found in Linux Kernel up to 6.18.49/7.2.3. The affected element is the function __unmap_hugepage_range of the component hugetlb. Executing a manipulation can lead to integer overflow. This vul
CVE-2026-80978 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 IP Tunnel integer overflow (Nessus ID 345399)
A vulnerability categorized as very critical has been discovered in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected by this vulnerability is an unknown functionality of the component IP Tunnel. The manipulation results in integer overfl
CVE-2026-89538 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 SUNRPC gss_krb5_unwrap_v2 ec buffer overflow (Nessus ID 345401)
A vulnerability was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. It has been classified as very critical. Affected is the function gss_krb5_unwrap_v2 of the component SUNRPC. This manipulation of the argument ec causes buffer overflo
CVE-2026-89447 | Linux Kernel up to 6.18.49/7.2.3 iommufd iommufd_access_notify_unmap denial of service (Nessus ID 345400)
A vulnerability classified as problematic was found in Linux Kernel up to 6.18.49/7.2.3. This affects the function iommufd_access_notify_unmap of the component iommufd. The manipulation results in denial of service. This vulnerability is re
CVE-2026-89740 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 Serial UART imx_uart_probe imx_uart_ports use after free (Nessus ID 345404)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This affects the function imx_uart_probe of the component Serial UART. Executing a manipulation of the argument imx_uart_ports can lead to use
CVE-2026-80988 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 ntb_transport ntb_transport_tx_enqueue memory leak (Nessus ID 345403)
A vulnerability labeled as critical has been found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. This affects the function ntb_transport_tx_enqueue of the component ntb_transport. The manipulation results in memory leak. This vulnerability
CVE-2026-89573 | Linux Kernel up to 6.12.108/6.18.49/7.2.3 dm array array_block_check out-of-bounds (Nessus ID 345402)
A vulnerability, which was classified as very critical, was found in Linux Kernel up to 6.12.108/6.18.49/7.2.3. Affected by this vulnerability is the function array_block_check of the component dm array. Executing a manipulation can lead to
CVE-2022-43971 | Linksys WUMC710 up to 1.0.02 httpd /setNTP.cgi do_setNTP os command injection (EUVD-2022-46939)
A vulnerability has been found in Linksys WUMC710 up to 1.0.02 and classified as critical. This affects the function do_setNTP of the file /setNTP.cgi of the component httpd. Performing a manipulation results in os command injection. This v
CVE-2022-43970 | Linksys WRT54GL up to 4.30.18.006 httpd /apply.cgi Start_EPI buffer overflow (EUVD-2022-46938)
A vulnerability, which was classified as critical, was found in Linksys WRT54GL up to 4.30.18.006. The impacted element is the function Start_EPI of the file /apply.cgi of the component httpd. Such manipulation leads to buffer overflow. Thi
CVE-2022-43969 | Ricoh mp_c4504ex 1.06 Credentials insufficiently protected credentials (ricoh-2022-000002 / EUVD-2022-46937)
A vulnerability classified as critical was found in Ricoh mp_c4504ex 1.06. This impacts an unknown function of the component Credentials Handler. Such manipulation leads to insufficiently protected credentials. This vulnerability is documen
CVE-2022-43958 | Siemens QMS Automotive cleartext storage in memory (ssa-587547 / EUVD-2022-46928)
A vulnerability was found in Siemens QMS Automotive and classified as problematic. The affected element is an unknown function. Such manipulation leads to cleartext storage of sensitive information in memory. This vulnerability is listed as
CVE-2022-43945 | Linux Kernel up to 5.19.16/6.0.1 NFSD buffer size (EUVD-2022-46915 / Nessus ID 239841)
A vulnerability was found in Linux Kernel up to 5.19.16/6.0.1. It has been rated as critical. The impacted element is an unknown function of the component NFSD. This manipulation causes incorrect calculation of buffer size. The identificati
CVE-2022-43776 | Metabase up to 44.4 URL Parameter /api/geojson url server-side request forgery (EUVD-2022-46746)
A vulnerability identified as critical has been detected in Metabase up to 44.4. Affected by this vulnerability is an unknown functionality of the file /api/geojson of the component URL Parameter Handler. The manipulation of the argument ur
CVE-2026-90781 | ALSA Project alsa-lib up to 1.2.16.1 Control Element Identifier Parsing __snd_ctl_ascii_elem_id_parse Name stack-based overflow (EUVD-2026-77008)
A vulnerability, which was classified as problematic, was found in ALSA Project alsa-lib up to 1.2.16.1. This issue affects the function __snd_ctl_ascii_elem_id_parse of the component Control Element Identifier Parsing. Such manipulation of
CVE-2026-90519 | PHPGurukul Bank Locker Management System 1.0 add-locker-form.php addressproof unrestricted upload (EUVD-2026-77007)
A vulnerability has been found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. Affected is an unknown function of the file /blms/banker/add-locker-form.php. This manipulation of the argument addressproof causes u
CVE-2026-90783 | Moritz Bunkus MKVToolNix up to 101.0 ODML Superindex Parser heap-based overflow (EUVD-2026-77010)
A vulnerability was found in Moritz Bunkus MKVToolNix up to 101.0 and classified as problematic. The affected element is an unknown function of the component ODML Superindex Parser. Executing a manipulation can lead to heap-based buffer ove
CVE-2026-90782 | Systerel S2OPC up to 1.7.3 null pointer dereference (EUVD-2026-77009)
A vulnerability has been found in Systerel S2OPC up to 1.7.3 and classified as problematic. Impacted is the function msg_subscription_publish_bs__alloc_notification_message_items. Performing a manipulation results in null pointer dereferenc
CVE-2026-90520 | jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64 Authorization Interceptor AuthorizationInterceptor.java improper authorization (EUVD-2026-77011)
A vulnerability was found in jaychouchannel Tourism-Management-System up to 84d8ec384f669df3985293dab293bb7b477efa64. It has been rated as critical. This vulnerability affects unknown code of the file AuthorizationInterceptor.java of the co
CVE-2026-90522 | jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d Password Recovery UsersController.java resetPass password recovery (EUVD-2026-77020)
A vulnerability identified as critical has been detected in jaychouchannel Tourism-Management-System up to d984d172dceca907f8b447efbdb06dc233f7938d. Impacted is the function resetPass of the file UsersController.java of the component Passwo
CVE-2026-90521 | jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132 CRUD MenpiaodingdanController.java ID authorization (EUVD-2026-77012)
A vulnerability categorized as critical has been discovered in jaychouchannel Tourism-Management-System up to 8122bf020d91199eddfff3ee02d1632a70a9a132. This issue affects some unknown processing of the file MenpiaodingdanController.java of
CVE-2026-90523 | jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09 User Register Endpoint UsersController.java UsersEntity privileges management (EUVD-2026-77021)
A vulnerability labeled as critical has been found in jaychouchannel Tourism-Management-System up to 229956e20dbd4a80eeff14535e44d3099502af09. The affected element is an unknown function of the file travel/src/main/java/com/controller/Users
CVE-2026-90569 | linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0 Admin Topic index.vue AdminTopicController.validate cross site scripting (IK5SUU / EUVD-2026-77046)
A vulnerability identified as problematic has been detected in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicController.validate of the file litemall-vue/src/views/items/topic/index.vue of th
CVE-2026-90568 | moxi624 Mogu Blog v2 up to 5.2 blogSort Endpoint info.ftl BlogSortServiceImpl.addBlogSort sortName cross site scripting (IK5STW / EUVD-2026-77045)
A vulnerability categorized as problematic has been discovered in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSort of the file mogu_web/src/main/resources/templates/info.ftl of the component blogSort