Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
205 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.80% | 💥 PoC | Langflow | 28/8/2026 | 1/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary code due to improper enforcement of security restrictions on the A2A public endpoint. | |
| Analizada | Alta (8.2) | 0.31% | — | Langflow | 28/8/2026 | 31/8/2026 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to obtain sensitive information and inject unauthorized messages due to a namespace collision between user identifiers. | |
| Analizada | Alta (7.5) | 0.46% | — | Langflow | 28/8/2026 | 1/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to read arbitrary files due to path traversal. | |
| Analizada | Alta (8.2) | 0.32% | — | Langflow | 28/8/2026 | 31/8/2026 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote attacker to execute arbitrary flows and access sensitive information due to improper authentication. | |
| Analizada | Alta (8.8) | 1.8% | 💥 Exploit | Langflow | 28/8/2026 | 1/9/2026 | IBM Langflow OSS 1.0.0 through 1.11.1 could allow a remote authenticated attacker to execute arbitrary code due to improper control of generation of code. | |
| Analizada | Media (4.3) | 0.22% | — | Langflow | 28/8/2026 | 31/8/2026 | IBM Langflow OSS 1.0.0 through 1.11.1 is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Analizada | Alta (7.5) | 0.52% | — | Langflow | 19/8/2026 | 26/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to overwrite administrator email information and abuse the server as an outbound relay due to missing authentication for the registration endpoint. | |
| Analizada | Crítica (9.1) | 0.61% | — | Langflow | 13/8/2026 | 26/8/2026 | IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to obtain unauthorized access to user accounts due to improper restriction of excessive authentication attempts. | |
| Analizada | Crítica (9.8) | 0.30% | — | Langflow | 5/8/2026 | 7/8/2026 | IBM Langflow OSS contains a weak cryptographic key derivation vulnerability in the ensure_fernet_key() function. | |
| Analizada | Alta (8.8) | 0.38% | — | Langflow | 5/8/2026 | 17/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute arbitrary code due to a cryptographic weakness in the custom component validation mechanism. When the optional hardening mode that restricts execution to trusted component templates is enabled, the application validates component… | |
| Analizada | Alta (8.8) | 0.53% | — | Langflow | 5/8/2026 | 7/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user approval, which may allow… | |
| Modificada | Alta (7.1) | 0.30% | — | Langflow | 5/8/2026 | 7/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3 contain an authorization bypass vulnerability in the MemoryComponent that allows authenticated users to access chat history of other users via session_id collision. The MemoryComponent.retrieve_messages and store_message methods filter on session_id without validating flow_id or… | |
| Analizada | Alta (8.8) | 0.63% | — | Langflow | 5/8/2026 | 6/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote attacker to inject arbitrary code on the system, due to the improper control of user input code. | |
| Analizada | Crítica (9.1) | 0.19% | — | Langflow | 5/8/2026 | 6/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 use Python's non-cryptographic random module for generating Fernet encryption keys from user secrets under 32 characters. The deterministic Mersenne Twister PRNG produces identical keys for identical seeds,… | |
| Analizada | Alta (7.7) | 0.56% | — | Langflow | 5/8/2026 | 6/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to… | |
| Analizada | Alta (8.8) | 0.65% | — | Langflow | 5/8/2026 | 6/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3 installations allow anyone on the internet to execute arbitrary code on the server without any credentials via 2 HTTP requests. | |
| Analizada | Media (5.4) | 0.32% | — | Langflow | 5/8/2026 | 6/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3 is vulnerable to Path Traversal in the Knowledge Bases API (`POST /api/v1/knowledge_bases`). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or containment checks. An authenticated attacker can exploit this… | |
| Analizada | Media (6.5) | 0.51% | — | Langflow | 5/8/2026 | 6/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate the username field, allowing attackers to inject path traversal sequences and bypass containment checks. This enables multiple severe impacts, including arbitrary directory deletion, cross-tenant data destruction, and JWT signing key deletion leading to… | |
| Analizada | Alta (8.8) | 0.68% | 💥 PoC | Langflow | 5/8/2026 | 6/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to code injection. | |
| Analizada | Alta (8.8) | 0.66% | — | Langflow | 5/8/2026 | 6/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of Python code during AST-based security scanning. | |
| Analizada | Alta (8.8) | 0.68% | — | Langflow | 5/8/2026 | 6/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary code due to improper validation of module imports. | |
| Analizada | Alta (8.1) | 0.40% | — | Langflow | 5/8/2026 | 6/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3 does not properly validate ownership in the deprecated POST /api/v1/build/{flow_id}/vertices endpoint, allowing an authenticated user to inject arbitrary graph data into a shared cache for any flow. This may result in cross-user cache pollution, unauthorized workflow execution, or… | |
| Analizada | Alta (7.1) | 0.31% | — | Langflow | 5/8/2026 | 6/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 contains a Server-Side Request Forgery (SSRF) vulnerability in the validate_model_provider_key() function for the Ollama provider. The function accepts a user-supplied OLLAMA_BASE_URL parameter and passes it directly to requests.get() without validation,… | |
| Analizada | Media (6.5) | 0.38% | — | Langflow | 5/8/2026 | 6/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3 Langflow could allow server-side request forgery (SSRF) due to incomplete and ineffective SSRF protection enforcement. | |
| Analizada | Alta (8.8) | 0.80% | — | Langflow | 5/8/2026 | 6/8/2026 | IBM Langflow OSS 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, 1.0.0 through 1.10.3, and 1.0.0 through 1.10.3 could allow a remote authenticated attacker to execute arbitrary commands due to improper neutralization of special elements used in an OS… |