🔍 Filter Threats
| Title | Severity | PoC | Actively Exploited | Source | Date |
|---|---|---|---|---|---|
| CVE-2026-103765 Mooncake through 0.3.13.post1 contains a missing authentication vulnerability in the HTTP metadata server /metadata handler that allows unauthenticate... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103764 Mooncake transfer engine before 0.3.13 contains an untrusted pointer dereference in ServerSession::readHeader that allows unauthenticated attackers to... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103761 Mooncake transfer engine through 0.3.13.post1 contains a memory exhaustion vulnerability in TransferMetadata::receivePeerNotify that allows unauthenti... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-103760 Mooncake transfer engine through 0.3.13.post1 contains a denial of service vulnerability that allows unauthenticated remote attackers to block the han... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2025-71427 Office-PowerPoint-MCP-Server through 2.0.7 contains a path traversal vulnerability that allows MCP callers to write and read files outside the working... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-86344 A flaw was found in 389-ds-base. An unauthenticated remote attacker can send a complete LDAP operation followed by the first bytes of an incomplete LD... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51897 RAGFlow 0.24.0 contains improper access control in get_dataset (api/apps/evaluation_app). Depending on the exposed entry, an attacker can trigger atta... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51896 infiniflow ragflow 0.25.3 contains improper access control in resume (api/apps/connector_app.py). Depending on the exposed entry, an attacker can perf... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51895 Ragflow 0.24.0 and prior contains improper access control in update_metadata_setting (api/apps/kb_app.py). Depending on the exposed entry, an attacker... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51894 infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via run_mindmap. A reachable path accepts a caller-selected object or tenant ident... | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51893 infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via trace_mindmap. An externally reachable path accepts a caller-selected object o... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51892 infiniflow ragflow 0.24.0 is vulnerable to Incorrect Access Control via /v1/document/get/<doc_id>. | MEDIUM | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51888 langflow-ai langflow v1.8.4 is affected by: Directory Traversal. The impact is: Arbitrary file write outside the intended workspace or storage boundar... | HIGH | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51886 langflow-ai langflow v1.9.3 is affected by: Code Injection. The impact is: execute arbitrary code (remote). The component is: src/backend/base/langflo... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51884 The /knowledge_base/upload_temp_docs temporary document upload endpoint in Langchain Chatchat 0.3.1 is vulnerable to path traversal. By crafting malic... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51883 The knowledge base creation and document upload interfaces in Langchain-Chatchat 0.3.0;0.3.1 is vulnerable to path traversal. An attacker can inject p... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51882 The OpenAI-compatible file upload endpoint `/v1/files` in Langchain-Chatchat 0.3.0 is vulnerable to path traversal. An attacker can write files to arb... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51876 DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can reuse a pu... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51875 In Devika v1.0, the Feature Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside t... | CRITICAL | ????? | ????? | NVD | 6 days ago |
| CVE-2026-51874 In Devika v1.0, the Patcher Agent save_code_to_project function contains a path traversal vulnerability that allows attackers to write files outside t... | HIGH | ????? | ????? | NVD | 6 days ago |