VulnScope — package-centric CVE lookup
CRITICAL9.6 CVE-2026-55447 Langflow: BaseFileComponent-based nodes arbitrary file read with RCE exploit 6/19/2026 CRITICAL9.9 Langflow: IDOR Vulnerability in `/api/v1/responses` Endpoint Allows Authenticated Attackers to Access Another User's Flow 6/19/2026 CRITICAL9.9 Network-AI: Improper Neutralization of Special Elements used in an OS Command 6/19/2026 CRITICAL9.1 Network-AI: CVE-2026-46701 fix incomplete — empty default secret still authorizes all requests 6/19/2026 CRITICAL9.8 gemini-mcp-tool vulnerable to OS command injection and @file exfiltration via prompt quoting (CVE-2026-0755) 6/18/2026 CRITICAL9.8 python-statemachine SCXML <data expr> Eval Injection 6/18/2026 CRITICAL9.3 Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak 6/17/2026 CRITICAL9.1 Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory 6/17/2026 CRITICAL9.1 Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks 6/17/2026 CRITICAL9.8 Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure 6/17/2026 CRITICAL10.0 n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions 6/16/2026 CRITICAL9.9 n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints 6/16/2026 CRITICAL9.6 n8n: Credential Exfiltration via Permission Bypass 6/16/2026 CRITICAL9.0 LobeHub: Unauthenticated SSRF in `/webapi/proxy` 6/16/2026 CRITICAL9.8 Crawl4AI: AST Sandbox Escape via gi_frame.f_back Chain - Pre-Auth RCE in Docker API 6/16/2026 CRITICAL9.9 n8n: SQL Injection in Postgres v1/TimesclaeDB Nodes 6/16/2026 CRITICAL9.1 vLLM: OpenAI auth bypass 6/16/2026 CRITICAL9.6 Langflow: Unauthenticated RCE in Shareable Playgrounds 6/16/2026 CRITICAL9.1 Remotion: arbitrary file write vulnerability 6/15/2026 CRITICAL9.8 Remotion: remote code execution (RCE) vulnerability 6/15/2026 CRITICAL9.8 Vitest Browser: Exposed Browser Mode API Can Proxy CDP and Overwrite Config Files, Leading to RCE 6/15/2026 CRITICAL9.0 Budibase: Workspace-scoped builder escalates to global admin via /api/public/v1/roles/assign 6/12/2026 CRITICAL9.1 Meta Ads MCP: Unauthenticated HTTP MCP Tool Execution Leaks Operator Meta Access Token 6/11/2026 CRITICAL9.8 GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. 6/10/2026 CRITICAL9.8 Issue summary: A specially crafted PKCS#7 or S/MIME signed message could trigger a use-after-free during PKCS#7 signature verification. 6/9/2026