| Feb 27 | Vitess users with backup storage access can write to arbitrary file paths on restore vitessCriticalFeb 27 | vitess | Critical | 0.22.4+1 more |
| Feb 27 | Langflow has Remote Code Execution in CSV Agent LangflowCritical9.8Feb 27 | Langflow | Critical9.8 | No fix yet |
| Feb 26 | Vitess users with backup storage access can gain unauthorized access to production deployment environments vitessHighFeb 26 | vitess | High | No fix yet |
| Feb 26 | n8n has Webhook Forgery on Zendesk Trigger Node n8nMedium4.0Feb 26 | n8n | Medium4.0 | 1.123.18+1 more |
| Feb 26 | n8n has a Guardrail Node Bypass n8nMedium3.7Feb 26 | n8n | Medium3.7 | 2.10.0 |
| Feb 26 | n8n has an Authentication Bypass in its Chat Trigger Node n8nMedium4.8Feb 26 | n8n | Medium4.8 | 1.123.22+2 more |
| Feb 26 | n8n has an SSO Enforcement Bypass in its Self-Service Settings API n8nMedium6.3Feb 26 | n8n | Medium6.3 | 2.8.0 |
| Feb 26 | n8n: Webhook Forgery on Github Webhook Trigger n8nMedium4.0Feb 26 | n8n | Medium4.0 | 1.123.15+1 more |
| Feb 26 | n8n: SQL Injection in MySQL, PostgreSQL, and Microsoft SQL nodes n8nMedium8.2Feb 26 | n8n | Medium8.2 | 2.4.0 |
| Feb 25 | LangChain Community: redirect chaining can lead to SSRF bypass via RecursiveUrlLoader LangChainMedium4.1Feb 25 | LangChain | Medium4.1 | 1.1.18 |
| Feb 25 | n8n Vulnerable to Stored XSS via Various Nodes n8nHigh5.4Feb 25 | n8n | High5.4 | 1.123.22+2 more |
| Feb 25 | n8n: Expression Sandbox Escape Leads to RCE n8nCritical9.9Feb 25 | n8n | Critical9.9 | 1.123.22+2 more |
| Feb 25 | n8n has Arbitrary Command Execution via File Write and Git Operations n8nCritical8.5Feb 25 | n8n | Critical8.5 | 1.123.8+1 more |
| Feb 25 | n8n has Potential Remote Code Execution via Merge Node n8nCritical9.9Feb 25 | n8n | Critical9.9 | 1.123.22+2 more |
| Feb 25 | n8n has a Sandbox Escape in its JavaScript Task Runner n8nCriticalFeb 25 | n8n | Critical | 1.123.22+2 more |
| Feb 25 | n8n has Arbitrary File Read via Python Code Node Sandbox Escape n8nHigh9.9Feb 25 | n8n | High9.9 | 1.123.22+2 more |
| Feb 25 | n8n has Unauthenticated Expression Evaluation via Form Node n8nCritical9.0Feb 25 | n8n | Critical9.0 | 1.123.22+2 more |
| Feb 25 | cli_history database does not restrict file permissions on Unix systems AWSMedium5.9Feb 25 | AWS | Medium5.9 | 1.44.37+1 more |
| Feb 24 | MindsDB: Path Traversal in /api/files Leading to Remote Code Execution MindsDBHigh8.8Feb 24 | MindsDB | High8.8 | 25.9.1.1 |
| Feb 24 | nats-server websockets are vulnerable to pre-auth memory DoS nats-serverMedium5.9Feb 24 | nats-server | Medium5.9 | No fix yet |
| Feb 24 | Apache Superset Improper Authorization allows low-privileged users to bypass access controls Apache SupersetHighFeb 24 | Apache Superset | High | 6.0.0 |
| Feb 24 | Apache Superset: Incomplete DISALLOWED_SQL_FUNCTIONS default list for ClickHouse engine Apache SupersetMediumFeb 24 | Apache Superset | Medium | 4.1.2 |
| Feb 24 | Apache Superset allows privileged users to conduct error-based SQL Injection Apache SupersetMediumFeb 24 | Apache Superset | Medium | 6.0.0 |
| Feb 24 | Apache Superset allows authenticated users to view sensitive data without explicit permissions Apache SupersetLowFeb 24 | Apache Superset | Low | 6.0.0 |
| Feb 24 | Apache Superset: Read-Only Bypass via Improper Input Validation on PostgreSQL Connections Apache SupersetHighFeb 24 | Apache Superset | High | 6.0.0 |
| Feb 24 | Apache Airflow exposes sensitive information in its log files Apache AirflowMedium6.5Feb 24 | Apache Airflow | Medium6.5 | 2.11.1 |
| Feb 24 | Apache Airflow vulnerable to Code Injection in the web-server context via LogTemplate table Apache AirflowHigh8.4Feb 24 | Apache Airflow | High8.4 | 2.11.1 |
| Feb 24 | Incorrect calculation in circl secp384r1 CombinedMult CloudflareLowFeb 24 | Cloudflare | Low | 1.6.3 |
| Feb 21 | Apache Airflow error reporting may expose full kwargs Apache AirflowMedium6.5Feb 21 | Apache Airflow | Medium6.5 | 2.11.1+1 more |
| Feb 21 | MLflow Use of Default Password Authentication Bypass Vulnerability MLflowCritical9.8Feb 21 | MLflow | Critical9.8 | 3.8.0rc0 |
| Feb 21 | MLflow Tracking Server Artifact Handler Directory Traversal Remote Code Execution Vulnerability MLflowHigh8.1Feb 21 | MLflow | High8.1 | 3.8.0rc0 |
| Feb 20 | Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion) RayMedium5.9Feb 20 | Ray | Medium5.9 | 2.54.0 |
| Feb 19 | Microsoft Semantic Kernel InMemoryVectorStore filter functionality vulnerable to remote code execution Semantic KernelCritical9.9Feb 19 | Semantic Kernel | Critical9.9 | 1.39.4 |
| Feb 18 | Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading KerasHigh7.1Feb 18 | Keras | High7.1 | 3.12.1+1 more |
| Feb 18 | NLTK has a Zip Slip Vulnerability NLTKCritical10.0Feb 18 | NLTK | Critical10.0 | 3.9.3 |
| Feb 17 | Apache Arrow: Potential use-after-free when reading IPC file with pre-buffering Apache ArrowHigh7.0Feb 17 | Apache Arrow | High7.0 | 23.0.1 |
| Feb 16 | MindsDB affected by a SSRF vulnerability MindsDBLow6.3Feb 16 | MindsDB | Low6.3 | No fix yet |
| Feb 13 | Cloudflare Agents has a Reflected Cross-Site Scripting (XSS) vulnerability in AI Playground site agentsMediumFeb 13 | agents | Medium | 0.3.10 |
| Feb 13 | agents: cross-site scripting agentsMediumFeb 13 | agents | Medium | 0.3.10 |
| Feb 13 | Sandbox escape via Git hooks CursorHigh8.0Feb 13 | Cursor | High8.0 | 2.5 |
| Feb 12 | SurrealDB vulnerable to Denial of Service through scripting function memory edge case SurrealDBMediumFeb 12 | SurrealDB | Medium | 2.6.1+1 more |
| Feb 11 | Milvus: Unauthenticated Access to Restful API on Metrics Port (9091) Leads to Critical System Compromise MilvusCritical9.8Feb 11 | Milvus | Critical9.8 | 2.5.27+1 more |
| Feb 11 | @langchain/community affected by SSRF Bypass in RecursiveUrlLoader via insufficient URL origin validation LangChainMedium4.1Feb 11 | LangChain | Medium4.1 | 1.1.14 |
| Feb 11 | LangChain affected by SSRF via image_url token counting in ChatOpenAI.get_num_tokens_from_messages LangChainLow3.7Feb 11 | LangChain | Low3.7 | 1.2.11 |
| Feb 10 | Terminal auto replies restriction MicrosoftHigh8.0Feb 10 | Microsoft | High8.0 | 1.109.1 |
| Feb 10 | Workspace trust for MCP servers MicrosoftLowFeb 10 | Microsoft | Low | 1.109.1 |
| Feb 9 | Apache Airflow UI Exposes DAG Import Errors to Unauthorized Authenticated Users Apache AirflowMedium6.5Feb 9 | Apache Airflow | Medium6.5 | 3.1.7 |
| Feb 9 | Apache Airflow Has an Authorization Bypass That Allows Unauthorized Task Log Access Apache AirflowMedium6.5Feb 9 | Apache Airflow | Medium6.5 | 3.1.7 |
| Feb 6 | Pydantic AI has Stored XSS via Path Traversal in Web UI CDN URL pydantic-aiHigh7.1Feb 6 | pydantic-ai | High7.1 | 1.51.0 |
| Feb 6 | Semantic Kernel has Arbitrary File Write via AI Agent Function Calling in .NET SDK Semantic KernelCritical9.9Feb 6 | Semantic Kernel | Critical9.9 | 1.39.3 |
| Feb 6 | Pydantic AI has Server-Side Request Forgery (SSRF) in URL Download Handling pydantic-aiHigh8.6Feb 6 | pydantic-ai | High8.6 | 1.56.0 |
| Feb 6 | Command Injection via Directory Change Bypasses Write Protection AnthropicHigh7.7Feb 6 | Anthropic | High7.7 | v2.0.57 |
| Feb 6 | Command Injection via Piped sed Command Bypasses File Write Restrictions AnthropicHigh7.7Feb 6 | Anthropic | High7.7 | v2.0.55 |
| Feb 6 | Sandbox Escape via Persistent Configuration Injection in settings.json AnthropicHigh7.7Feb 6 | Anthropic | High7.7 | v2.1.2 |
| Feb 6 | Permission Deny Bypass Through Symbolic Links AnthropicLow2.3Feb 6 | Anthropic | Low2.3 | v2.1.7 |
| Feb 5 | qdrant has arbitrary file write via `/logger` endpoint QdrantHigh8.5Feb 5 | Qdrant | High8.5 | 1.15.6 |
| Feb 4 | n8n's domain allowlist bypass enables credential exfiltration n8nMediumFeb 4 | n8n | Medium | 1.121.0 |
| Feb 4 | @modelcontextprotocol/sdk has cross-client data leak via shared server/transport instance reuse MCP SDKsHigh7.1Feb 4 | MCP SDKs | High7.1 | 1.26.0 |
| Feb 4 | n8n has a Python sandbox escape n8nCritical9.9Feb 4 | n8n | Critical9.9 | 2.4.8 |
| Feb 4 | n8n Merge Node has Arbitrary File Write leading to RCE n8nCriticalFeb 4 | n8n | Critical | 1.118.0+1 more |