| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-6599 | langflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injection | langflow-ai | langflow | Medium | 6.3 | 2026-04-20 03:00:16 | Deep Dive |
| CVE-2026-6598 | langflow-ai langflow Project Creation Endpoint projects.py encrypt_auth_settings cleartext storage in file | langflow-ai | langflow | Medium | 4.3 | 2026-04-20 02:45:16 | Deep Dive |
| CVE-2026-6597 | langflow-ai langflow Flow Using API core.py has_api_terms credentials storage | langflow-ai | langflow | Low | 2.7 | 2026-04-20 02:30:15 | Deep Dive |
| CVE-2026-6596 | langflow-ai langflow API Endpoint endpoints.py create_upload_file unrestricted upload | langflow-ai | langflow | High | 7.3 | 2026-04-20 02:15:14 | Deep Dive |
| CVE-2026-6595 | ProjectsAndPrograms School Management System HTTP GET Parameter buslocation.php sql injection | ProjectsAndPrograms | School Management System | High | 7.3 | 2026-04-20 02:00:49 | Deep Dive |
| CVE-2026-6594 | brikcss merge prototype pollution | brikcss | merge | High | 7.3 | 2026-04-20 01:45:12 | Deep Dive |
| CVE-2026-6593 | ComfyUI View Endpoint server.py cross site scripting | - | ComfyUI | Low | 3.5 | 2026-04-20 01:30:18 | Deep Dive |
| CVE-2026-6592 | ComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting | - | ComfyUI | Low | 3.5 | 2026-04-20 01:15:15 | Deep Dive |
| CVE-2026-6591 | ComfyUI LoadImage Node folder_paths.py folder_paths.get_annotated_filepath path traversal | - | ComfyUI | Medium | 4.3 | 2026-04-20 01:00:18 | Deep Dive |
| CVE-2026-6590 | ComfyUI Model Preview Endpoint model_manager.py get_model_preview path traversal | - | ComfyUI | Medium | 4.3 | 2026-04-20 00:45:12 | Deep Dive |
| CVE-2026-6589 | ComfyUI server.py create_origin_only_middleware cross-site request forgery | - | ComfyUI | Medium | 4.3 | 2026-04-20 00:30:21 | Deep Dive |
| CVE-2026-6588 | serge-chat serge Model API Endpoint model.py delete_model missing authentication | serge-chat | serge | Medium | 6.5 | 2026-04-20 00:15:12 | Deep Dive |
| CVE-2026-6587 | vibrantlabsai RAGAS Collections util.py _try_process_url server-side request forgery | vibrantlabsai | RAGAS | Medium | 6.3 | 2026-04-20 00:00:20 | Deep Dive |
| CVE-2026-30266 | DeepCool DeepCreative 安全漏洞 | - | - | - | - | 2026-04-20 00:00:00 | Deep Dive |
| CVE-2026-30269 | doorman 安全漏洞 | - | - | - | - | 2026-04-20 00:00:00 | Deep Dive |
| CVE-2025-66954 | Buffalo LinkStation 安全漏洞 | - | - | - | - | 2026-04-20 00:00:00 | Deep Dive |
| CVE-2026-26399 | Arduino 安全漏洞 | - | - | - | - | 2026-04-20 00:00:00 | Deep Dive |
| CVE-2026-39112 | PHPGurukul Apartment Visitors Management System 安全漏洞 | - | - | - | - | 2026-04-20 00:00:00 | Deep Dive |
| CVE-2026-39110 | PHPGurukul Apartment Visitors Management System 安全漏洞 | - | - | - | - | 2026-04-20 00:00:00 | Deep Dive |
| CVE-2026-39111 | PHPGurukul Apartment Visitors Management System 安全漏洞 | - | - | - | - | 2026-04-20 00:00:00 | Deep Dive |