Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
IBM Langflow OSS versions 1.0.0 through 1.10.1 have a vulnerability that allows an attacker with limited privileges to access another user's private vector documents by creating a flow with matching Chroma persist_directory and collection_name values. This unauthorized access exposes the victim's exact content in the attacker's workflow output. Additionally, the attacker can insert documents into the victim's collection, potentially polluting the victim's data. The vulnerability does not require user interaction but does require some level of privilege to create flows. Join the discussion | GCVE Database | 07/30/2026, 21:31:48 UTC Added: 07/30/2026, 23:26:02 UTC |
0 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrary file-read vulnerability, depending on the exact flow configuration used. By making a flow public, public execution of the flow is allowed. The execution request can contain a list of files that gets read by Langflow and fed into the LLM. The files path can be any path supported by the storage - it can be either a local file or S3 path if supported by the local configuration This vulnerability is fixed in 1.10.0. Join the discussion | CVE Database V5 | 06/23/2026, 16:31:27 UTC Added: 06/23/2026, 16:39:53 UTC |
0 Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link. Specifically, it enables the route /api/v1/build_public_tmp to execute any public flow, given a public flow ID. When the route executes the flow, it allows for providing arbitrary custom Python code as the nodes code, inside the JSON payload. The vulnerable field is data.nodes[X].data.node.template.code.value. This vulnerability is fixed in 1.9.2. Join the discussion | CVE Database V5 | 06/23/2026, 16:25:09 UTC Added: 06/23/2026, 16:39:53 UTC |
0 A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation leads to code injection. The attack needs to be performed locally. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 06/21/2026, 23:30:09 UTC Added: 06/21/2026, 23:54:12 UTC |
0 CVE-2026-7700 is a medium severity code injection vulnerability in langflow-ai langflow versions up to 1.8.4. It affects the eval function in the LambdaFilterComponent, allowing remote attackers to inject code. The vulnerability has a CVSS 4.0 base score of 5.3. Although the exploit code is publicly available, no known exploits in the wild have been reported. The vendor was contacted but did not respond. The product is a cloud service, and a patch is available. Join the discussion | CVE Database V5 | 05/03/2026, 14:15:15 UTC Added: 05/03/2026, 14:21:55 UTC |
0 CVE-2026-7687 is a command injection vulnerability in langflow-ai langflow versions up to 1.8.4. It affects the function CodeParser.parse_callable_details in the Full Builtins Module Handler component. The vulnerability allows remote attackers to execute arbitrary commands by manipulating input to this function. The exploit has been publicly disclosed, but the vendor has not responded or provided a fix. The vulnerability has a medium severity with a CVSS score of 5.3. Join the discussion | CVE Database V5 | 05/03/2026, 08:45:14 UTC Added: 05/04/2026, 01:54:02 UTC |
A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src/modals/IOModal/components/chatView/chatMessage/components/edit-message.tsx of the component Frontend React Component Rendering. Executing a manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 04/20/2026, 03:15:12 UTC Added: 04/20/2026, 04:01:09 UTC |
0 A vulnerability was detected in langflow-ai langflow up to 1.8.3. The impacted element is the function get_client_ip/install_mcp_config of the file src/backend/base/langflow/api/v1/mcp_projects.py of the component Model Context Protocol Configuration API. Performing a manipulation of the argument X-Forwarded-For results in injection. The attack may be initiated remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 04/20/2026, 03:00:15 UTC Added: 04/20/2026, 04:01:09 UTC |
A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function create_project/encrypt_auth_settings of the file src/backend/base/Langflow/api/v1/projects.py of the component Project Creation Endpoint. Such manipulation of the argument auth_settings leads to cleartext storage in a file or on disk. The attack can be launched remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 04/20/2026, 02:45:15 UTC Added: 04/20/2026, 04:01:09 UTC |
A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flow Using API. This manipulation causes unprotected storage of credentials. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 04/20/2026, 02:30:14 UTC Added: 04/20/2026, 02:46:07 UTC |
Showing 1 to 10 of 19 results