CVE-2026-33017
Langflow Code Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
See how vulnerabilities affect your specific environment
CRS uses the System Security Context Vector (SSCV) Framework v1.0 to adjust CVSS scores based on your system's exposure level, network position, and business criticality. Learn more about SSCV Framework
Monday's vulnerability disclosures affect a broad range of products including ASUS CMS, Google Dawn, Langflow, Aquasecurity Trivy, and TrueConf Client, with four vulnerabilities confirmed under active exploitation. The day saw 1 critical CVE, down 67% from Sunday's 3, while high-priority disclosures rose 19% to 87. CVE-2019-25687 in ASUS CMS carries a CVSS 9.8 rating, and actively exploited flaws in Langflow (CVE-2026-33017), Trivy (CVE-2026-33634), and Google Dawn (CVE-2026-5281) each score CVSS 9.5. Attack patterns span developer toolchains, container security infrastructure, and video conferencing software, indicating broad exposure across engineering and communications stacks. No patches are currently available for any of the 88 disclosed vulnerabilities, requiring organizations to prioritize compensating controls and monitoring.
Immediate action: Organizations using ASUS CMS, Langflow, Aquasecurity Trivy, Google Dawn, or TrueConf Client should immediately assess exposure and apply network-level mitigations such as access restrictions and enhanced monitoring. With zero patches available, compensating controls including WAF rules, segmentation, and increased logging are essential until vendor fixes are released.
Langflow Code Injection Vulnerability - Active in CISA KEV catalog.
Aquasecurity Trivy Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.
A use-after-free vulnerability exists in the Dawn component of Google Chrome. This flaw allows attackers to potentially execute arbitrary code or cause a denial-of-service via a crafted HTML page.
TrueConf Client Download of Code Without Integrity Check Vulnerability - Active in CISA KEV catalog.
Pegasus CMS 1.0 is vulnerable to unauthenticated remote code execution via the extra_fields.php plugin due to unsafe eval() usage.
phpBB contains an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by exploiting the plupload functionality and phar:// stream wrapper
Kados R10 GreenBee is vulnerable to SQL injection via the menu_lev1 parameter, allowing unauthenticated attackers to execute arbitrary database queries.
Kados R10 GreenBee contains an SQL injection vulnerability in the mng_profile_id parameter, enabling attackers to manipulate database queries.
Kados R10 GreenBee is susceptible to SQL injection via the 'id_to_modify' parameter, allowing unauthorized database query manipulation.
Kados R10 GreenBee is vulnerable to unauthenticated SQL injection via the user2reset parameter, facilitating unauthorized database interaction.
Kados R10 GreenBee contains an SQL injection vulnerability in the language_tag parameter, allowing attackers to manipulate database queries.
Kados R10 GreenBee contains an SQL injection vulnerability in the id_to_delete parameter, enabling unauthorized database query manipulation.
Kados R10 GreenBee is susceptible to SQL injection via the sort_direction parameter, allowing for unauthorized database query manipulation.
Kados R10 GreenBee is vulnerable to SQL injection via the id_project parameter, allowing attackers to manipulate database queries.
Kados R10 GreenBee is susceptible to SQL injection via the filter_user_mail parameter, allowing unauthorized database query manipulation.
eDirectory contains multiple SQL injection vulnerabilities that allow unauthenticated attackers to bypass administrator authentication and disclose sensitive files by injecting SQL code into parameters
A security vulnerability has been identified in the Apache VA MAX software platform.
UniSharp Laravel File Manager v2
Core FTP 2 contains an unspecified vulnerability that requires immediate remediation to prevent potential security compromise.
CMSsite 1
C4G Basic Laboratory Information System 3
A vulnerability has been found in code-projects Simple Laundry System 1
A security flaw has been discovered in itsourcecode Free Hotel Reservation System 1
A weakness has been identified in code-projects Concert Ticket Reservation System 1
A security vulnerability has been detected in code-projects Simple Laundry System 1
A vulnerability was detected in SourceCodester/jkev Record Management System 1
A vulnerability was identified in projectworlds Car Rental Project 1
A security vulnerability has been detected in projectworlds Car Rental System 1
A vulnerability was determined in Cyber-III Student-Management-System up to 1a938fa61e9f735078e9b291d2e6215b4942af3f
A weakness has been identified in projectworlds Car Rental System 1
A flaw has been found in code-projects Simple Laundry System 1
SuiteCRM 7
A critical security vulnerability exists within the Code-Projects News Website Script that may allow for unauthorized system interaction.
A security vulnerability has been identified in the itsourcecode Online Enrollment System, which may allow attackers to compromise system integrity.
A security vulnerability in Code-Projects Easy Blog Site 1 may allow attackers to compromise the integrity of the application.
A security vulnerability has been identified in the MyBB Downloads Plugin, potentially leading to unauthorized access or system impact.
VPN Browser+ 1
A vulnerability was found in Tenda AC10 16
A vulnerability was identified in Tenda AC10 16
A flaw has been found in Tenda M3 1
A security flaw has been discovered in Tenda CH22 1
A weakness has been identified in Tenda CH22 1
A flaw has been found in Tenda i12 1
Advance Gift Shop Pro Script 2
Missing Authentication for Critical Function vulnerability in Honeywell Handheld Scanners allows Authentication Abuse
7 Tik 1
Wikipedia 12
A security flaw has been discovered in the UTT HiPER 1250GW router, which could allow for unauthorized system compromise.
A critical vulnerability has been discovered in the UTT HiPER 1250GW router, potentially allowing for unauthorized system access.
A security vulnerability has been identified in the Belkin F9K1122 router, potentially exposing it to unauthorized interference.
A high-severity vulnerability has been identified in the Belkin F9K1015 router, requiring immediate attention from security administrators.
A security vulnerability has been identified in the Belkin F9K1015 router, necessitating immediate security review and patching.
A security vulnerability has been identified in the Belkin F9K1015, requiring immediate attention to mitigate potential unauthorized access.
A security vulnerability has been identified in the Belkin F9K1015, requiring immediate attention to mitigate potential unauthorized access.
A security flaw has been identified in the Belkin F9K1015, necessitating immediate review and firmware updates.
A security vulnerability has been detected in the Belkin F9K1015, requiring immediate security attention.
A vulnerability has been detected in the Belkin F9K1015, requiring immediate security attention.
A vulnerability in the Mattermost Plugin Legal Hold allows for potential security bypasses in version 1 and earlier.
A security vulnerability has been identified in the Snes9K software, which may expose users to potential system compromise.
A vulnerability in 10-Strike LANState 8 may allow for unauthorized system interaction or information disclosure.
R i386 3
River Past Video Cleaner 7
Xlight FTP Server 3
ResourceSpace 8
qdPM 9
PilusCart 1
Ask Expert Script 3
OpenDocMan 1
IObit Advanced SystemCare 10
Spy Emergency build 23
NETGATE Registry Cleaner build 16
Netgate AMITI Antivirus build 23
IObit Malware Fighter 4
Hotspot Shield 6
sheed AntiVirus 2
RealTerm Serial Terminal 2
A security flaw has been discovered in Tenda 4G03 Pro up to 1
A security weakness has been identified in the FedML-AI FedML framework, affecting versions up to 0.
A security flaw has been discovered in code-projects Concert Ticket Reservation System 1
A vulnerability has been identified in Provectus kafka-ui, potentially impacting the management of Kafka clusters.
A weakness has been identified in code-projects Simple Laundry System 1
A security vulnerability has been identified in the Technostrobe HI-LED-WR120-G2 lighting control system.
A security vulnerability has been determined in the Technostrobe HI-LED-WR120-G2 lighting control system.
A security weakness has been identified in the Technostrobe HI-LED-WR120-G2 lighting control system.
A vulnerability has been found in Song-Li cross_browser up to ca690f0fe6954fd9bcda36d071b68ed8682a786a
A vulnerability has been found in Fosowl agenticSeek 0
A security vulnerability has been detected in the JeecgBoot application platform.
A vulnerability has been found in assafelovic gpt-researcher up to 3
A vulnerability was found in assafelovic gpt-researcher up to 3
A vulnerability was determined in assafelovic gpt-researcher up to 3
MyBB Last User's Threads in Profile Plugin 1
SuiteCRM 7