CVE-2026-33017
Langflow Code Injection Vulnerability - Active in CISA KEV catalog.
Critical vulnerabilities, curated daily for security professionals
Fortinet FortiClientEMS, HP, and NICO FTP carry critical-severity ratings at CVSS 9.8, while Langflow, Aquasecurity Trivy, Google Dawn, and TrueConf face confirmed active exploitation at CVSS 9.5. Sunday's disclosures include 3 critical and 73 high-priority CVEs, down 88% and 27% respectively from Saturday's counts. CVE-2026-35616 affects Fortinet FortiClientEMS, CVE-2026-33017 targets Langflow, and CVE-2026-33634 impacts Aquasecurity Trivy — all rated 9.5 or above. Attack patterns span endpoint management, DevSecOps tooling, browser rendering components, and communication platforms. No patches are currently available for any of the 76 disclosed vulnerabilities, requiring defenders to prioritize compensating controls and monitoring.
Immediate action: Organizations running Fortinet FortiClientEMS, Langflow, Aquasecurity Trivy, Google Dawn, or TrueConf should assess exposure immediately and apply network segmentation or access restrictions. With no patches available for any disclosed vulnerability, implement monitoring for exploitation indicators and restrict access to affected services until vendor fixes are released.
CVSS score (e.g. 9.1) — severity from 0–10. Red marks critical (9+), orange high (7–8.9).
Exploitability — how hard the flaw is to attack, read from the CVSS vector:
The lower the bar on all three, the easier to exploit at scale — “Network · No privileges · No interaction” is the worst case: hit from anywhere, no credentials, no victim action.
🔴 Actively exploited — confirmed under attack in the wild (CISA’s Known Exploited Vulnerabilities catalog). Prioritize these regardless of score.
EPSS · Nth percentile — FIRST.org’s estimated chance a flaw is exploited within 30 days. We flag it only in the top 10% — a statistical signal it’s unusually likely to be targeted, separate from whether attacks are confirmed.
Langflow Code Injection Vulnerability - Active in CISA KEV catalog.
Aquasecurity Trivy Embedded Malicious Code Vulnerability - Active in CISA KEV catalog.
A use-after-free vulnerability exists in the Dawn component of Google Chrome. This flaw allows attackers to potentially execute arbitrary code or cause a denial-of-service via a crafted HTML page.
TrueConf Client Download of Code Without Integrity Check Vulnerability - Active in CISA KEV catalog.
Snews CMS 1.7 contains an unrestricted file upload vulnerability, allowing unauthenticated attackers to upload and execute arbitrary PHP files to achieve remote code execution.
Fortinet FortiClientEMS versions 7.4.5 and 7.4.6 contain an improper access control vulnerability. Unauthenticated attackers can execute unauthorized code or commands via crafted requests.
NICO-FTP 3.0.1.19 contains a structured exception handler (SEH) buffer overflow vulnerability, allowing remote unauthenticated attackers to execute arbitrary code via crafted FTP commands.
A high-severity vulnerability has been discovered in the PraisonAI multi-agent teams system.
A security vulnerability has been identified in the PraisonAI multi-agent teams system.
An Insecure Direct Object Reference (IDOR) vulnerability exists in the WCFM – Frontend Manager for WooCommerce plugin for WordPress.
A security vulnerability has been identified in the PraisonAI multi-agent teams system.
A security vulnerability has been discovered in the PraisonAI multi-agent teams system.
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Distribution Lists report
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions based on Distribution Groups report
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Mails Exchanged Between Users report
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Equipment Mailbox Details report
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Public Folder Client Permissions report
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Folder Message Count and Size report
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Non-Owner Mailbox Permission report
Zohocorp ManageEngine Exchange Reporter Plus versions before 5802 are vulnerable to Stored XSS in Permissions Based on Mailboxes report
The wpForo Forum plugin for WordPress is vulnerable to arbitrary file deletion in all versions up to and including 2.
A high-severity vulnerability in the Electron framework could allow for unauthorized code execution or system compromise in desktop applications.
A high-severity security vulnerability in the Electron framework could facilitate unauthorized access or data compromise in affected desktop applications.
A vulnerability in the Electron framework has been identified that could allow for unauthorized actions within cross-platform desktop applications.
A late-disclosure vulnerability in Hirschmann HiOS devices prior to version 08 poses a high-severity risk to network infrastructure security.
The core-rs-albatross Rust implementation of the Nimiq Proof-of-Stake protocol contains a high-severity vulnerability affecting its consensus mechanism.
A security vulnerability in the Electron framework could allow attackers to perform unauthorized operations in applications built on the platform.
The Text to Speech for WP plugin for WordPress is vulnerable to sensitive information exposure in all versions up to and including 1.
The Widgets for Social Photo Feed plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'feed_data' parameter.
The Visitor Traffic Real Time Statistics plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) via the 'page_title' parameter.
The ProfilePress WordPress plugin is vulnerable to an unauthorized membership payment bypass, potentially allowing users to access restricted content without completing payment.
A vulnerability has been identified in the Electron framework, a platform for cross-platform desktop applications using web technologies.
A security issue has been identified in DokuWiki, a popular open-source wiki software, which could lead to unauthorized system access or data exposure.
A vulnerability has been found in code-projects Simple Laundry System 1
Mesop, a Python-based UI framework, contains a high-severity vulnerability that could allow for unauthorized access or manipulation of web applications.
A security vulnerability has been identified in the itsourcecode Online Enrollment System, which may allow attackers to compromise system integrity.
A security vulnerability has been identified in the MyBB Downloads Plugin, potentially leading to unauthorized access or system impact.
Piwigo, an open-source photo gallery application, contains a security vulnerability that could allow for unauthorized access or site compromise.
VPN Browser+ 1
A vulnerability was found in Tenda AC10 16
A vulnerability was identified in Tenda AC10 16
Cloudreve, a self-hosted file management system, is affected by a security vulnerability that could lead to unauthorized file access or administrative compromise.
A vulnerability in the Amazon Athena ODBC driver's browser-based authentication component allows for OS command injection, potentially leading to unauthorized code execution.
7 Tik 1
Wikipedia 12
OAuthenticator, used with JupyterHub for OAuth2 identity provision, contains a high-severity vulnerability that could allow for unauthorized authentication or privilege escalation.
A security flaw has been discovered in the UTT HiPER 1250GW router, which could allow for unauthorized system compromise.
A high-severity vulnerability has been identified in the Budibase open-source low-code platform that could lead to unauthorized access or system compromise.
A vulnerability in the Budibase platform could allow for unauthorized actions, potentially leading to a breach of the application environment.
Storage credentials are hardcoded in the mobile application and device firmware, allowing unauthorized parties to access stored data.
A security vulnerability has been identified in the Snes9K software, which may expose users to potential system compromise.
10-Strike LANState 8
An issue was discovered in BizTalk360 before version 11 that could allow for unauthorized access or system manipulation within the monitoring environment.
Hirschmann HiLCOS industrial networking devices are affected by a high-severity vulnerability in versions prior to version 8, potentially impacting critical network infrastructure.
Focalboard version 8 is affected by a high-severity vulnerability; however, the product was designated as unsupported at the time the CVE was assigned.
A high-severity vulnerability has been identified in the "prompts" library, potentially impacting applications that utilize this component for user input handling.
A high-severity vulnerability has been identified in the "prompts" component as utilized within Canon products, potentially affecting device security.
Hirschmann HiLCOS Classic Platform switches are affected by a high-severity vulnerability in versions prior to 09, impacting industrial network reliability.
The Amazon Athena ODBC driver contains a high-severity vulnerability due to improper neutralization of special elements in its authentication components.
IObit Advanced SystemCare 10
Spy Emergency build 23
NETGATE Registry Cleaner build 16
Netgate AMITI Antivirus build 23
IObit Malware Fighter 4
Hotspot Shield 6
sheed AntiVirus 2
A high-severity vulnerability exists in Fal products related to prompt handling. The flaw could allow for unauthorized input manipulation or system exploitation.
The "prompts" library, a popular Node.js package for interactive CLI prompts, contains a vulnerability that could lead to improper input handling.
An administrative endpoint is exposed without authentication, allowing remote attackers to access sensitive device management functions.
The Amazon Athena ODBC driver is vulnerable to resource exhaustion due to unlimited resource allocation within its parsing components during data processing.
The Amazon Athena ODBC driver fails to properly validate certificates within its identity provider (IdP) connection components, enabling potential interception.
The Amazon Athena ODBC driver contains insufficient security controls in its browser-based authentication components, potentially allowing for unauthorized session access.
Hirschmann Industrial HiVision version 08
A security flaw has been discovered in Tenda 4G03 Pro up to 1
A security weakness has been identified in the FedML-AI FedML framework, affecting versions up to 0.
A security vulnerability has been identified in Piwigo, an open-source photo gallery application for the web.
A security vulnerability has been identified in the Piwigo photo gallery application, potentially impacting web-based image hosting security.
Emlog is an open source website building system
MyBB Last User's Threads in Profile Plugin 1
Hirschmann Industrial HiVision versions 06