🐞 CVE Tracking and Search

Search and filter Common Vulnerabilities and Exposures

← Dashboard CVE Search Exploitation Radar Breaches Trends Industries Vendors MITRE ATT&CK MITRE ATLAS Threat Actors Attack-Tools Alerts Investigations
Search: Time Range:
Sources: Clear All Filters
378,232+
CVEs Tracked
378,232
Exploit Intel
358,051
EPSS Scored
5,202
CISA KEV
2,698
Metasploit Modules
30,385
ExploitDB Entries
61
MITRE ATT&CK Maps
0
Actively Exploited
0
CISA KEV
1
PoC Available
0
Zero-Days
0
Recent Discoveries
0
Most Mentioned

CVE Severity Distribution (Last 30 Days)

Found 1 CVEs in the last 30 days.

CVE-2026-0768 CRITICAL CVSS: 9.8 EPSS: 2.3% VulnCheck KEV PoC Available CWE-94 T1059
Langflow code Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Langflow. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of the code parameter provided to the validate endpoint. The issue results from the lack of proper validation of a user-supplied string before using it to execute Python code. An attacker can leverage this vulnerability to execute code in the context of root. . Was ZDI-CAN-27322.
Published: 2026-01-23
Mentioned in 4 article(s):
Critical Langflow Flaw Exploited as Attacks on AI Platform Rise
Dark Reading
Critical Langflow flaw exploited to steal OpenAI and AWS keys
BleepingComputer
Hackers Start Exploiting Critical Langflow Vulnerability
SecurityWeek
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
The Hacker News