Vulnerabilities
Vulnerable Software
Microsoft:  >> Windows  Security Vulnerabilities
CommServe contained an authentication bypass issue affecting access authorization and information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
CVSS Score
8.7
EPSS Score
0.003
Published
2026-09-08
CommServe contained a path traversal issue affecting information disclosure. Software customers upgrade to resolved maintenance release. Update CommServe.
CVSS Score
8.3
EPSS Score
0.004
Published
2026-09-08
CommServe contained a cryptographic signature verification issue affecting privilege management. Software customers upgrade to resolved maintenance release. Update CommServe and Web Server.
CVSS Score
8.7
EPSS Score
0.002
Published
2026-09-08
CommServe contained a stack-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
CVSS Score
8.7
EPSS Score
0.003
Published
2026-09-08
CommServe contained a heap-based buffer overflow issue affecting service availability. Software customers upgrade to resolved maintenance release. Update CommServe.
CVSS Score
8.7
EPSS Score
0.003
Published
2026-09-08
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot " sequences ( /.. /) to view arbitrary files on the system.
CVSS Score
5.4
EPSS Score
0.003
Published
2026-09-04
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to improper limitation of a pathname to a restricted directory.
CVSS Score
6.5
EPSS Score
0.005
Published
2026-09-04
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information and inject messages into workflow history due to improper authorization.
CVSS Score
4.9
EPSS Score
0.002
Published
2026-09-04
IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authenticated attacker to obtain sensitive information due to a server-side request forgery (SSRF) vulnerability.
CVSS Score
5.0
EPSS Score
0.002
Published
2026-09-04
IBM Langflow OSS 1.0.0 through 1.10.2 could allow an authenticated attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system.
CVSS Score
6.5
EPSS Score
0.003
Published
2026-09-04


Contact Us

Shodan ® - All rights reserved