- CRITICAL9.8CVE-2026-42208⚠ KEVEPSS 56.9%LiteLLM has SQL Injection in Proxy API key verification
- CRITICAL9.8CVE-2026-39987⚠ KEVEPSS 82.2%Marimo: Pre-Auth Remote Code Execution via Terminal WebSocket Authentication Bypass
- —CVE-2026-33634⚠ KEVEPSS 29.4%Trivy ecosystem supply chain was briefly compromised
- CRITICAL9.8CVE-2026-33017⚠ KEVEPSS 24.0%Unauthenticated Remote Code Execution in Langflow via Public Flow Build Endpoint
- HIGH8.8CVE-2025-34291⚠ KEVEPSS 32.7%Langflow CORS misconfiguration enables Account Takeover and RCE
- CRITICAL9.8CVE-2025-3248⚠ KEVEPSS 92.7%Langflow Unauth RCE
- HIGH8.8CVE-2023-4863⚠ KEVEPSS 93.3%libwebp: OOB write in BuildHuffmanTable
- HIGH8.9CVE-2023-27524⚠ KEVEPSS 84.0%Apache superset missing check for default SECRET_KEY
- HIGH8.8CVE-2022-33891⚠ KEVEPSS 93.5%Apache Spark UI can allow impersonation if ACLs enabled
- CRITICAL9.8CVE-2020-16846⚠ KEVEPSS 94.4%salt - security update
- CRITICAL9.8CVE-2020-11651⚠ KEVEPSS 94.2%salt - security update
- MEDIUM6.5CVE-2020-11652⚠ KEVEPSS 93.7%SaltStack Salt is vulnerable Arbitrary Directory Access
- CRITICAL9.8CVE-2020-13927⚠ KEVEPSS 94.1%Authentication bypass in Apache Airflow
- HIGH8.8CVE-2020-11978⚠ KEVEPSS 94.3%Remote code execution (RCE) in Apache Airflow