IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Langflow deployments
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
Use after free in Microsoft Office Excel allows an unauthorized attacker to execute code over a network.
| Version | Type | Source | Base | Exp | Imp |
|---|---|---|---|---|---|
| 3.1 | Primary | cve.org | 8.8 | — | — |
| 3.1 | Primary | NVD | 8.8 | 2.8 | 5.9 |
| 3.1 | Secondary | NVD | 8.8 | 2.8 | 5.9 |
| 3.1 | Secondary | ENISA EUVD | 8.8 | — | — |