CRITICAL
NVDSUPPLY-CHAINCVE-2026-14535
2026-07-04
A vulnerability in Trail of Bits fickling versions up to and including 0.1.11 allows for arbitrary code execution via pickle deserialization.
HIGH
NVDSUPPLY-CHAINCVE-2026-5757
2026-06-26
An unauthenticated remote information disclosure vulnerability in Ollama's model quantization engine allows an attacker to read and exfiltrate the server's heap
HIGH
NVDSUPPLY-CHAINCVE-2026-13493
2026-06-28
A flaw in AIDC-AI ComfyUI-Copilot up to 2.0.28 allows remote attacks with high complexity.
HIGH
NVDSUPPLY-CHAINCVE-2026-58116
2026-06-30
Remote code execution vulnerability in LLaMA-Factory allows attackers to execute arbitrary Python code.
HIGH
NVDSUPPLY-CHAINCVE-2026-49119
2026-07-01
Path traversal vulnerability allows unauthenticated attackers to escape configured root directory and access sensitive files.
HIGH
NVDSUPPLY-CHAINCVE-2026-14742
2026-07-05
A vulnerability in langchain-ai langgraph up to 1.2.4 allows remote attacks with high complexity and difficulty.