Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-64633 |
|
A vulnerability allowing remote unauthenticated code execution on the agent host.
A vulnerability allowing remote unauthenticated code execution on the agent host.
|
| CVE-2026-63456 |
|
Authentication Bypass in CVE-2026-63456 (CVE-2026-63456)
authentication bypass in CVE-2026-63456 (CVE-2026-63456). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64631 |
|
A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
|
| CVE-2026-58074 |
|
A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
|
| CVE-2026-58075 |
|
Authentication Bypass in CVE-2026-58075 (CVE-2026-58075)
authentication bypass in CVE-2026-58075 (CVE-2026-58075). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-63455 |
|
Vulnerability in CVE-2026-63455 (CVE-2026-63455)
vulnerability in CVE-2026-63455 (CVE-2026-63455). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64630 |
|
Authorization Flaw in CVE-2026-64630 (CVE-2026-64630)
vulnerability in CVE-2026-64630 (CVE-2026-64630). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58073 |
|
Vulnerability in CVE-2026-58073 (CVE-2026-58073)
vulnerability in CVE-2026-58073 (CVE-2026-58073). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58071 |
|
Vulnerability in CVE-2026-58071 (CVE-2026-58071)
vulnerability in CVE-2026-58071 (CVE-2026-58071). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-58072 |
|
Path Traversal in CVE-2026-58072 (CVE-2026-58072)
path traversal in CVE-2026-58072 (CVE-2026-58072). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18784 |
|
Buffer Overflow in c (CVE-2026-18784)
vulnerability in c (CVE-2026-18784). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15314 |
|
Vulnerability in tp-link (CVE-2026-15314)
vulnerability in tp-link (CVE-2026-15314). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15337 |
|
Vulnerability in django (CVE-2026-15337)
vulnerability in django (CVE-2026-15337). Risk of unauthorized operations or information disclosure. Exploitable via ``DATA_UPLOAD_MAX_MEMORY_SIZE``.
|
| CVE-2025-29296 |
|
Command Injection in CVE-2025-29296 (CVE-2025-29296)
command injection in CVE-2025-29296 (CVE-2025-29296). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58067 |
|
Vulnerability in CVE-2026-58067 (CVE-2026-58067)
vulnerability in CVE-2026-58067 (CVE-2026-58067). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-56848 |
|
Use-After-Free in CVE-2026-56848 (CVE-2026-56848)
vulnerability in CVE-2026-56848 (CVE-2026-56848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15920 |
|
Vulnerability in django (CVE-2026-15920)
vulnerability in django (CVE-2026-15920). Risk of unauthorized operations or information disclosure. Exploitable via ``URLField``.
|
| CVE-2026-18787 |
|
Vulnerability in CVE-2026-18787 (CVE-2026-18787)
vulnerability in CVE-2026-18787 (CVE-2026-18787). Successful exploitation can lead to full system takeover.
|
| CVE-2026-15307 |
|
Vulnerability in django (CVE-2026-15307)
vulnerability in django (CVE-2026-15307). Successful exploitation can lead to full system takeover. Exploitable via ``django.contrib.gis.gdal.GDALRaster``.
|
| CVE-2026-18775 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-18775 (CVE-2026-18775)
SSRF in CVE-2026-18775 (CVE-2026-18775). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15830 |
|
Vulnerability in django (CVE-2026-15830)
vulnerability in django (CVE-2026-15830). Risk of unauthorized operations or information disclosure. Exploitable via ``django.contrib.gis.geos.GEOSGeometry``.
|
| CVE-2026-18774 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-18774 (CVE-2026-18774)
SSRF in CVE-2026-18774 (CVE-2026-18774). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18785 |
|
Buffer Overflow in c (CVE-2026-18785)
vulnerability in c (CVE-2026-18785). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18830 |
|
Vulnerability in Amazon aws (CVE-2026-18830)
vulnerability in Amazon aws (CVE-2026-18830). Confidential information can be exposed externally.
|
| CVE-2026-70474 |
|
Authorization Flaw in flowise (CVE-2026-70474)
vulnerability in flowise (CVE-2026-70474). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/oauth2-credential/authorize/`. Mitigation: upgrade to `3.1.3` or later.
|
| GHSA-rwrp-9823-p2xq |
|
Information Disclosure in flowise (GHSA-rwrp-9823-p2xq)
vulnerability in flowise (GHSA-rwrp-9823-p2xq). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/credentials/`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70473 |
|
Information Disclosure in flowise (CVE-2026-70473)
vulnerability in flowise (CVE-2026-70473). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/upsert-history`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70472 |
|
Vulnerability in flowise (CVE-2026-70472)
vulnerability in flowise (CVE-2026-70472). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/openai-assistants-vector-store`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69264 |
|
Code Injection in flowise (CVE-2026-69264)
code injection in flowise (CVE-2026-69264). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/prediction/`. Mitigation: upgrade to `3.1.3` or later.
|
| GHSA-88pr-878c-24wf |
|
Path Traversal in flowise-components (GHSA-88pr-878c-24wf)
path traversal in flowise-components (GHSA-88pr-878c-24wf). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/document-store/loader/preview`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70471 |
|
Authorization Flaw in flowise (CVE-2026-70471)
vulnerability in flowise (CVE-2026-70471). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70470 |
|
Vulnerability in flowise (CVE-2026-70470)
vulnerability in flowise (CVE-2026-70470). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/prediction/{chatflowId}`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69263 |
|
Vulnerability in flowise (CVE-2026-69263)
vulnerability in flowise (CVE-2026-69263). Risk of unauthorized operations or information disclosure. Exploitable via ``npx``. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69262 |
|
Authorization Flaw in flowise (CVE-2026-69262)
vulnerability in flowise (CVE-2026-69262). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /api/v1/chatflows/`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69110 |
|
Path Traversal in CVE-2026-69110 (CVE-2026-69110)
path traversal in CVE-2026-69110 (CVE-2026-69110). Confidential information can be exposed externally. Exploitable via `GET /api/tmp/`.
|
| CVE-2026-69100 |
|
Code Injection in CVE-2026-69100 (CVE-2026-69100)
code injection in CVE-2026-69100 (CVE-2026-69100). Successful exploitation can lead to full system takeover.
|
| CVE-2026-69098 |
|
Unsafe Deserialization in c (CVE-2026-69098)
vulnerability in c (CVE-2026-69098). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25292 |
|
Vulnerability in qualcomm (CVE-2026-25292)
vulnerability in qualcomm (CVE-2026-25292). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25289 |
|
Vulnerability in qualcomm (CVE-2026-25289)
vulnerability in qualcomm (CVE-2026-25289). Successful exploitation can lead to full system takeover.
|
| CVE-2026-25288 |
|
Vulnerability in dos (CVE-2026-25288)
vulnerability in dos (CVE-2026-25288). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-24084 |
|
Vulnerability in qualcomm (CVE-2026-24084)
vulnerability in qualcomm (CVE-2026-24084). Confidential information can be exposed externally.
|
| CVE-2026-24083 |
|
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
|
| CVE-2026-24080 |
|
Memory Corruption when handling malformed request parameters in the fingerprint TA.
Memory Corruption when handling malformed request parameters in the fingerprint TA.
|
| CVE-2026-24079 |
|
Vulnerability in qualcomm (CVE-2026-24079)
vulnerability in qualcomm (CVE-2026-24079). Confidential information can be exposed externally.
|
| CVE-2026-24078 |
|
Vulnerability in qualcomm (CVE-2026-24078)
vulnerability in qualcomm (CVE-2026-24078). Confidential information can be exposed externally.
|
| CVE-2026-24077 |
|
Vulnerability in qualcomm (CVE-2026-24077)
vulnerability in qualcomm (CVE-2026-24077). Confidential information can be exposed externally.
|
| CVE-2026-24076 |
|
Memory Corruption when processing registry values with incorrect types using a direct query method.
Memory Corruption when processing registry values with incorrect types using a direct query method.
|
| CVE-2026-21366 |
|
Memory corruption while processing a packet with a size close to the maximum allowed value.
Memory corruption while processing a packet with a size close to the maximum allowed value.
|
| CVE-2026-18801 |
|
Vulnerability in sqli (CVE-2026-18801)
vulnerability in sqli (CVE-2026-18801). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18773 |
|
Vulnerability in CVE-2026-18773 (CVE-2026-18773)
vulnerability in CVE-2026-18773 (CVE-2026-18773). Risk of unauthorized operations or information disclosure.
|