Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
CVE-2026-64633 A vulnerability allowing remote unauthenticated code execution on the agent host.
A vulnerability allowing remote unauthenticated code execution on the agent host.
CVE-2026-63456 Authentication Bypass in CVE-2026-63456 (CVE-2026-63456)
authentication bypass in CVE-2026-63456 (CVE-2026-63456). Successful exploitation can lead to full system takeover.
CVE-2026-64631 A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
A vulnerability allowing a low-privileged user to inject SQL and extract database contents.
CVE-2026-58074 A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
A vulnerability allowing a high-privileged user to execute arbitrary code on the server.
CVE-2026-58075 Authentication Bypass in CVE-2026-58075 (CVE-2026-58075)
authentication bypass in CVE-2026-58075 (CVE-2026-58075). Risk of unauthorized operations or information disclosure.
CVE-2026-63455 Vulnerability in CVE-2026-63455 (CVE-2026-63455)
vulnerability in CVE-2026-63455 (CVE-2026-63455). Successful exploitation can lead to full system takeover.
CVE-2026-64630 Authorization Flaw in CVE-2026-64630 (CVE-2026-64630)
vulnerability in CVE-2026-64630 (CVE-2026-64630). Risk of unauthorized operations or information disclosure.
CVE-2026-58073 Vulnerability in CVE-2026-58073 (CVE-2026-58073)
vulnerability in CVE-2026-58073 (CVE-2026-58073). Risk of unauthorized operations or information disclosure.
CVE-2026-58071 Vulnerability in CVE-2026-58071 (CVE-2026-58071)
vulnerability in CVE-2026-58071 (CVE-2026-58071). Risk of unauthorized operations or information disclosure.
CVE-2026-58072 Path Traversal in CVE-2026-58072 (CVE-2026-58072)
path traversal in CVE-2026-58072 (CVE-2026-58072). Risk of unauthorized operations or information disclosure.
CVE-2026-18784 Buffer Overflow in c (CVE-2026-18784)
vulnerability in c (CVE-2026-18784). Risk of unauthorized operations or information disclosure.
CVE-2026-15314 Vulnerability in tp-link (CVE-2026-15314)
vulnerability in tp-link (CVE-2026-15314). Risk of unauthorized operations or information disclosure.
CVE-2026-15337 Vulnerability in django (CVE-2026-15337)
vulnerability in django (CVE-2026-15337). Risk of unauthorized operations or information disclosure. Exploitable via ``DATA_UPLOAD_MAX_MEMORY_SIZE``.
CVE-2025-29296 Command Injection in CVE-2025-29296 (CVE-2025-29296)
command injection in CVE-2025-29296 (CVE-2025-29296). Successful exploitation can lead to full system takeover.
CVE-2026-58067 Vulnerability in CVE-2026-58067 (CVE-2026-58067)
vulnerability in CVE-2026-58067 (CVE-2026-58067). Risk of unauthorized operations or information disclosure.
CVE-2026-56848 Use-After-Free in CVE-2026-56848 (CVE-2026-56848)
vulnerability in CVE-2026-56848 (CVE-2026-56848). Risk of unauthorized operations or information disclosure.
CVE-2026-15920 Vulnerability in django (CVE-2026-15920)
vulnerability in django (CVE-2026-15920). Risk of unauthorized operations or information disclosure. Exploitable via ``URLField``.
CVE-2026-18787 Vulnerability in CVE-2026-18787 (CVE-2026-18787)
vulnerability in CVE-2026-18787 (CVE-2026-18787). Successful exploitation can lead to full system takeover.
CVE-2026-15307 Vulnerability in django (CVE-2026-15307)
vulnerability in django (CVE-2026-15307). Successful exploitation can lead to full system takeover. Exploitable via ``django.contrib.gis.gdal.GDALRaster``.
CVE-2026-18775 SSRF (Server-Side Request Forgery) in CVE-2026-18775 (CVE-2026-18775)
SSRF in CVE-2026-18775 (CVE-2026-18775). Risk of unauthorized operations or information disclosure.
CVE-2026-15830 Vulnerability in django (CVE-2026-15830)
vulnerability in django (CVE-2026-15830). Risk of unauthorized operations or information disclosure. Exploitable via ``django.contrib.gis.geos.GEOSGeometry``.
CVE-2026-18774 SSRF (Server-Side Request Forgery) in CVE-2026-18774 (CVE-2026-18774)
SSRF in CVE-2026-18774 (CVE-2026-18774). Risk of unauthorized operations or information disclosure.
CVE-2026-18785 Buffer Overflow in c (CVE-2026-18785)
vulnerability in c (CVE-2026-18785). Risk of unauthorized operations or information disclosure.
CVE-2026-18830 Vulnerability in Amazon aws (CVE-2026-18830)
vulnerability in Amazon aws (CVE-2026-18830). Confidential information can be exposed externally.
CVE-2026-70474 Authorization Flaw in flowise (CVE-2026-70474)
vulnerability in flowise (CVE-2026-70474). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/oauth2-credential/authorize/`. Mitigation: upgrade to `3.1.3` or later.
GHSA-rwrp-9823-p2xq Information Disclosure in flowise (GHSA-rwrp-9823-p2xq)
vulnerability in flowise (GHSA-rwrp-9823-p2xq). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/credentials/`. Mitigation: upgrade to `3.1.3` or later.
CVE-2026-70473 Information Disclosure in flowise (CVE-2026-70473)
vulnerability in flowise (CVE-2026-70473). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/upsert-history`. Mitigation: upgrade to `3.1.3` or later.
CVE-2026-70472 Vulnerability in flowise (CVE-2026-70472)
vulnerability in flowise (CVE-2026-70472). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/openai-assistants-vector-store`. Mitigation: upgrade to `3.1.3` or later.
CVE-2026-69264 Code Injection in flowise (CVE-2026-69264)
code injection in flowise (CVE-2026-69264). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/prediction/`. Mitigation: upgrade to `3.1.3` or later.
GHSA-88pr-878c-24wf Path Traversal in flowise-components (GHSA-88pr-878c-24wf)
path traversal in flowise-components (GHSA-88pr-878c-24wf). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/document-store/loader/preview`. Mitigation: upgrade to `3.1.3` or later.
CVE-2026-70471 Authorization Flaw in flowise (CVE-2026-70471)
vulnerability in flowise (CVE-2026-70471). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.3` or later.
CVE-2026-70470 Vulnerability in flowise (CVE-2026-70470)
vulnerability in flowise (CVE-2026-70470). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/prediction/{chatflowId}`. Mitigation: upgrade to `3.1.3` or later.
CVE-2026-69263 Vulnerability in flowise (CVE-2026-69263)
vulnerability in flowise (CVE-2026-69263). Risk of unauthorized operations or information disclosure. Exploitable via ``npx``. Mitigation: upgrade to `3.1.3` or later.
CVE-2026-69262 Authorization Flaw in flowise (CVE-2026-69262)
vulnerability in flowise (CVE-2026-69262). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /api/v1/chatflows/`. Mitigation: upgrade to `3.1.3` or later.
CVE-2026-69110 Path Traversal in CVE-2026-69110 (CVE-2026-69110)
path traversal in CVE-2026-69110 (CVE-2026-69110). Confidential information can be exposed externally. Exploitable via `GET /api/tmp/`.
CVE-2026-69100 Code Injection in CVE-2026-69100 (CVE-2026-69100)
code injection in CVE-2026-69100 (CVE-2026-69100). Successful exploitation can lead to full system takeover.
CVE-2026-69098 Unsafe Deserialization in c (CVE-2026-69098)
vulnerability in c (CVE-2026-69098). Successful exploitation can lead to full system takeover.
CVE-2026-25292 Vulnerability in qualcomm (CVE-2026-25292)
vulnerability in qualcomm (CVE-2026-25292). Successful exploitation can lead to full system takeover.
CVE-2026-25289 Vulnerability in qualcomm (CVE-2026-25289)
vulnerability in qualcomm (CVE-2026-25289). Successful exploitation can lead to full system takeover.
CVE-2026-25288 Vulnerability in dos (CVE-2026-25288)
vulnerability in dos (CVE-2026-25288). Risk of unauthorized operations or information disclosure.
CVE-2026-24084 Vulnerability in qualcomm (CVE-2026-24084)
vulnerability in qualcomm (CVE-2026-24084). Confidential information can be exposed externally.
CVE-2026-24083 Memory Corruption while processing IOCTL device driver requests with invalid arguments.
Memory Corruption while processing IOCTL device driver requests with invalid arguments.
CVE-2026-24080 Memory Corruption when handling malformed request parameters in the fingerprint TA.
Memory Corruption when handling malformed request parameters in the fingerprint TA.
CVE-2026-24079 Vulnerability in qualcomm (CVE-2026-24079)
vulnerability in qualcomm (CVE-2026-24079). Confidential information can be exposed externally.
CVE-2026-24078 Vulnerability in qualcomm (CVE-2026-24078)
vulnerability in qualcomm (CVE-2026-24078). Confidential information can be exposed externally.
CVE-2026-24077 Vulnerability in qualcomm (CVE-2026-24077)
vulnerability in qualcomm (CVE-2026-24077). Confidential information can be exposed externally.
CVE-2026-24076 Memory Corruption when processing registry values with incorrect types using a direct query method.
Memory Corruption when processing registry values with incorrect types using a direct query method.
CVE-2026-21366 Memory corruption while processing a packet with a size close to the maximum allowed value.
Memory corruption while processing a packet with a size close to the maximum allowed value.
CVE-2026-18801 Vulnerability in sqli (CVE-2026-18801)
vulnerability in sqli (CVE-2026-18801). Risk of unauthorized operations or information disclosure.
CVE-2026-18773 Vulnerability in CVE-2026-18773 (CVE-2026-18773)
vulnerability in CVE-2026-18773 (CVE-2026-18773). Risk of unauthorized operations or information disclosure.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →