Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-10032 |
|
Cross-Site Scripting (XSS) in CVE-2026-10032 (CVE-2026-10032)
cross-site scripting in CVE-2026-10032 (CVE-2026-10032). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-69259 |
|
Code Injection in flowise (CVE-2026-69259)
code injection in flowise (CVE-2026-69259). Risk of unauthorized operations or information disclosure. Exploitable via ``additionalConfig``. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69258 |
|
Vulnerability in flowise (CVE-2026-69258)
vulnerability in flowise (CVE-2026-69258). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/prediction/`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69257 |
|
SSRF (Server-Side Request Forgery) in flowise (CVE-2026-69257)
SSRF in flowise (CVE-2026-69257). Risk of unauthorized operations or information disclosure. Exploitable via ``httpSecurity.ts``. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69256 |
|
Code Injection in flowise-components (CVE-2026-69256)
code injection in flowise-components (CVE-2026-69256). Risk of unauthorized operations or information disclosure. Exploitable via ``pyodide``. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69255 |
|
Code Injection in flowise (CVE-2026-69255)
code injection in flowise (CVE-2026-69255). Risk of unauthorized operations or information disclosure. Exploitable via ``cbce3fb352b7``. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-67200 |
|
Path Traversal in path-traversal (CVE-2026-67200)
path traversal in path-traversal (CVE-2026-67200). Confidential information can be exposed externally.
|
| CVE-2026-67618 |
|
Vulnerability in CVE-2026-67618 (CVE-2026-67618)
vulnerability in CVE-2026-67618 (CVE-2026-67618). Confidential information can be exposed externally.
|
| CVE-2026-67199 |
|
Vulnerability in dos (CVE-2026-67199)
vulnerability in dos (CVE-2026-67199). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68494 |
|
Vulnerability in CVE-2026-68494 (CVE-2026-68494)
vulnerability in CVE-2026-68494 (CVE-2026-68494). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67198 |
|
Vulnerability in CVE-2026-67198 (CVE-2026-67198)
vulnerability in CVE-2026-67198 (CVE-2026-67198). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61514 |
|
Vulnerability in CVE-2026-61514 (CVE-2026-61514)
vulnerability in CVE-2026-61514 (CVE-2026-61514). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67196 |
|
Cross-Site Scripting (XSS) in CVE-2026-67196 (CVE-2026-67196)
cross-site scripting in CVE-2026-67196 (CVE-2026-67196). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67195 |
|
Vulnerability in CVE-2026-67195 (CVE-2026-67195)
vulnerability in CVE-2026-67195 (CVE-2026-67195). Successful exploitation can lead to full system takeover.
|
| CVE-2026-61515 |
|
Vulnerability in CVE-2026-61515 (CVE-2026-61515)
vulnerability in CVE-2026-61515 (CVE-2026-61515). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18766 |
|
Vulnerability in sqli (CVE-2026-18766)
vulnerability in sqli (CVE-2026-18766). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18650 |
|
Vulnerability in privilege-escalation (CVE-2026-18650)
vulnerability in privilege-escalation (CVE-2026-18650). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18770 |
|
Vulnerability in CVE-2026-18770 (CVE-2026-18770)
vulnerability in CVE-2026-18770 (CVE-2026-18770). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18401 |
|
Vulnerability in dos (CVE-2026-18401)
vulnerability in dos (CVE-2026-18401). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-17070 |
|
Vulnerability in CVE-2026-17070 (CVE-2026-17070)
vulnerability in CVE-2026-17070 (CVE-2026-17070). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70373 |
|
SQL Injection in CVE-2026-70373 (CVE-2026-70373)
SQL injection in CVE-2026-70373 (CVE-2026-70373). Successful exploitation can lead to full system takeover.
|
| CVE-2026-63252 |
|
Vulnerability in eclipse (CVE-2026-63252)
vulnerability in eclipse (CVE-2026-63252). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70371 |
|
SQL Injection in CVE-2026-70371 (CVE-2026-70371)
SQL injection in CVE-2026-70371 (CVE-2026-70371). Successful exploitation can lead to full system takeover.
|
| CVE-2026-60007 |
|
Vulnerability in eclipse (CVE-2026-60007)
vulnerability in eclipse (CVE-2026-60007). Confidential information can be exposed externally. Exploitable via ``Basic128Rsa15``.
|
| CVE-2026-63248 |
|
Vulnerability in eclipse (CVE-2026-63248)
vulnerability in eclipse (CVE-2026-63248). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-61387 |
|
Vulnerability in eclipse (CVE-2026-61387)
vulnerability in eclipse (CVE-2026-61387). Risk of unauthorized operations or information disclosure. Exploitable via ``CreateMonitoredItems``.
|
| CVE-2026-62927 |
|
Authorization Flaw in eclipse (CVE-2026-62927)
vulnerability in eclipse (CVE-2026-62927). Data can be tampered with by attackers.
|
| CVE-2026-70369 |
|
SQL Injection in CVE-2026-70369 (CVE-2026-70369)
SQL injection in CVE-2026-70369 (CVE-2026-70369). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70370 |
|
SQL Injection in CVE-2026-70370 (CVE-2026-70370)
SQL injection in CVE-2026-70370 (CVE-2026-70370). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70372 |
|
SQL Injection in CVE-2026-70372 (CVE-2026-70372)
SQL injection in CVE-2026-70372 (CVE-2026-70372). Successful exploitation can lead to full system takeover.
|
| CVE-2026-58080 |
|
Vulnerability in eclipse (CVE-2026-58080)
vulnerability in eclipse (CVE-2026-58080). Data can be tampered with by attackers. Exploitable via ``RoleMapper``.
|
| CVE-2026-10710 |
|
Vulnerability in CVE-2026-10710 (CVE-2026-10710)
vulnerability in CVE-2026-10710 (CVE-2026-10710). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10709 |
|
Vulnerability in CVE-2026-10709 (CVE-2026-10709)
vulnerability in CVE-2026-10709 (CVE-2026-10709). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18806 |
|
Vulnerability in CVE-2026-18806 (CVE-2026-18806)
vulnerability in CVE-2026-18806 (CVE-2026-18806). Data can be tampered with by attackers.
|
| CVE-2026-70368 |
|
Out-of-Bounds Read in CVE-2026-70368 (CVE-2026-70368)
vulnerability in CVE-2026-70368 (CVE-2026-70368). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14337 |
|
Cross-Site Scripting (XSS) in CVE-2026-14337 (CVE-2026-14337)
cross-site scripting in CVE-2026-14337 (CVE-2026-14337). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70367 |
|
SSRF (Server-Side Request Forgery) in ssrf (CVE-2026-70367)
SSRF in ssrf (CVE-2026-70367). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18809 |
|
Information Disclosure in CVE-2026-18809 (CVE-2026-18809)
vulnerability in CVE-2026-18809 (CVE-2026-18809). Confidential information can be exposed externally.
|
| CVE-2026-69254 |
|
Code Injection in flowise (CVE-2026-69254)
code injection in flowise (CVE-2026-69254). Risk of unauthorized operations or information disclosure. Exploitable via ``nodeVMOptions``. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-11368 |
|
Use-After-Free in c (CVE-2026-11368)
vulnerability in c (CVE-2026-11368). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-69253 |
|
Vulnerability in flowise (CVE-2026-69253)
vulnerability in flowise (CVE-2026-69253). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/auth/login`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69252 |
|
Vulnerability in flowise (CVE-2026-69252)
vulnerability in flowise (CVE-2026-69252). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/files`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69251 |
|
Code Injection in flowise (CVE-2026-69251)
code injection in flowise (CVE-2026-69251). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/auth/login`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69250 |
|
Vulnerability in flowise (CVE-2026-69250)
vulnerability in flowise (CVE-2026-69250). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/oauth2-credential/refresh/`. Mitigation: upgrade to `3.1.3` or later.
|
| GHSA-2364-jh4q-m9vm |
|
Vulnerability in flowise (GHSA-2364-jh4q-m9vm)
vulnerability in flowise (GHSA-2364-jh4q-m9vm). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/organization/customer-default-source`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-14194 |
|
Path Traversal in path-traversal (CVE-2026-14194)
path traversal in path-traversal (CVE-2026-14194). Confidential information can be exposed externally.
|
| CVE-2026-18772 |
|
Vulnerability in CVE-2026-18772 (CVE-2026-18772)
vulnerability in CVE-2026-18772 (CVE-2026-18772). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14804 |
|
Vulnerability in CVE-2026-14804 (CVE-2026-14804)
vulnerability in CVE-2026-14804 (CVE-2026-14804). Confidential information can be exposed externally.
|
| CVE-2026-14202 |
|
Vulnerability in CVE-2026-14202 (CVE-2026-14202)
vulnerability in CVE-2026-14202 (CVE-2026-14202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14175 |
|
Unrestricted File Upload in CVE-2026-14175 (CVE-2026-14175)
vulnerability in CVE-2026-14175 (CVE-2026-14175). Successful exploitation can lead to full system takeover.
|