| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-28701 | Cri | 0.64 | 9.8 | 0.01 | Jun 26, 2026 | Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths. | ||
| CVE-2026-53576 | Cri | 0.58 | 10.0 | 0.03 | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a… | ||
| CVE-2026-49869 | Cri | 0.70 | 10.0 | 0.02 | KEV | Jun 26, 2026 | Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather… | |
| CVE-2026-54352 | Cri | 0.52 | 9.6 | 0.00 | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with [email protected] into a temp directory, then for each entry listed in icons.json validates… | ||
| CVE-2026-54350 | Cri | 0.52 | 10.0 | 0.01 | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with-JSON-body collection and, where the builder has published… | ||
| CVE-2026-50137 | Cri | 0.61 | 9.4 | 0.00 | Jun 26, 2026 | Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-source datasource id (ds_...) can call this endpoint with no auth and obtain a 15-minute pre-signed PUT URL minted on the victim's… | ||
| CVE-2026-53309 | Cri | 0.57 | 9.8 | 0.00 | Jun 26, 2026 | In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison The local-vs-remote region comparison loop uses '<=' instead of '<', causing it to read one entry past the valid range of qr_regions. The… | ||
| CVE-2026-52785 | Cri | 0.00 | 9.9 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work-package attributes using the timestamps parameter. This… | ||
| CVE-2026-52782 | Cri | 0.00 | 9.9 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects//settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources.… | ||
| CVE-2026-52780 | Cri | 0.00 | 9.6 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (RCE). This vulnerability is fixed in 17.3.3 and 17.4.1. | ||
| CVE-2026-46386 | Cri | 0.00 | 9.9 | 0.00 | Jun 26, 2026 | OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a… | ||
| CVE-2026-33646 | Cri | 0.62 | 9.6 | 0.01 | Jun 26, 2026 | mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function registered, enabling arbitrary command execution. Unlike .mise.toml files,… | ||
| CVE-2026-54636 | Cri | 0.00 | 9.0 | 0.01 | Jun 26, 2026 | Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the… | ||
| CVE-2026-45408 | Cri | 0.00 | 9.0 | 0.00 | Jun 26, 2026 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash pre-receive hook script via an… | ||
| CVE-2026-45406 | Cri | 0.00 | 9.0 | 0.01 | Jun 26, 2026 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and then interpolates their filenames, unescaped, into a single-quoted shell string that is later parsed by eval.… | ||
| CVE-2026-45405 | Cri | 0.00 | 9.0 | 0.00 | Jun 26, 2026 | Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanitizing member paths or preventing symlink traversal. GNU tar creates symlinks during extraction and follows… | ||
| CVE-2026-0685 | Cri | 0.00 | 9.8 | 0.01 | Jun 26, 2026 | Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions. | ||
| CVE-2025-11919 | Cri | 0.62 | 9.6 | 0.00 | Jun 26, 2026 | The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the same cloud instance (`/tmp/UserTemporaryFiles/`). The `-init` file for the the JVM initialization exists in the vulnerable directory during the startup of… | ||
| CVE-2026-57658 | Cri | 0.00 | 9.1 | 0.01 | Jun 26, 2026 | Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions. | ||
| CVE-2026-56070 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions. | ||
| CVE-2026-56068 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions. | ||
| CVE-2026-56067 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions. | ||
| CVE-2026-56062 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions. | ||
| CVE-2026-56059 | Cri | 0.00 | 9.9 | 0.00 | Jun 26, 2026 | Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions. | ||
| CVE-2026-56058 | Cri | 0.00 | 9.9 | 0.00 | Jun 26, 2026 | Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions. | ||
| CVE-2026-56057 | Cri | 0.00 | 9.8 | 0.01 | Jun 26, 2026 | Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions. | ||
| CVE-2026-56036 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions. | ||
| CVE-2026-56034 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions. | ||
| CVE-2026-56033 | Cri | 0.57 | 9.8 | 0.00 | Jun 26, 2026 | Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions. | ||
| CVE-2026-56032 | Cri | 0.57 | 9.8 | 0.01 | Jun 26, 2026 | Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions. | ||
| CVE-2026-56030 | Cri | 0.00 | 9.8 | 0.00 | Jun 26, 2026 | Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions. | ||
| CVE-2026-56028 | Cri | 0.00 | 9.8 | 0.01 | Jun 26, 2026 | Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions. | ||
| CVE-2026-56027 | Cri | 0.00 | 9.9 | 0.00 | Jun 26, 2026 | Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions. | ||
| CVE-2026-54831 | Cri | 0.53 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions. | ||
| CVE-2026-54827 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions. | ||
| CVE-2026-54825 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in wpDataTables <= 7.4 versions. | ||
| CVE-2026-54820 | Cri | 0.00 | 9.3 | 0.00 | Jun 26, 2026 | Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions. | ||
| CVE-2025-64152 | Cri | 0.59 | 9.1 | 0.01 | Jun 26, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.6 and 2.0.7, which fixes the issue. | ||
| CVE-2025-55017 | Cri | 0.59 | 9.1 | 0.01 | Jun 26, 2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6. Users are recommended to upgrade to version 1.3.6 and 2.0.6, which fixes the issue. | ||
| CVE-2026-57881 | Cri | 0.00 | 9.8 | 0.01 | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation when processing remote login data. A remote attacker may exploit this… | ||
| CVE-2026-57880 | Cri | 0.00 | 9.8 | 0.01 | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest authentication fields. A remote attacker may exploit this… | ||
| CVE-2026-57879 | Cri | 0.00 | 9.8 | 0.01 | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing RTSP custom authentication data. A remote attacker may exploit this… | ||
| CVE-2026-57878 | Cri | 0.00 | 9.8 | 0.01 | Jun 26, 2026 | An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a specific request path. A remote… | ||
| CVE-2026-48930 | Cri | 0.64 | 9.8 | 0.00 | Jun 26, 2026 | A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**. | ||
| CVE-2026-40702 | Cri | 0.61 | 9.4 | 0.01 | Jun 25, 2026 | WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is… | ||
| CVE-2025-71338 | Cri | 0.58 | 10.0 | 0.01 | Jun 25, 2026 | Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application… | ||
| CVE-2025-71336 | Cri | 0.57 | 9.8 | 0.01 | Jun 25, 2026 | Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers. Because Flowise's authentication and… | ||
| CVE-2025-71334 | Cri | 0.57 | 9.8 | 0.04 | Jun 25, 2026 | Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-traversal value (e.g.,… | ||
| CVE-2025-71333 | Cri | 0.64 | 9.8 | 0.01 | Jun 25, 2026 | Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary… | ||
| CVE-2025-71327 | Cri | 0.59 | 9.1 | 0.01 | Jun 25, 2026 | Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and authenticate to the system,… |
- risk 0.64cvss 9.8epss 0.01
Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.
- risk 0.58cvss 10.0epss 0.03
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /configs as the public instance-config endpoint and forwards it without a…
- risk 0.70cvss 10.0epss 0.02
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public configuration endpoint from Basic Auth. Because the check is a suffix match rather…
- risk 0.52cvss 9.6epss 0.00
Budibase is an open-source low-code platform. Prior to 3.39.9, `POST /api/pwa/process-zip` at packages/server/src/api/routes/static.ts:24 accepts a builder-uploaded .zip, extracts it with [email protected] into a temp directory, then for each entry listed in icons.json validates…
- risk 0.52cvss 10.0epss 0.01
Budibase is an open-source low-code platform. Prior to 3.39.12, an unauthenticated visitor of any published Budibase app reads every document of the backing MongoDB, CouchDB, Elasticsearch, DynamoDB-PartiQL, or REST-with-JSON-body collection and, where the builder has published…
- risk 0.61cvss 9.4epss 0.00
Budibase is an open-source low-code platform. Prior to 3.39.0, an anonymous attacker who knows or can enumerate a workspace id (app_...) and an S3-source datasource id (ds_...) can call this endpoint with no auth and obtain a 15-minute pre-signed PUT URL minted on the victim's…
- risk 0.57cvss 9.8epss 0.00
In the Linux kernel, the following vulnerability has been resolved: ocfs2/dlm: fix off-by-one in dlm_match_regions() region comparison The local-vs-remote region comparison loop uses '<=' instead of '<', causing it to read one entry past the valid range of qr_regions. The…
- risk 0.00cvss 9.9epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is a SQL injection in timestamps functionality. OpenProject baseline comparison allows callers to request historic work-package attributes using the timestamps parameter. This…
- risk 0.00cvss 9.9epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, there is an IDOR through /projects//settings/project_storages/<A_ps_id> via PATCH parameter "storages_project_storage[project_folder_id]" leads to Access to Unauthorized Resources.…
- risk 0.00cvss 9.6epss 0.00
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (RCE). This vulnerability is fixed in 17.3.3 and 17.4.1.
- risk 0.00cvss 9.9epss 0.00
OpenProject is open-source, web-based project management software. Prior to , the official openproject/openproject Docker image ships ENV SECRET_KEY_BASE=OVERWRITE_ME as the default Rails master key. Combined with cookies_serializer = :marshal, this gives any logged-in user a…
- risk 0.62cvss 9.6epss 0.01
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function registered, enabling arbitrary command execution. Unlike .mise.toml files,…
- risk 0.00cvss 9.0epss 0.01
Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron running as the Dokku user. An app.json cron command utilizing special shell characters - including, but not limited to, > or ; - can break out of the…
- risk 0.00cvss 9.0epss 0.00
Dokku is a docker-powered PaaS. Prior to 0.38.2, the app name validation regex (^[a-z0-9][^/:_A-Z]*$) permits shell metacharacters. When an authenticated user pushes to a git remote with a crafted app name, the name is embedded unquoted into a bash pre-receive hook script via an…
- risk 0.00cvss 9.0epss 0.01
Dokku is a docker-powered PaaS. Prior to 0.38.2, the openresty-vhosts plugin copies files from an app's openresty/http-includes/ git repository directory to the host and then interpolates their filenames, unescaped, into a single-quoted shell string that is later parsed by eval.…
- risk 0.00cvss 9.0epss 0.00
Dokku is a docker-powered PaaS. Prior to 0.38.2, the git:from-archive and certs:add commands extract user-supplied tar/zip archives into temporary directories without sanitizing member paths or preventing symlink traversal. GNU tar creates symlinks during extraction and follows…
- risk 0.00cvss 9.8epss 0.01
Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template expressions.
- risk 0.62cvss 9.6epss 0.00
The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the same cloud instance (`/tmp/UserTemporaryFiles/`). The `-init` file for the the JVM initialization exists in the vulnerable directory during the startup of…
- risk 0.00cvss 9.1epss 0.01
Administrator Arbitrary File Upload in TemplateSpare <= 4.2.0 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in JetEngine <= 3.8.10.2 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in JetSmartFilters <= 3.8.3 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Quotes llama <= 3.1.5 versions.
- risk 0.00cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Travel Booking <= 2.2.5 versions.
- risk 0.00cvss 9.9epss 0.00
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
- risk 0.00cvss 9.8epss 0.01
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.
- risk 0.57cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Dokan Pro <= 5.0.4 versions.
- risk 0.57cvss 9.8epss 0.01
Subscriber PHP Object Injection in Buddyboss Platform <= 3.0.4 versions.
- risk 0.00cvss 9.8epss 0.00
Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.
- risk 0.00cvss 9.8epss 0.01
Unauthenticated Privilege Escalation in Easy Elements for Elementor – Addons & Website Templates <= 1.4.9 versions.
- risk 0.00cvss 9.9epss 0.00
Customer Arbitrary File Upload in Booster for WooCommerce <= 8.0.1 versions.
- risk 0.53cvss 9.3epss 0.00
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in wpDataTables <= 7.4 versions.
- risk 0.00cvss 9.3epss 0.00
Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
- risk 0.59cvss 9.1epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7. Users are recommended to upgrade to version 1.3.6 and 2.0.7, which fixes the issue.
- risk 0.59cvss 9.1epss 0.01
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB. This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6. Users are recommended to upgrade to version 1.3.6 and 2.0.6, which fixes the issue.
- risk 0.00cvss 9.8epss 0.01
An unauthenticated stack-based buffer overflow vulnerability exists in vlsvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient length validation when processing remote login data. A remote attacker may exploit this…
- risk 0.00cvss 9.8epss 0.01
An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when parsing RTSP Digest authentication fields. A remote attacker may exploit this…
- risk 0.00cvss 9.8epss 0.01
An unauthenticated stack-based buffer overflow vulnerability exists in ssvr in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing RTSP custom authentication data. A remote attacker may exploit this…
- risk 0.00cvss 9.8epss 0.01
An unauthenticated stack-based buffer overflow vulnerability exists in thttpd in GeoVision GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by insufficient bounds checking when processing web request parameters in a specific request path. A remote…
- risk 0.64cvss 9.8epss 0.00
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings. This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, and **Node.js 26**.
- risk 0.61cvss 9.4epss 0.01
WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is…
- risk 0.58cvss 10.0epss 0.01
Flowise through 2.2.7 fails to sanitize path segments in the document-store loader endpoint, allowing unauthenticated attackers to write files outside the storage directory. Attackers can use parent-directory sequences to escape the storage directory and overwrite application…
- risk 0.57cvss 9.8epss 0.01
Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers. Because Flowise's authentication and…
- risk 0.57cvss 9.8epss 0.04
Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-traversal value (e.g.,…
- risk 0.64cvss 9.8epss 0.01
Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary…
- risk 0.59cvss 9.1epss 0.01
Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and authenticate to the system,…