Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-69252 |
|
Vulnerability in flowise (CVE-2026-69252)
vulnerability in flowise (CVE-2026-69252). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/files`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69251 |
|
Code Injection in flowise (CVE-2026-69251)
code injection in flowise (CVE-2026-69251). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/auth/login`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69250 |
|
Vulnerability in flowise (CVE-2026-69250)
vulnerability in flowise (CVE-2026-69250). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/oauth2-credential/refresh/`. Mitigation: upgrade to `3.1.3` or later.
|
| GHSA-2364-jh4q-m9vm |
|
Vulnerability in flowise (GHSA-2364-jh4q-m9vm)
vulnerability in flowise (GHSA-2364-jh4q-m9vm). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/organization/customer-default-source`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-14194 |
|
Path Traversal in path-traversal (CVE-2026-14194)
path traversal in path-traversal (CVE-2026-14194). Confidential information can be exposed externally.
|
| CVE-2026-18772 |
|
Vulnerability in CVE-2026-18772 (CVE-2026-18772)
vulnerability in CVE-2026-18772 (CVE-2026-18772). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14804 |
|
Vulnerability in CVE-2026-14804 (CVE-2026-14804)
vulnerability in CVE-2026-14804 (CVE-2026-14804). Confidential information can be exposed externally.
|
| CVE-2026-14202 |
|
Vulnerability in CVE-2026-14202 (CVE-2026-14202)
vulnerability in CVE-2026-14202 (CVE-2026-14202). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14175 |
|
Unrestricted File Upload in CVE-2026-14175 (CVE-2026-14175)
vulnerability in CVE-2026-14175 (CVE-2026-14175). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14192 |
|
Cross-Site Scripting (XSS) in CVE-2026-14192 (CVE-2026-14192)
cross-site scripting in CVE-2026-14192 (CVE-2026-14192). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15721 |
|
Vulnerability in sqli (CVE-2026-15721)
vulnerability in sqli (CVE-2026-15721). Successful exploitation can lead to full system takeover.
|
| CVE-2026-14465 |
|
Vulnerability in CVE-2026-14465 (CVE-2026-14465)
vulnerability in CVE-2026-14465 (CVE-2026-14465). Confidential information can be exposed externally.
|
| CVE-2026-14219 |
|
Open Redirect in CVE-2026-14219 (CVE-2026-14219)
vulnerability in CVE-2026-14219 (CVE-2026-14219). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14838 |
|
Vulnerability in CVE-2026-14838 (CVE-2026-14838)
vulnerability in CVE-2026-14838 (CVE-2026-14838). Confidential information can be exposed externally.
|
| CVE-2026-66884 |
|
Cross-Site Request Forgery (CSRF) in CVE-2026-66884 (CVE-2026-66884)
vulnerability in CVE-2026-66884 (CVE-2026-66884). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-66883 |
|
Vulnerability in csrf (CVE-2026-66883)
vulnerability in csrf (CVE-2026-66883). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67243 |
|
Unrestricted File Upload in jvn (CVE-2026-67243)
vulnerability in jvn (CVE-2026-67243). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18759 |
|
Privilege Escalation in path-traversal (CVE-2026-18759)
vulnerability in path-traversal (CVE-2026-18759). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18755 |
|
Vulnerability in CVE-2026-18755 (CVE-2026-18755)
vulnerability in CVE-2026-18755 (CVE-2026-18755). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18754 |
|
Vulnerability in CVE-2026-18754 (CVE-2026-18754)
vulnerability in CVE-2026-18754 (CVE-2026-18754). Confidential information can be exposed externally.
|
| CVE-2026-18753 |
|
Vulnerability in CVE-2026-18753 (CVE-2026-18753)
vulnerability in CVE-2026-18753 (CVE-2026-18753). Confidential information can be exposed externally.
|
| CVE-2026-64565 |
|
Vulnerability in CVE-2026-64565 (CVE-2026-64565)
vulnerability in CVE-2026-64565 (CVE-2026-64565). Risk of unauthorized operations or information disclosure. Exploitable via ``read_pos``.
|
| CVE-2026-64564 |
|
Vulnerability in CVE-2026-64564 (CVE-2026-64564)
vulnerability in CVE-2026-64564 (CVE-2026-64564). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64563 |
|
Vulnerability in c (CVE-2026-64563)
vulnerability in c (CVE-2026-64563). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64562 |
|
Vulnerability in CVE-2026-64562 (CVE-2026-64562)
vulnerability in CVE-2026-64562 (CVE-2026-64562). Successful exploitation can lead to full system takeover.
|
| CVE-2026-64561 |
|
Vulnerability in CVE-2026-64561 (CVE-2026-64561)
vulnerability in CVE-2026-64561 (CVE-2026-64561). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16623 |
|
Code Injection in wordpress (CVE-2026-16623)
code injection in wordpress (CVE-2026-16623). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16618 |
|
Unrestricted File Upload in wordpress (CVE-2026-16618)
vulnerability in wordpress (CVE-2026-16618). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16548 |
|
Unrestricted File Upload in wordpress (CVE-2026-16548)
vulnerability in wordpress (CVE-2026-16548). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16547 |
|
Vulnerability in wordpress (CVE-2026-16547)
vulnerability in wordpress (CVE-2026-16547). Confidential information can be exposed externally.
|
| CVE-2026-16546 |
|
Vulnerability in wordpress (CVE-2026-16546)
vulnerability in wordpress (CVE-2026-16546). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16536 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-16536)
SSRF in wordpress (CVE-2026-16536). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16296 |
|
Open Redirect in wordpress (CVE-2026-16296)
vulnerability in wordpress (CVE-2026-16296). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16295 |
|
Vulnerability in wordpress (CVE-2026-16295)
vulnerability in wordpress (CVE-2026-16295). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16293 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16293)
cross-site scripting in wordpress (CVE-2026-16293). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16070 |
|
Vulnerability in wordpress (CVE-2026-16070)
vulnerability in wordpress (CVE-2026-16070). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16069 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16069)
cross-site scripting in wordpress (CVE-2026-16069). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16068 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-16068)
cross-site scripting in wordpress (CVE-2026-16068). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16056 |
|
Vulnerability in wordpress (CVE-2026-16056)
vulnerability in wordpress (CVE-2026-16056). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-16035 |
|
Vulnerability in wordpress (CVE-2026-16035)
vulnerability in wordpress (CVE-2026-16035). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15958 |
|
Vulnerability in wordpress (CVE-2026-15958)
vulnerability in wordpress (CVE-2026-15958). Confidential information can be exposed externally.
|
| CVE-2026-15233 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-15233)
cross-site scripting in wordpress (CVE-2026-15233). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14939 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-14939)
SSRF in wordpress (CVE-2026-14939). Confidential information can be exposed externally.
|
| CVE-2026-14872 |
|
SQL Injection in wordpress (CVE-2026-14872)
SQL injection in wordpress (CVE-2026-14872). Confidential information can be exposed externally.
|
| CVE-2026-14848 |
|
Vulnerability in wordpress (CVE-2026-14848)
vulnerability in wordpress (CVE-2026-14848). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14824 |
|
Cross-Site Scripting (XSS) in wordpress (CVE-2026-14824)
cross-site scripting in wordpress (CVE-2026-14824). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14816 |
|
Vulnerability in wordpress (CVE-2026-14816)
vulnerability in wordpress (CVE-2026-14816). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-12698 |
|
Vulnerability in wordpress (CVE-2026-12698)
vulnerability in wordpress (CVE-2026-12698). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-11366 |
|
Authentication Bypass in wordpress (CVE-2026-11366)
authentication bypass in wordpress (CVE-2026-11366). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-10526 |
|
SSRF (Server-Side Request Forgery) in wordpress (CVE-2026-10526)
SSRF in wordpress (CVE-2026-10526). Risk of unauthorized operations or information disclosure.
|