Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28561
Total
2193
Critical
8548
High
8866
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-28525 | MEDIUM | 6.8 | SWUpdate contains an integer underflow vulnerability in the multipart upload parser in mongoose_multipart.c that allows unauthenticated attackers to cause a denial of service by sending … | Apr 23, 2026 |
| CVE-2026-41279 | HIGH | 7.5 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST /api/v1/text-to-speech/generate) … | Apr 23, 2026 |
| CVE-2026-41278 | HIGH | 7.5 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the GET /api/v1/public-chatflows/:id endpoint returns the … | Apr 23, 2026 |
| CVE-2026-41277 | HIGH | 8.8 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the … | Apr 23, 2026 |
| CVE-2026-41276 | CRITICAL | 9.8 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to … | Apr 23, 2026 |
| CVE-2026-41275 | HIGH | 7.5 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.flowiseai.com … | Apr 23, 2026 |
| CVE-2026-41273 | HIGH | 8.2 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vulnerability … | Apr 23, 2026 |
| CVE-2026-41272 | HIGH | 7.1 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosRequest and … | Apr 23, 2026 |
| CVE-2026-41271 | HIGH | 8.3 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnerability … | Apr 23, 2026 |
| CVE-2026-41270 | HIGH | 7.1 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protection … | Apr 23, 2026 |
| CVE-2026-41269 | HIGH | 7.1 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings … | Apr 23, 2026 |
| CVE-2026-41268 | CRITICAL | 9.8 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical … | Apr 23, 2026 |
| CVE-2026-41267 | HIGH | 8.1 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection) … | Apr 23, 2026 |
| CVE-2026-41266 | HIGH | 7.5 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes sensitive data including … | Apr 23, 2026 |
| CVE-2026-41265 | CRITICAL | 9.8 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the … | Apr 23, 2026 |
| CVE-2026-41264 | CRITICAL | 9.8 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the … | Apr 23, 2026 |
| CVE-2026-41138 | HIGH | 8.8 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution … | Apr 23, 2026 |
| CVE-2026-41137 | HIGH | 8.8 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent allows providing a custom … | Apr 23, 2026 |
| CVE-2026-25874 | UNKNOWN | — | LeRobot through 0.5.1 contains an unsafe deserialization vulnerability in the async inference pipeline where pickle.loads() is used to deserialize data received over unauthenticated gRPC channels … | Apr 23, 2026 |
| CVE-2026-6074 | UNKNOWN | — | A path traversal condition in Intrado 911 Emergency Gateway could allow an attacker with existing network access the ability to access the EGW management interface … | Apr 23, 2026 |
| CVE-2026-41259 | UNKNOWN | — | Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on … | Apr 23, 2026 |
| CVE-2026-41247 | UNKNOWN | — | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the … | Apr 23, 2026 |
| CVE-2026-41246 | HIGH | 8.1 | Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable to Lua … | Apr 23, 2026 |
| CVE-2026-41241 | HIGH | 8.7 | pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submission titles, speaker display names, and user names/emails … | Apr 23, 2026 |
| CVE-2026-41213 | MEDIUM | 5.9 | @node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKCE … | Apr 23, 2026 |