Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2655 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 1.1% | — | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers. Because Flowise's authentication and authorization model is minimal and lacks… | |
| Analizada | Alta (8.6) | 0.38% | — | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a device left logged in, remains authenticated as the legitimate user even… | |
| Analizada | Crítica (9.3) | 4.4% | 💥 Exploit | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-traversal value (e.g., '../../../../../tmp') as the chatflow id, an… | |
| Analizada | Crítica (9.3) | 0.90% | — | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories, potentially enabling remote code… | |
| Analizada | Alta (8.7) | 0.47% | — | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification, as the application does not enforce a current-password check on the… | |
| Analizada | Crítica (9.3) | 0.68% | — | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and authenticate to the system, gaining full API access without… | |
| Modificada | Alta (8.7) | 1.6% | 💥 Exploit | Flowiseai Flowise | 25/6/2026 | 30/9/2026 | Flowise before 3.0.6 contains an arbitrary file read vulnerability in the chatId parameter of the /api/v1/get-upload-file and /api/v1/openai-assistants-file/download endpoints. The chatId value is not validated and is passed to streamStorageFile(), where a fallback file-lookup path constructed without the orgId is… | |
| Analizada | Media (5.6) | 0.10% | — | Flowiseai Flowise | 24/6/2026 | 26/6/2026 | Flowise before 3.0.13 uses bcrypt with default salt rounds of 5, providing only 32 iterations instead of the OWASP-recommended minimum of 10 rounds. Attackers can crack password hashes approximately 30 times faster with modern GPU hardware, potentially compromising all user accounts in a database breach scenario. | |
| Analizada | Alta (8.7) | 2.0% | 💥 Exploit | Flowiseai Flowise | 24/6/2026 | 26/6/2026 | Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users to retrieve an organization's complete SSO configuration, including OAuth client secrets in cleartext, by providing an organizationId parameter.… | |
| Analizada | Media (4.3) | 0.13% | — | Flowiseai Flowise | 24/6/2026 | 26/6/2026 | Flowise before 3.1.0 (npm package flowise, versions 3.0.13 and earlier) uses a weak hardcoded default value 'Secre$t' for the TOKEN_HASH_SECRET environment variable in packages/server/src/enterprise/utils/tempTokenUtils.ts when the variable is not configured. This secret derives the AES-256-CBC key used to encrypt… | |
| Analizada | Alta (8.5) | 0.52% | — | Flowiseai Flowise | 24/6/2026 | 30/9/2026 | Flowise through 2.2.7 contains a SQL injection vulnerability in the importChatflows API. Due to insufficient validation of the chatflow.id value, an authenticated user can supply a crafted JSON import file whose id field is concatenated unsanitized into a SQL IN clause, allowing arbitrary SQL to be executed, including… | |
| Analizada | Crítica (9.3) | 1.2% | 💥 Exploit | Langflow | 23/6/2026 | 24/6/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, unauthenticated users can upload any amount of data to the server without any limitations. No need for any prior knowledge, only network access to Langflow. This can lead to space exhaustion on the server. In addition, in… | |
| Analizada | Crítica (9.6) | 0.66% | — | Langflow | 23/6/2026 | 24/6/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, by controlling a files that are digested into the RAG, an attacker can direct the node to read any file on the file-system by absolute path. All components based on BaseFileComponent are vulnerable to the vulnerability. This… | |
| Analizada | Alta (7.5) | 0.58% | — | Langflow | 23/6/2026 | 24/6/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.0.19, an attacker can send a /api/v1/files/upload/ request without any authentication token/cookies and abuse a very long multipart form boundary to make the langflow app unusable for all users for an indefinite amount of time.… | |
| Analizada | Media (6.1) | 0.22% | — | Langflow | 23/6/2026 | 24/6/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.7.0, the logout button does not clear the session. The previous user stays logged in unless another user explicitly logs in. This vulnerability is fixed in 1.7.0. | |
| Analizada | Media (6.1) | 0.44% | — | Langflow | 23/6/2026 | 26/6/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.10.0, the "Shareable Playground" (or "Public Flows" in code) contains a potential arbitrary file-read vulnerability, depending on the exact flow configuration used. By making a flow public, public execution of the flow is… | |
| Analizada | Crítica (9.6) | 0.78% | 💥 PoC | Langflow | 23/6/2026 | 26/6/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.2, the "Shareable Playground" (or "Public Flows" in code) contains a critical RCE vulnerability. Shareable Playground feature works by enabling the execution of workflows by unauthenticated users, by accessing a link.… | |
| Analizada | Media (6.5) | 0.47% | — | Langflow | 23/6/2026 | 26/6/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow is vulnerable to Path Traversal in the Knowledge Bases API (POST /api/v1/knowledge_bases). This occurs because user-supplied knowledge base names are used directly to create file paths without proper sanitization or… | |
| Analizada | Alta (8.8) | 0.50% | — | Langflow | 23/6/2026 | 26/6/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.0, Langflow's /api/v1/monitor router exposes 7 endpoints that perform read, write, and delete operations on user-owned resources — messages, sessions, build artifacts, and LLM transaction logs — without verifying that the… | |
| Analizada | Alta (8.4) | 0.89% | ⚠ Explotación activa💥 PoC | Langflow | 23/6/2026 | 7/10/2026 | Langflow is a tool for building and deploying AI-powered agents and workflows. Prior to 1.9.1, an Insecure Direct Object Reference (IDOR) vulnerability in /api/v1/responses endpoint allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. This… | |
| Analizada | Media (6) | 0.32% | — | Flowiseai Flowise | 23/6/2026 | 25/6/2026 | Flowise before 3.1.0 contains a server-side request forgery vulnerability in the Execute Flow node that allows attackers to bypass security validation by providing intranet addresses through the base URL field. Attackers can initiate HTTP requests to internal network addresses, access cloud metadata, and enumerate… | |
| Analizada | Alta (8.7) | 7.5% | 💥 Exploit | Flowiseai Flowise | 23/6/2026 | 25/6/2026 | Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation and a regex bypass in local file access restrictions. An attacker with a Flowise account of any role, or API access with view/update permissions for chatflows, can… | |
| Analizada | Alta (8.7) | 0.42% | — | Flowiseai Flowise | 23/6/2026 | 30/9/2026 | Flowise before 3.0.10 (affected versions 3.0.7 and earlier) contains an unverified email change vulnerability. An authenticated user can change the account email address, used as a login identifier and password-recovery channel, via the account profile endpoint without confirming the change to the original email… | |
| Analizada | Media (5.3) | 0.39% | — | Flowiseai Flowise | 22/6/2026 | 25/6/2026 | Flowise before 3.1.2 contains an information disclosure vulnerability in the /api/v1/chatflows/apikey/:apikey endpoint. When the keyonly query parameter is omitted (the default), the endpoint returns not only the chatflows bound to the supplied API key but also all chatflows across every workspace that have no API key… | |
| Analizada | Crítica (9.8) | 0.50% | — | Langflow | 22/6/2026 | 26/6/2026 | IBM Langflow OSS 1.0.0 through 1.8.4 could allow unauthenticated attackers to access protected MCP project resources and execute MCP operations due to improper authorization enforcement in the Streamable MCP transport endpoint. |