Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2702▼ 361 respecto a la semana anterior
Críticas / altas1278▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)216▼ 113 respecto a la semana anterior
2655 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.6) | 0.48% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Mass Assignment vulnerability in the DocumentStore creation endpoint allows authenticated users to control the primary key (id) and internal state fields of DocumentStore entities. Because the service uses… | |
| Modificada | Alta (7.7) | 0.65% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, this vulnerability allows remote attackers to bypass authentication on affected installations of FlowiseAI Flowise. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Alta (7.5) | 0.25% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the password reset functionality on cloud.flowiseai.com sends a reset password link over the unsecured HTTP protocol instead of HTTPS. This behavior introduces the risk of a man-in-the-middle (MITM) attack, where… | |
| Modificada | Alta (7.7) | 0.44% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise contains an authentication bypass vulnerability that allows an unauthenticated attacker to obtain OAuth 2.0 access tokens associated with a public chatflow. By accessing a public chatflow configuration… | |
| Analizada | Alta (7.1) | 0.35% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the core security wrappers (secureAxiosRequest and secureFetch) intended to prevent Server-Side Request Forgery (SSRF) contain multiple logic flaws. These flaws allow attackers to bypass the allow/deny lists via… | |
| Analizada | Alta (8.3) | 0.34% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) vulnerability exists in FlowiseAI's POST/GET API Chain components that allows unauthenticated attackers to force the server to make arbitrary HTTP requests to internal and… | |
| Modificada | Alta (8.3) | 0.33% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, a Server-Side Request Forgery (SSRF) protection bypass vulnerability exists in the Custom Function feature. While the application implements SSRF protection via HTTP_DENY_LIST for axios and node-fetch libraries,… | |
| Modificada | Alta (8.8) | 0.69% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the Chatflow configuration file upload settings can be modified to allow the application/javascript MIME type. This lets an attacker upload .js files even though the frontend doesn’t normally allow JavaScript… | |
| Analizada | Crítica (9.8) | 1.2% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, Flowise is vulnerable to a critical unauthenticated remote command execution (RCE) vulnerability. It can be exploited via a parameter override bypass using the FILE-STORAGE:: keyword combined with a NODE_OPTIONS… | |
| Analizada | Crítica (9.8) | 0.48% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection) vulnerability in the account registration endpoint of Flowise Cloud allows unauthenticated attackers to inject server-managed fields and nested objects during account… | |
| Modificada | Alta (7.7) | 0.50% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes sensitive data including API keys, HTTP authorization headers and internal configuration without any authentication. An attacker with knowledge just of a chatflow UUID… | |
| Analizada | Crítica (9.2) | 0.56% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the Airtable_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. Using prompt injection techniques,… | |
| Analizada | Crítica (9.2) | 1.2% | 💥 Exploit | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the specific flaw exists within the run method of the CSV_Agents class. The issue results from the lack of proper sandboxing when evaluating an LLM generated python script. An attacker can leverage this… | |
| Modificada | Alta (8.8) | 0.84% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas. The user’s input is directly applied to the question parameter within the prompt template… | |
| Analizada | Crítica (9.4) | 2.1% | — | Flowiseai Flowise | 23/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent allows providing a custom Pandas CSV read code. Due to lack of sanitization, an attacker can provide a command injection payload that will get interpolated and executed by the server. This… | |
| Modificada | Alta (7.7) | 0.59% | — | Argoproj Argo Workflows | 23/4/2026 | 15/7/2026 | Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From 3.6.5 to 4.0.4, an unchecked array index in the pod informer's podGCFromPod() function causes a controller-wide panic when a workflow pod carries a malformed workflows.argoproj.io/pod-gc-strategy… | |
| Analizada | Crítica (9.9) | 1.3% | — | Flowiseai Flowise | 21/4/2026 | 17/6/2026 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker can add an MCP stdio server with an arbitrary command, achieving command execution. The vulnerability lies in a bug in the… | |
| Analizada | Media (5.5) | 0.33% | — | Oracle Workflow | 21/4/2026 | 17/6/2026 | Vulnerability in the Oracle Workflow product of Oracle E-Business Suite (component: Workflow Loader). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle Workflow. While the vulnerability is in… | |
| Analizada | Crítica (9.3) | 0.74% | — | Flowsint | 20/4/2026 | 17/6/2026 | Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of nodes and relationships. The… | |
| Analizada | Crítica (9.3) | 0.65% | — | Digiwin Easyflow .net | 20/4/2026 | 17/6/2026 | EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Analizada | Crítica (9.3) | 0.65% | — | Digiwin Easyflow .net | 20/4/2026 | 17/6/2026 | EasyFlow .NET developed by Digiwin has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents. | |
| Aplazada | Baja (2) | 0.33% | — | LangflowAI | 20/4/2026 | 17/6/2026 | A flaw has been found in langflow-ai langflow up to 1.8.3. This affects an unknown function of the file src/frontend/src/modals/IOModal/components/chatView/chatMessage/components/edit-message.tsx of the component Frontend React Component Rendering. Executing a manipulation can lead to cross site scripting. The attack… | |
| Aplazada | Baja (2.1) | 0.39% | — | LangflowAI | 20/4/2026 | 17/6/2026 | A vulnerability was detected in langflow-ai langflow up to 1.8.3. The impacted element is the function get_client_ip/install_mcp_config of the file src/backend/base/langflow/api/v1/mcp_projects.py of the component Model Context Protocol Configuration API. Performing a manipulation of the argument X-Forwarded-For… | |
| Aplazada | Baja (2.1) | 0.24% | — | LangflowAI | 20/4/2026 | 17/6/2026 | A security vulnerability has been detected in langflow-ai langflow up to 1.8.3. The affected element is the function create_project/encrypt_auth_settings of the file src/backend/base/Langflow/api/v1/projects.py of the component Project Creation Endpoint. Such manipulation of the argument auth_settings leads to… | |
| Aplazada | Baja (2) | 0.38% | — | LangflowAI | 20/4/2026 | 17/6/2026 | A weakness has been identified in langflow-ai langflow up to 1.8.3. Impacted is the function remove_api_keys/has_api_terms of the file src/backend/base/langflow/api/utils/core.py of the component Flow Using API. This manipulation causes unprotected storage of credentials. The attack can be initiated remotely. The… |