Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

150 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.2)0.93%—Flowiseai Flowise7/3/202617/6/2026
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, the /api/v1/attachments/:chatflowId/:chatId endpoint is listed in WHITELIST_URLS, allowing unauthenticated access to the file upload API. While the server validates uploads based on the MIME types defined…
AnalizadaAlta (8.7)0.65%—Flowiseai Flowise7/3/202617/6/2026
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.0.13, Flowise trusts any HTTP client that sets the header x-request-from: internal, allowing an authenticated tenant session to bypass all /api/v1/** authorization checks. With only a browser cookie, a…
AnalizadaMedia (6.5)0.64%—Flowiseai Flowise17/10/202517/6/2026
Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field.
AnalizadaAlta (8.4)6.6%—Flowiseai Flowise14/10/20255/10/2026
Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node VM sandbox escape due to insecure use of integrated modules (Puppeteer and Playwright) within the nodevm execution environment. An authenticated attacker able to create…
AnalizadaCrítica (9.9)13%—Flowiseai Flowise8/10/202530/9/2026
Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool in Flowise do not restrict file path access, allowing authenticated attackers to exploit this vulnerability to read and write arbitrary files to any path in the file…
AnalizadaAlta (8.8)11%—Flowiseai Flowise6/10/202530/9/2026
Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in version 3.0.7 of FlowiseAI allows authenticated users to upload arbitrary files without proper validation. This enables attackers to persistently store malicious Node.js web shells on the server,…
AnalizadaMedia (6.1)14%—Flowiseai Flowise6/10/202530/9/2026
Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log.
AnalizadaMedia (6.1)0.41%—Flowiseai Flowise6/10/202530/9/2026
Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log.
AnalizadaCrítica (10)86%💥 ExploitFlowiseai Flowise22/9/202517/6/2026
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an external MCP server. This node parses the user-provided mcpServerConfig string…
AnalizadaAlta (7.5)5.0%—Flowiseai Flowise22/9/202530/9/2026
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side Request Forgery (SSRF) vulnerability was discovered in the /api/v1/fetch-links endpoint of the Flowise application. This vulnerability allows an attacker to use the Flowise server as a proxy to…
AplazadaCrítica (9.6)3.4%—Flowiseai FlowiseAI22/9/202530/9/2026
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to August 2025 Cloud-Hosted Flowise, an authenticated vulnerability in Flowise Cloud allows any user on the free tier to access sensitive environment variables from other tenants via the Custom JavaScript Function node. This…
AnalizadaCrítica (9.8)50%💥 ExploitFlowiseai Flowise12/9/202530/9/2026
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint in Flowise returns sensitive information including a valid password reset `tempToken` without authentication or verification. This enables any attacker to generate a…
AnalizadaCrítica (9.8)75%💥 ExploitFlowiseai Flowise14/8/202517/6/2026
The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inherent authentication and authorization model is minimal and lacks role-based access controls (RBAC). Furthermore, in Flowise versions before 3.0.1 the default…
AnalizadaAlta (7.6)0.31%—Flowiseai Flowise9/4/20255/10/2026
Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores.
AnalizadaCrítica (9.8)56%💥 ExploitFlowiseai Flowise4/3/202530/9/2026
FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.
AnalizadaMedia (6.1)0.56%—Flowiseai EmbedFlowiseai Flowise25/9/202417/6/2026
Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.
AnalizadaAlta (7.5)14%—Flowiseai Flowise27/8/202417/6/2026
An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the “/api/v1/get-upload-file” api endpoint.
ModificadaAlta (8.1)45%💥 ExploitFlowiseai Flowise27/8/202417/6/2026
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.
ModificadaMedia (6.1)0.40%—Flowiseai Flowise1/7/202417/6/2026
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting vulnerability occurs in the `/api/v1/credentials/id` endpoint. If the default configuration is used (unauthenticated), an attacker may be able to craft a specially…
ModificadaMedia (6.1)0.46%—Flowiseai Flowise1/7/202417/6/2026
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting vulnerability occurs in the `/api/v1/chatflows-streaming/id` endpoint. If the default configuration is used (unauthenticated), an attacker may be able to craft a…
ModificadaMedia (6.1)0.40%—Flowiseai Flowise1/7/202417/6/2026
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting vulnerability occurs in the `/api/v1/public-chatflows/id` endpoint. If the default configuration is used (unauthenticated), an attacker may be able to craft a specially…
ModificadaMedia (6.1)0.41%—Flowiseai Flowise1/7/202417/6/2026
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scripting vulnerability occurs in the `api/v1/chatflows/id` endpoint. If the default configuration is used (unauthenticated), an attacker may be able to craft a specially crafted…
ModificadaAlta (7.5)8.5%—Flowiseai Flowise1/7/202417/6/2026
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets the Access-Control-Allow-Origin header to all, allowing arbitrary origins to connect to the website. In the default configuration (unauthenticated), arbitrary origins may…
ModificadaAlta (7.5)1.8%💥 ExploitFlowiseai Flowise1/7/202417/6/2026
Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-file` endpoint in `index.ts` is vulnerable to arbitrary file read due to lack of sanitization of the `fileName` body parameter. No known patches for this issue are…
AnalizadaAlta (7.6)60%💥 ExploitFlowiseai Flowise29/4/202417/6/2026
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.
Orbitaley — Vulnerabilidades