Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.5 CRITICAL
CVE-2026-70477 — Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with…

flowise | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.3 HIGH
CVE-2026-70476 — Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billi…

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.r…

flowise | Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.1 HIGH
CVE-2026-70475 — Flowise: Missing Authorization on Execution Update Endpoint

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lack…

flowise | Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.9 MEDIUM
CVE-2026-48154 — GoRest: InMemorySecret2FA race condition allows process crash via concurrent map access

GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronize…

Remote | Race Condition
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.1 HIGH
CVE-2026-47682 — CVAT: Missing path-containment validation in multiple entry points allows arbitrary path …

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage that's been added to a CVAT …

Remote | Misconfiguration
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.5 HIGH
CVE-2026-18810 — H3C NX15 networkSetup missing authentication

A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack ma…

nx15 | Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.8 HIGH
CVE-2026-18657 — Executable Resolution from Untrusted Project Directory in Kiro CLI on Windows

An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory conta…

kiro_cli | Path Traversal
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.8 HIGH
CVE-2026-18656 — Executable Resolution from Untrusted Project Directory in Kiro IDE on Windows

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory cont…

kiro_ide | Path Traversal
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.8 HIGH
CVE-2026-16793 — Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker t…

xclarity_orchestrator | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.1 MEDIUM
CVE-2026-16792 — Global TLS Certificate Validation Bypass in Lenovo XClarity Orchestrator

An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive …

xclarity_orchestrator | Cryptography
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
3.9 LOW
CVE-2026-16791 — Predictable Temporary File Symlink Vulnerability in Lenovo XClarity Essentials OneCLI

A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite or truncate arbitrary local …

| Path Traversal
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.6 HIGH
CVE-2026-70474 — Flowise: Cross-Workspace OAuth2 Credential Metadata Leak

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look up credentials by id alone …

flowise | Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.3 HIGH
CVE-2026-70473 — Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-w…

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert history in…

flowise | Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.1 HIGH
CVE-2026-70472 — Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled credential paramet…

flowise | Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.1 HIGH
CVE-2026-70471 — Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure

Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox without requiring variables:v…

flowise | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.5 MEDIUM
CVE-2026-69704 — Atals-Livre SQL Injection via Unsanitized GET Parameter in supp()

Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion helper function. At…

Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.8 CRITICAL
CVE-2026-69703 — Atlas-Livre Unauthenticated Access via Admin Controllers Missing Exit

Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guar…

Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.5 MEDIUM
CVE-2026-69702 — SnailJob 1.7.0 Denial of Service via FuryUtil.deserialize OOM

SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed payloa…

Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.5 MEDIUM
CVE-2026-68743 — Sssd: sssd: pam responder out-of-bounds read via unchecked auth_token_length in protocol …

A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before processing. A local attacker ca…

Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.0 MEDIUM
CVE-2026-66300 — SNOMED International Snowstorm reflected XSS

SNOMED International Snowstorm contains a reflected XSS vulnerability within the "Web Route" redirection functionality. An attacker can inject arbitrary JavaScript which will execute upon a target us…

Remote | Cross-Site Scripting
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
Showing 20 of 9577 Results