Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-69263 — Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blo…

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx, but packages/components/no…

flowise | Remote | Misconfiguration
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.1 HIGH
CVE-2026-69262 — Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentf…

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPermission('chatflows:delete,a…

flowise | Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.4 CRITICAL
CVE-2026-69259 — Flowise RCE via SQLite Record Manager Node

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordmanager/SQLiteRecordManager/…

flowise | Remote | Path Traversal
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.8 HIGH
CVE-2026-69258 — Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `over…

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and…

flowise | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.6 HIGH
CVE-2026-69257 — Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IPv4-mapped IPv6 addresses su…

flowise | Remote | Misconfiguration
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.4 CRITICAL
CVE-2026-69256 — Flowise: Remote Code Execution Vulnerability in CSVAgent

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is executed through pyodide; altho…

flowise | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.2 CRITICAL
CVE-2026-69255 — Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.ts extracted attacker-contr…

flowise | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.4 HIGH
CVE-2026-64634 — Reporter Service Local Privilege Escalation

A vulnerability allowing local privilege escalation to the Reporter service context.

one one | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
10.0 CRITICAL
CVE-2026-64633 — Agent Host Remote Unauthenticated Code Execution

A vulnerability allowing remote unauthenticated code execution on the agent host.

one one | Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.5 HIGH
CVE-2026-64631 — SQL Injection in Database Management System

A vulnerability allowing a low-privileged user to inject SQL and extract database contents.

one one | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.3 MEDIUM
CVE-2026-64630 — Insecure Direct Object Reference in Report Data Access

A vulnerability allowing a low-privileged user to retrieve report data outside the scope of a shared report link.

one one | Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.8 CRITICAL
CVE-2026-63456 — Authentication bypass via spoofed HTTP headers Orchestrator REST API

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system funct…

Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.8 CRITICAL
CVE-2026-63455 — Authentication bypass via spoofed HTTP headers Orchestrator REST API

Multiple vulnerabilities in the REST API interface of HPE Networking SD-WAN Orchestrator could allow an unauthenticated remote attacker to bypass web authentication mechanisms and access system funct…

Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.7 HIGH
CVE-2026-58075 — Arbitrary File Read Vulnerability in [Product/Vendor]

A vulnerability allowing an unauthenticated attacker to read arbitrary files from the host, which can be further leveraged toescalate privileges locally.

one one | Remote | Path Traversal
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.6 HIGH
CVE-2026-58074 — Server-Side Arbitrary Code Execution

A vulnerability allowing a high-privileged user to execute arbitrary code on the server.

one one | Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.5 CRITICAL
CVE-2026-58073 — Veeam Service Provider Console Authentication Bypass

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to impersonate a managed agent andobtain that agent's credentials.

Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.0 CRITICAL
CVE-2026-58072 — Veeam Service Provider Console Arbitrary File Write Remote Code Execution

A vulnerability in Veeam Service Provider Console allowing arbitrary file write on the management server, which can lead to remotecode execution.

Remote | Path Traversal
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.2 HIGH
CVE-2026-58071 — Veeam Service Provider Console Authentication Bypass Vulnerability

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to access the proxied appliance API asPortal Administrator during a short window after an administrator session …

Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.7 HIGH
CVE-2026-58067 — Veeam Service Provider Console Denial of Service Vulnerability

A vulnerability in Veeam Service Provider Console allowing an unauthenticated attacker to exhaust host memory and cause adenial of service.

Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.5 HIGH
CVE-2026-56848 — Node.js HTTP/2 Heap Use-After-Free Vulnerability

A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` to be called re-entrantly while `nghttp2_session_mem_recv()` is executing, resulting in a heap-use-after-free. This vulnerabil…

Remote | Memory Corruption
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
Showing 20 of 9535 Results