8.1

CVSS3.1

CVE-2026-41267 - Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Associa…

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, an improper mass assignment (JSON injection) vulnerability in the account registration endpoint of Flowise Cloud allows unauthenticated attackers to inject server-managed fields and nested objec…

📅 Published: April 23, 2026, 7:12 p.m. 🔄 Last Modified: April 24, 2026, 3:14 p.m.

7.7

CVSS4.0

CVE-2026-41266 - Flowise: Sensitive Data Leak in public-chatbotConfig

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, /api/v1/public-chatbotConfig/:id ep exposes sensitive data including API keys, HTTP authorization headers and internal configuration without any authentication. An attacker with knowledge just o…

📅 Published: April 23, 2026, 7:11 p.m. 🔄 Last Modified: April 25, 2026, 1:27 a.m.

9.4

CVSS4.0

CVE-2026-41137 - Flowise: Code Injection in CSVAgent leads to Authenticated RCE

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, The CSVAgent allows providing a custom Pandas CSV read code. Due to lack of sanitization, an attacker can provide a command injection payload that will get interpolated and executed by the serve…

📅 Published: April 23, 2026, 7:10 p.m. 🔄 Last Modified: April 24, 2026, 3:15 p.m.

8.8

CVSS3.1

CVE-2026-41138 - Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verificati…

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, there is a remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas. The user’s input is directly applied to the question parameter within t…

📅 Published: April 23, 2026, 7:05 p.m. 🔄 Last Modified: April 24, 2026, 6:20 p.m.

8.2

CVSS4.0

CVE-2026-41259 - Mastodon: Insufficient verification of email addresses

Mastodon is a free, open-source social network server based on ActivityPub. Prior to v4.5.9, v4.4.16, and v4.3.22, Mastodon allows restricting new user sign-up based on e-mail domain names, and performs basic validation on e-mail addresses, but fails to restrict characters that are interpreted diff…

📅 Published: April 23, 2026, 6:55 p.m. 🔄 Last Modified: April 23, 2026, 7:24 p.m.

7.7

CVSS4.0

CVE-2026-41205 - Mako: Path traversal via double-slash URI prefix in TemplateLookup

Mako is a template library written in Python. Prior to 1.3.11, TemplateLookup.get_template() is vulnerable to path traversal when a URI starts with // (e.g., //../../../secret.txt). The root cause is an inconsistency between two slash-stripping implementations. Any file readable by the process can …

📅 Published: April 23, 2026, 6:52 p.m. 🔄 Last Modified: April 24, 2026, 2:50 p.m.

8.9

CVSS4.0

CVE-2026-41247 - elFinder: Command injection in resize background color parameter when using ImageMagick CLI

elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In c…

📅 Published: April 23, 2026, 6:47 p.m. 🔄 Last Modified: April 25, 2026, 1:25 a.m.

8.1

CVSS3.1

CVE-2026-41246 - Contour: Lua code injection via Cookie Path Rewrite Policy

Contour is a Kubernetes ingress controller using Envoy proxy. From v1.19.0 to before v1.33.4, v1.32.5, and v1.31.6, Contour's Cookie Rewriting feature is vulnerable to Lua code injection. An attacker with RBAC permissions to create or modify HTTPProxy resources can craft a malicious value in spec.r…

📅 Published: April 23, 2026, 6:44 p.m. 🔄 Last Modified: April 24, 2026, 6:20 p.m.

5.9

CVSS3.1

CVE-2026-41213 - @node-oauth/oauth2-server: PKCE code_verifier ABNF not enforced in token exchange allows brute-forc…

@node-oauth/oauth2-server is a module for implementing an OAuth2 server in Node.js. The token exchange path accepts RFC7636-invalid code_verifier values (including one-character strings) for S256 PKCE flows. Because short/weak verifiers are accepted and failed verifier attempts do not consume the a…

📅 Published: April 23, 2026, 6:33 p.m. 🔄 Last Modified: April 25, 2026, 1:23 a.m.

8.7

CVSS3.1

CVE-2026-41241 - pretalx: Stored cross-site scripting in organiser search typeahead

pretalx is a conference planning tool. Prior to 2026.1.0, The organiser search in the pretalx backend rendered submission titles, speaker display names, and user names/emails into the result dropdown using innerHTML string interpolation. Any user who controls one of those fields (which includes any…

📅 Published: April 23, 2026, 6:30 p.m. 🔄 Last Modified: April 23, 2026, 7:23 p.m.
Total resulsts: 346569
Page 41 of 34,657
« previous page » next page
Filters