2026-06-25
2026-06-25 22:16Z
CRIT

CVE-2025-71338 — Flowise: contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71338

Flowise contains a path traversal vulnerability in the /api/v1/document-store/loader/process endpoint that allows unauthenticated attackers to write arbitrary files to the filesystem. Attackers can exploit unsanitized fileName parameters with ../ sequences to overwrite critical files like package.json and achieve remote code execution when the application restarts. CVSSv3.1 10.0 (CRITICAL)

CWECWE 73VNDFlowiseTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-25
2026-06-25 22:16Z
CRIT

CVE-2025-71336 — Flowise: before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71336

Flowise before 3.0.6 (affected versions 2.2.7-patch.1 and earlier) contains an unsandboxed remote code execution vulnerability in the Custom MCP feature, which is designed to execute OS commands such as launching local MCP servers. Because Flowise's authentication and authorization model is minimal and lacks role-based access control, and the default installation runs without authentication unless FLOWISE_USERNAME and FLOWISE_PASSWORD are set, an attacker can send a crafted J CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 22:16Z
HIGH

CVE-2025-71335 — Flowise: before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71335

Flowise before 3.0.10 (affected versions 3.0.7 and earlier) fails to invalidate existing sessions and session tokens after a user changes their password. An attacker who already holds an active session, for example via a stolen session token or a device left logged in, remains authenticated as the legitimate user even after the user rotates their credentials, undermining the security purpose of the password change. CVSSv3.1 8.1 (HIGH)

CWECWE 613VNDFlowiseTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 22:16Z
CRIT

CVE-2025-71334 — Flowise: before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71334

Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatflowId and chatId parameters are UUIDs or numbers in file handling operations. By supplying a path-traversal value (e.g., '../../../../../tmp') as the chatflow id, an unauthenticated attacker can use the /api/v1/chatflows endpoint (via addBase64FilesToStorage) to write arbitrary files, and the /api/v1/get-upload-file and /api/v1/ope CVSSv3.1 9.8 (CRITICAL)

CWECWE 73VNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 22:16Z
CRIT

CVE-2025-71333 — Flowiseai Flowise: through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71333

Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. Attackers can exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories, potentially enabling remote code execution and server compromise. CVSSv3.1 9.8 (CRITICAL) · EPSS 40th percentile

CWECWE 73VNDFlowiseaiVNDFlowiseTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 22:16Z
HIGH

CVE-2025-71328 — Flowise: This can lead to full account takeover, particularly if an attacker can hijack or

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71328

Flowise before 3.0.10 contains an unverified password change vulnerability. An authenticated user can change their account password through the account settings (Security) section without supplying the current password or any additional verification, as the application does not enforce a current-password check on the credential change. This can lead to full account takeover, particularly if an attacker can hijack or coerce an authenticated session. CVSSv3.1 8.3 (HIGH)

CWECWE 620VNDFlowiseTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-25
2026-06-25 22:16Z
CRIT

CVE-2025-71327 — Flowise: contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2025-71327

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers to create user accounts. Remote attackers can exploit this endpoint to register arbitrary accounts and authenticate to the system, gaining full API access without credentials. CVSSv3.1 9.1 (CRITICAL)

CWECWE 306VNDFlowiseTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-25
2026-06-25 21:16Z
CRIT

CVE-2026-56445 — STORE: The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56445

The qrscp application's C-STORE handler uses a specific instance from attacker-supplied DICOM datasets directly in os.path.join() without sanitization, allowing file writes to arbitrary paths. CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDStoreTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-25
2026-06-25 21:16Z
HIGH

CVE-2026-12473 — Two: data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12473

Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default configuration fetch an arbitrary URL parameter without validation. A global authentication service in OHIF automatically injects the authenticated user's OIDC Bearer token into the resulting requests, sending it to the attacker-controlled server. DICOMweb data sources are not impacted. CVSSv3.1 8.2 (HIGH)

CWECWE 918VNDTwoTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 20:17Z
CRIT

CVE-2026-7531 — Wolfssl Wolfssl: Use-after-free in PQC hybrid key-share handling.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-7531

Use-after-free in PQC hybrid key-share handling. This is an incomplete-fix follow-up to CVE-2026-5460 (released in 5.9.1): a malicious TLS 1.3 server sending a truncated PQC hybrid KeyShare can still trigger the error cleanup path to operate on freed memory. CVSSv3.1 9.8 (CRITICAL)

CWECWE 416VNDWolfsslTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 19:16Z
CRIT

CVE-2026-57700 — Upload: Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-57700

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from n/a through 5.2.6. CVSSv3.1 10.0 (CRITICAL)

CWECWE 434TYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-25
2026-06-25 19:16Z
CRIT

CVE-2026-56786 — RTKLIB: through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56786

RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in decode_type1033 function that fails to clamp length counters to destination buffer size, allowing up to 191-byte overflow into fixed 64-byte descriptor fields. An attacker controlling an NTRIP or serial RTCM3 correction stream can craft a valid CRC-bearing type-1033 message to corrupt adjacent rtcm_t object members, potentially achieving arbitrary code execution or denial of service. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDRtklibTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 19:16Z
HIGH

CVE-2026-56771 — NewsBlur: before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56771

NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make arbitrary server requests to internal networks by failing to filter private IP addresses. Attackers can exploit this to access localhost services and cloud metadata endpoints, enabling internal network scanning and sensitive data exfiltration. CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDNewsblurTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-25
2026-06-25 19:16Z
HIGH

CVE-2026-56769 — Huly: Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56769

Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerability in the /import endpoint of front pod that allows workspace users to make arbitrary server requests. Attackers can exploit this by supplying malicious URLs to fetch internal services, exfiltrate responses, and replay credentials against backend systems. CVSSv3.1 8.5 (HIGH)

CWECWE 918VNDHulyTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-25
2026-06-25 19:16Z
HIGH

CVE-2026-56768 — Seahub: before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56768

Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download entire shared directory trees. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDSeahubTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 19:16Z
HIGH

CVE-2026-56767 — Maxun: before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56767

Maxun before 0.0.42 contains a cross-tenant insecure direct object reference vulnerability in storage and webhook API handlers that allows authenticated users to access other users' robots and OAuth tokens. Attackers can read plaintext Google and Airtable access tokens, modify, delete, or execute other users' robots by bypassing ownership checks in API endpoints. CVSSv3.1 8.8 (HIGH)

CWECWE 862VNDMaxunTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 19:16Z
HIGH

CVE-2026-56766 — Hydra: through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-56766

Hydra through 9.7, fixed in commit 9cc84c2, contains a stack buffer overflow in NTLM authentication across SMTP, POP3, IMAP, NNTP, HTTP, HTTP-Proxy, and HTTP-Proxy-Urlenum modules when processing malicious NTLM Type-2 challenges. A malicious server can send a crafted NTLM Type-2 challenge with an excessively long domain string, causing base64-encoded response data to overflow a 500-byte stack buffer by 18 to 330 bytes, enabling remote code execution on systems without stack p CVSSv3.1 8.8 (HIGH)

CWECWE 121VNDHydraTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-25
2026-06-25 19:16Z
HIGH

CVE-2026-55667 — File: Prior to 2.63.16, a scoped, non-admin File Browser user holding only the Create permission

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55667

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.16, a scoped, non-admin File Browser user holding only the Create permission can delete arbitrary files outside their scope (other tenants' data, and the application's own database) via the upload failure-cleanup path. ScopedFs.RemoveAll is the one dereferencing operation that skips the symlink guard every other method enforces CVSSv3.1 8.2 (HIGH)

CWECWE 22CWECWE 59TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-25
2026-06-25 19:16Z
CRIT

CVE-2026-54917 — Seaweedfs Seaweedfs: Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway construct

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54917

SeaweedFS is a distributed storage system for object storage (S3), file systems, and Iceberg tables. Prior to 4.30, the S3 API gateway and the Iceberg REST catalog gateway construct their routers with mux.NewRouter().SkipClean(true). With path cleaning disabled, a .. segment inside the URL survives routing, so a request such as `GET /bucket-A/../evil-bucket/key`, is matched as bucket=bucket-A, object=../evil-bucket/key. The captured object key is then joined into a filer path CVSSv3.1 10.0 (CRITICAL) · EPSS 26th percentile

CWECWE 22VNDSeaweedfsTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-25
2026-06-25 19:16Z
HIGH

CVE-2026-54096 — File: Prior to 2.63.7, `POST /api/share/<path>` accepts an authenticated request for an arbitrary path and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54096

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.7, `POST /api/share/<path>` accepts an authenticated request for an arbitrary path and stores a public share record without checking whether the target file currently exists. Later, when a file is created at that same path, the previously created public share immediately becomes valid and exposes the new file through `GET /api/ CVSSv3.1 8.4 (HIGH)

CWECWE 863TYPVulnerability
8.4
CVSS v3.1
92
Edit Score
2026-06-25
2026-06-25 19:16Z
CRIT

CVE-2026-54089 — File: Starting with 2.0.0-rc.1, when FileBrowser is configured with proxy authentication (auth.method=proxy), any unauthenticated attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-54089

File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Starting with 2.0.0-rc.1, when FileBrowser is configured with proxy authentication (auth.method=proxy), any unauthenticated attacker who can reach the server directly can impersonate any user - including admin - by sending a single forged HTTP header. No credentials are required. Additionally, specifying a non-existent username causes the se CVSSv3.1 9.1 (CRITICAL)

CWECWE 287CWECWE 290TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-25
2026-06-25 19:16Z
CRIT

CVE-2026-50549 — Anysphere Cursor: This enables non-sandboxed Remote Code Execution — for example by overwriting the cursorsandbox helper

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50549

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, the agent canonicalizes the target path to confirm it stays inside the workspace, but when canonicalization fails it falls back to the original path and writes without approval. A malicious agent can create an in-workspace symlink that points outside the workspace and force canonicalization to fail — either because the target does n CVSSv3.1 9.8 (CRITICAL)

CWECWE 59VNDAnysphereVNDCursorTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 19:16Z
CRIT

CVE-2026-50548 — Anysphere Cursor: This enables non-sandboxed Remote Code Execution — for example by overwriting the cursorsandbox helper

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50548

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working directory. A flaw was identified in how the agent could modify the working_directory parameter, which could cause the sandbox to include writable paths outside the intended workspace. A malicious agent could set working_directory to a sensitive location and write arbitrary files outside t CVSSv3.1 9.8 (CRITICAL)

CWECWE 22VNDAnysphereVNDCursorTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-25
2026-06-25 18:16Z
CRIT

CVE-2026-6094 — Wolfssl Wolfssl: Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6094

Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS. CVSSv3.1 9.1 (CRITICAL)

CWECWE 125VNDHeapVNDWolfsslTYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-25
2026-06-25 18:16Z
HIGH

CVE-2026-55698 — pnpm is a package manager.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-55698

pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct pnpm execution trusted an already resolved packageManagerDependencies entry when the committed env lockfile contained matching pnpm and @pnpm/exe versions. A malicious repository could therefore commit package-manager lockfile package records and snapshots that bypassed fresh package-manager resoluti CVSSv3.1 8.8 (HIGH)

CWECWE 345CWECWE 829CWECWE 494TYPVulnerability
8.8
CVSS v3.1
94
Edit Score