Записи dify
12 опубликованных записей вендора dify.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 41,7 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-639 Authorization Bypass Through User-Controlled Key2
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-284 Improper Access Control1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
12 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
38Наблюдать | CVE-2026-41948Proof of concept | Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Accessdify · dify · CWE-23 | Критическая9,3 | — | 1,9 % | 18 мая 2026 г. |
37Наблюдать | CVE-2026-41947Эксплойта нет | Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpointsdify · dify · CWE-639 | Критическая9,3 | — | 0,6 % | 18 мая 2026 г. |
35Наблюдать | CVE-2025-0185Эксплойта нет | Pandas Query Injection in langgenius/difydify · dify · CWE-94 | Высокая8,8 | — | 1,1 % | 20 мар. 2025 г. |
34Наблюдать | CVE-2026-61461Эксплойта нет | Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_textdify · dify · CWE-89 | Высокая8,7 | — | 0,5 % | 10 июл. 2026 г. |
33Наблюдать | CVE-2025-67732Эксплойта нет | Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpointdify · dify · CWE-200 | Высокая8,4 | — | 0,3 % | 5 янв. 2026 г. |
32Наблюдать | CVE-2026-41949Эксплойта нет | Dify < 1.14.2 Authorization Bypass via File Preview Endpointdify · dify · CWE-639 | Высокая8,2 | — | 0,6 % | 18 мая 2026 г. |
30Наблюдать | CVE-2024-11822Эксплойта нет | Server-Side Request Forgery (SSRF) in langgenius/difydify · dify · CWE-918 | Высокая7,5 | — | 0,6 % | 20 мар. 2025 г. |
22Наблюдать | CVE-2026-28288Proof of concept | Dify has a user enumeration issuedify · dify · CWE-204 | Средняя5,5 | — | 0,7 % | 27 февр. 2026 г. |
21Наблюдать | CVE-2025-56520Proof of concept | Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUplodify · dify · CWE-918 | Средняя5,3 | — | 0,7 % | 30 сент. 2025 г. |
21Наблюдать | CVE-2026-26023Эксплойта нет | Client‑side DOM XSS in the web chat app of Dify when using echartsdify · dify · CWE-79 | Средняя5,3 | — | 0,4 % | 11 февр. 2026 г. |
21Наблюдать | CVE-2026-34082Эксплойта нет | Dify has IDOR in deleting someone else's chat conversationdify · dify · CWE-284 | Средняя5,3 | — | 0,3 % | 20 апр. 2026 г. |
20Наблюдать | CVE-2026-21866Эксплойта нет | Dify - Stored XSS in chatdify · dify · CWE-79 | Средняя5,1 | — | 0,2 % | 3 мар. 2026 г. |
- CVE-2026-4194838Наблюдать
Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access
КритическаяCVSS 9,3Proof of conceptEPSS 2 %dify · dify18 мая 2026 г.
- CVE-2026-4194737Наблюдать
Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpoints
КритическаяCVSS 9,3Эксплойта нетEPSS 1 %dify · dify18 мая 2026 г.
- CVE-2025-018535Наблюдать
Pandas Query Injection in langgenius/dify
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %dify · dify20 мар. 2025 г.
- CVE-2026-6146134Наблюдать
Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_text
ВысокаяCVSS 8,7Эксплойта нетEPSS 0 %dify · dify10 июл. 2026 г.
- CVE-2025-6773233Наблюдать
Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpoint
ВысокаяCVSS 8,4Эксплойта нетEPSS 0 %dify · dify5 янв. 2026 г.
- CVE-2026-4194932Наблюдать
Dify < 1.14.2 Authorization Bypass via File Preview Endpoint
ВысокаяCVSS 8,2Эксплойта нетEPSS 1 %dify · dify18 мая 2026 г.
- CVE-2024-1182230Наблюдать
Server-Side Request Forgery (SSRF) in langgenius/dify
ВысокаяCVSS 7,5Эксплойта нетEPSS 1 %dify · dify20 мар. 2025 г.
- CVE-2026-2828822Наблюдать
Dify has a user enumeration issue
СредняяCVSS 5,5Proof of conceptEPSS 1 %dify · dify27 февр. 2026 г.
- CVE-2025-5652021Наблюдать
Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUplo
СредняяCVSS 5,3Proof of conceptEPSS 1 %dify · dify30 сент. 2025 г.
- CVE-2026-2602321Наблюдать
Client‑side DOM XSS in the web chat app of Dify when using echarts
СредняяCVSS 5,3Эксплойта нетEPSS 0 %dify · dify11 февр. 2026 г.
- CVE-2026-3408221Наблюдать
Dify has IDOR in deleting someone else's chat conversation
СредняяCVSS 5,3Эксплойта нетEPSS 0 %dify · dify20 апр. 2026 г.
- CVE-2026-2186620Наблюдать
Dify - Stored XSS in chat
СредняяCVSS 5,1Эксплойта нетEPSS 0 %dify · dify3 мар. 2026 г.