İçeriğe atla
Noroxi

FlowiseAI kayıtları

flowiseai üreticisine ait 128 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
0 · %0
Silahlaştırılmış
4 · %3,1
Pre-auth RCE
15
Düzeltme kaydı olan
%82,8
Yayından KEV’e ortanca
KEV’e giren kayıt yok

Tüm kayıtlar

128 kayıt
  • CVE-2025-59528
    66Bu hafta

    Flowise has Remote Code Execution vulnerability

    KritikCVSS 10,0SilahlaştırılmışEPSS %86

    flowiseai · flowise22 Eyl 2025

  • CVE-2025-8943
    61Bu hafta

    Unsupervised OS command execution leads to remote code execution by unauthenticated network attackers

    KritikCVSS 9,8SilahlaştırılmışEPSS %75

    flowiseai · flowise14 Ağu 2025

  • CVE-2025-26319
    56Planlayın

    FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments.

    KritikCVSS 9,8Kavram kanıtıEPSS %56

    flowiseai · flowise4 Mar 2025

  • CVE-2025-58434
    54Planlayın

    Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover

    KritikCVSS 9,8Kavram kanıtıEPSS %50

    flowiseai · flowise12 Eyl 2025

  • CVE-2024-31621
    48Planlayın

    An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 c

    YüksekCVSS 7,6Kavram kanıtıEPSS %60

    flowiseai · flowise29 Nis 2024

  • CVE-2024-8181
    46Planlayın

    Flowise Authentication Bypass

    YüksekCVSS 8,1Kavram kanıtıEPSS %45

    flowiseai · flowise27 Ağu 2024

  • CVE-2025-61913
    43Planlayın

    Flowise is vulnerable to arbitrary file read, arbitrary file write

    KritikCVSS 9,9İstismar yokEPSS %13

    flowiseai · flowise8 Eki 2025

  • CVE-2025-71338
    40Planlayın

    Flowise through 2.2.7 - Arbitrary File Write to Remote Code Execution via document-store API

    KritikCVSS 10,0Kavram kanıtıEPSS %1

    flowiseai · flowise25 Haz 2026

  • CVE-2026-40933
    39İzleyin

    Flowise: Authenticated RCE Via MCP Adapters

    KritikCVSS 9,9İstismar yokEPSS %1

    flowiseai · flowise21 Nis 2026

  • CVE-2026-41268
    39İzleyin

    Flowise: Flowise Parameter Override Bypass Remote Command Execution

    KritikCVSS 9,8İstismar yokEPSS %1

    flowiseai · flowise23 Nis 2026

  • CVE-2026-52098
    39İzleyin

    An issue in Flowise 3.1.2 allows a remote attacker to execute arbitrary code via the /api/v1/prediction/<flowId> endpoint

    KritikCVSS 9,8İstismar yokEPSS %1

    flowiseai · flowise10 Eyl 2026

  • CVE-2026-41267
    39İzleyin

    Flowise: Improper Mass Assignment in Account Registration Enables Unauthorized Organization Association

    KritikCVSS 9,8İstismar yokEPSS %0

    flowiseai · flowise23 Nis 2026

  • CVE-2025-61687
    38İzleyin

    FlowiseAI/Flosise has File Upload vulnerability

    YüksekCVSS 8,8İstismar yokEPSS %11

    flowiseai · flowise6 Eki 2025

  • CVE-2025-71334
    38İzleyin

    Flowise - Arbitrary File Access via Missing Chat Flow ID Validation

    KritikCVSS 9,3Kavram kanıtıEPSS %4

    flowiseai · flowise25 Haz 2026

  • CVE-2026-46442
    38İzleyin

    Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape

    KritikCVSS 9,4Kavram kanıtıEPSS %3

    flowiseai · flowise8 Haz 2026

  • CVE-2026-41137
    38İzleyin

    Flowise: Code Injection in CSVAgent leads to Authenticated RCE

    KritikCVSS 9,4İstismar yokEPSS %2

    flowiseai · flowise23 Nis 2026

  • CVE-2026-70470
    38İzleyin

    Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE

    KritikCVSS 9,5İstismar yokEPSS %1

    flowiseai · flowise4 Ağu 2026

  • CVE-2026-70477
    38İzleyin

    Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

    KritikCVSS 9,5İstismar yokEPSS %1

    flowiseai · flowise4 Ağu 2026

  • CVE-2026-69251
    37İzleyin

    Flowise RCE via TypeORM DataSource

    KritikCVSS 9,0Kavram kanıtıEPSS %3

    flowiseai · flowise4 Ağu 2026

  • CVE-2025-71336
    37İzleyin

    Flowise - Unsandboxed Remote Code Execution via Custom MCP

    KritikCVSS 9,3İstismar yokEPSS %1

    flowiseai · flowise25 Haz 2026

  • CVE-2026-69264
    37İzleyin

    Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation

    KritikCVSS 9,4İstismar yokEPSS %1

    flowiseai · flowise4 Ağu 2026

  • CVE-2026-69256
    37İzleyin

    Flowise: Remote Code Execution Vulnerability in CSVAgent

    KritikCVSS 9,4İstismar yokEPSS %1

    flowiseai · flowise4 Ağu 2026

  • CVE-2025-71333
    37İzleyin

    Flowise - Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint

    KritikCVSS 9,3İstismar yokEPSS %1

    flowiseai · flowise25 Haz 2026

  • CVE-2026-69259
    37İzleyin

    Flowise RCE via SQLite Record Manager Node

    KritikCVSS 9,4İstismar yokEPSS %1

    flowiseai · flowise4 Ağu 2026

  • CVE-2026-73483
    37İzleyin

    Flowise before 3.1.3 Sandbox Escape via Puppeteer

    KritikCVSS 9,4İstismar yokEPSS %1

    flowiseai · flowise13 Ağu 2026