Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

283 CVEs · published 2026-08-04 to 2026-08-04

CVEs (283)

Showing 1–25 of 283

CVE ID Severity Patch CVSS Published Description
CVE-2026-45084 NONE Patched — 2026-08-04 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. When t…
CVE-2026-65986 NONE Patched — 2026-08-04 CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed throu…
CVE-2026-13227 NONE Patched &mdash; 2026-08-04 An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doct&hellip;
CVE-2026-70475 NONE Patched &mdash; 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/rout&hellip;
CVE-2026-70476 NONE Patched &mdash; 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enter&hellip;
CVE-2026-70477 NONE Patched &mdash; 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can ca&hellip;
CVE-2026-70478 NONE Patched &mdash; 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint i&hellip;
CVE-2026-47682 NONE Patched &mdash; 2026-08-04 CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage t&hellip;
CVE-2026-70471 NONE Patched &mdash; 2026-08-04 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox wi&hellip;
CVE-2026-70472 NONE Patched &mdash; 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-co&hellip;
CVE-2026-70473 NONE Patched &mdash; 2026-08-04 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire se&hellip;
CVE-2026-70474 NONE Patched &mdash; 2026-08-04 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look &hellip;
CVE-2026-47764 NONE Patched &mdash; 2026-08-04 pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDe&hellip;
CVE-2026-47781 NONE Patched &mdash; 2026-08-04 PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during i&hellip;
CVE-2026-13229 NONE &mdash; 2026-08-04 Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint.
CVE-2026-69264 NONE Patched &mdash; 2026-08-04 Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Py&hellip;
CVE-2026-70470 NONE Patched &mdash; 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/p&hellip;
CVE-2026-47763 NONE Patched &mdash; 2026-08-04 pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration fil&hellip;
CVE-2026-69258 NONE Patched &mdash; 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted a&hellip;
CVE-2026-69259 NONE Patched &mdash; 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordm&hellip;
CVE-2026-69262 NONE Patched &mdash; 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPer&hellip;
CVE-2026-69263 NONE Patched &mdash; 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx,&hellip;
CVE-2026-69255 NONE Patched &mdash; 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.&hellip;
CVE-2026-69256 NONE Patched &mdash; 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is exec&hellip;
CVE-2026-69257 NONE Patched &mdash; 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IP&hellip;