Search
283 CVEs · published 2026-08-04 to 2026-08-04
CVEs (283)
Showing 1–25 of 283
| CVE ID | Severity ↑ | Patch | CVSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-45084 | NONE | Patched | — | 2026-08-04 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. When t… |
| CVE-2026-65986 | NONE | Patched | — | 2026-08-04 | CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed throu… |
| CVE-2026-13227 | NONE | Patched | — | 2026-08-04 | An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doct… |
| CVE-2026-70475 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/rout… |
| CVE-2026-70476 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enter… |
| CVE-2026-70477 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can ca… |
| CVE-2026-70478 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint i… |
| CVE-2026-47682 | NONE | Patched | — | 2026-08-04 | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage t… |
| CVE-2026-70471 | NONE | Patched | — | 2026-08-04 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox wi… |
| CVE-2026-70472 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-co… |
| CVE-2026-70473 | NONE | Patched | — | 2026-08-04 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire se… |
| CVE-2026-70474 | NONE | Patched | — | 2026-08-04 | Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look … |
| CVE-2026-47764 | NONE | Patched | — | 2026-08-04 | pdm is a Python package and dependency manager supporting the latest PEP standards. Versions prior to 2.27.0 are vulnerable to path traversal through write_to_fs. InstallDe… |
| CVE-2026-47781 | NONE | Patched | — | 2026-08-04 | PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins from a .pdm-plugins directory during i… |
| CVE-2026-13229 | NONE | — | 2026-08-04 | Zammad 7.1.0 contains an authenticated improper authorization vulnerability in the ticket article attachment cloning endpoint. | |
| CVE-2026-69264 | NONE | Patched | — | 2026-08-04 | Prior to 3.1.3, Flowise CSVAgent interpolates an attacker-controlled segment of the csvFile data URI directly into a Python source-code template that is then executed by Py… |
| CVE-2026-70470 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise validatePythonCodeForDataFrame in packages/components/src/p… |
| CVE-2026-47763 | NONE | Patched | — | 2026-08-04 | pdm is a Python package and dependency manager supporting the latest PEP standards. In versions prior to 2.27.0, pdm writes several project-local state or configuration fil… |
| CVE-2026-69258 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted a… |
| CVE-2026-69259 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite Record Manager node in packages/components/nodes/recordm… |
| CVE-2026-69262 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, `DELETE /api/v1/chatflows/:id` authorized requests with checkAnyPer… |
| CVE-2026-69263 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the mitigation for CVE-2025-8943 blocked -y and --yes flags on npx,… |
| CVE-2026-69255 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent in packages/components/nodes/agents/CSVAgent/CSVAgent.… |
| CVE-2026-69256 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent node allowed users to provide Python code that is exec… |
| CVE-2026-69257 | NONE | Patched | — | 2026-08-04 | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise's HTTP security module httpSecurity.ts did not normalize IP… |