The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,274
Mitigations16,213
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
flowise<= 3.1.2
NPM: Flowise: Cross-Workspace OAuth2 Credential Metadata Leak
7.6
35 minutes ago
flowise<= 3.1.2
NPM: Flowise: Incomplete Credential Redaction Exposes Secrets via API
6.5
39 minutes ago
flowise<= 3.1.2
NPM: Flowise: Information Disclosure in GET /api/v1/upsert-history returns the entire server-wide upsert history
8.3
39 minutes ago
flowise<= 3.1.2
NPM: Flowise: Cross-workspace credential IDOR in openai-assistants-vector-store
7.1
45 minutes ago
flowise<= 3.1.2
NPM: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
9.4
53 minutes ago
flowise-components<= 3.1.2
NPM: Flowise: RCE via CSVAgent csvFile data URI base64 segment is interpolated into Python source without validation
9.4
53 minutes ago
flowise<= 3.1.2
NPM: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
7.2
53 minutes ago
flowise-components<= 3.1.2
NPM: Flowise: Authenticated arbitrary file write in the `S3 Directory` document loader via unsanitized S3 object keys
7.2
53 minutes ago
flowise<= 3.1.2
NPM: Flowise: RBAC Bypass Leading to Unauthorized Workspace Variables Disclosure
7.1
53 minutes ago
flowise<= 3.1.2
NPM: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
9.5
1 hour ago
flowise-components<= 3.1.2
NPM: Flowise: Pyodide validator Unicode homoglyph bypass leads to RCE
9.5
1 hour ago
flowise<= 3.1.2
NPM: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
8.7
1 hour ago
flowise-components<= 3.1.2
NPM: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
8.7
1 hour ago
flowise<= 3.1.2
NPM: Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
7.1
1 hour ago
flowise<= 3.1.2
NPM: Flowise RCE via SQLite Record Manager Node
9.4
2 hours ago
flowise-components<= 3.1.2
NPM: Flowise RCE via SQLite Record Manager Node
9.4
2 hours ago
flowise<= 3.1.2
NPM: Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
8.8
2 hours ago
flowise<= 3.1.2
NPM: Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
7.6
2 hours ago
flowise<= 3.1.2
NPM: Flowise: Remote Code Execution Vulnerability in CSVAgent
9.4
2 hours ago
flowise-components<= 3.1.2
NPM: Flowise: Remote Code Execution Vulnerability in CSVAgent
9.4
2 hours ago