The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,260
Mitigations16,213
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
flowise<= 3.1.2
NPM: Flowise RCE via SQLite Record Manager Node
9.4
24 minutes ago
flowise-components<= 3.1.2
NPM: Flowise RCE via SQLite Record Manager Node
9.4
24 minutes ago
flowise<= 3.1.2
NPM: Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
8.8
33 minutes ago
flowise<= 3.1.2
NPM: Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
7.6
37 minutes ago
flowise<= 3.1.2
NPM: Remote Code Execution Vulnerability in CSVAgent
9.4
43 minutes ago
flowise-components<= 3.1.2
NPM: Remote Code Execution Vulnerability in CSVAgent
9.4
43 minutes ago
flowise<= 3.1.2
NPM: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
9.2
49 minutes ago
flowise-components<= 3.1.2
NPM: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
9.2
49 minutes ago
flowise<= 3.1.2
NPM: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
9.4
1 hour ago
flowise-components<= 3.1.2
NPM: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
9.4
1 hour ago
flowise<= 3.1.2
NPM: Flowise Sandbox Escape to RCE
9
1 hour ago
flowise-components<= 3.1.2
NPM: Flowise Sandbox Escape to RCE
9
1 hour ago
flowise<= 3.1.2
NPM: Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
7.2
1 hour ago
flowise<= 3.1.2
NPM: Flowise RCE via TypeORM DataSource
9
2 hours ago
flowise-components<= 3.1.2
NPM: Flowise RCE via TypeORM DataSource
9
2 hours ago
flowise<= 3.1.2
NPM: Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
8.5
2 hours ago
flowise<= 3.1.2
NPM: Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
6
2 hours ago
Booking Calendar Contact Form<= 1.0.23
Reflected Cross-Site Scripting vulnerability
7.1
5 hours ago
WP Event SOlution< 4.1.16
Unauthenticated Payment Bypass vulnerability
5.3
5 hours ago
WP Travel< 11.8.1
Unauthenticated Payment Bypass vulnerability
5.3
5 hours ago