The leading open source vulnerability database

Instantly mitigate vulnerabilities in WordPress websites with Patchstack.

Total50,263
Mitigations16,213
Stats
CVSS0
10
Affected software | Vulnerability
RiskDisclosed
flowise<= 3.1.2
NPM: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
8.7
27 minutes ago
flowise-components<= 3.1.2
NPM: Flowise: CVE-2025-8943 Patch Bypass: npm_config_yes bypasses MCP environment variable blocklist (Unauthenticated RCE)
8.7
27 minutes ago
flowise<= 3.1.2
NPM: Flowise: `DELETE /api/v1/chatflows/:id` does not validate resource type, allowing `agentflows:delete` and `chatflows:delete` to delete each other’s flow type
7.1
47 minutes ago
flowise<= 3.1.2
NPM: Flowise RCE via SQLite Record Manager Node
9.4
1 hour ago
flowise-components<= 3.1.2
NPM: Flowise RCE via SQLite Record Manager Node
9.4
1 hour ago
flowise<= 3.1.2
NPM: Flowise: Unauthenticated Property Injection into Flow Execution Context via Ungated `overrideConfig` Spread in Prediction API
8.8
1 hour ago
flowise<= 3.1.2
NPM: Flowise: SSRF Protection Bypass via IPv4-Mapped IPv6 Addresses
7.6
1 hour ago
flowise<= 3.1.2
NPM: Remote Code Execution Vulnerability in CSVAgent
9.4
1 hour ago
flowise-components<= 3.1.2
NPM: Remote Code Execution Vulnerability in CSVAgent
9.4
1 hour ago
flowise<= 3.1.2
NPM: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
9.2
1 hour ago
flowise-components<= 3.1.2
NPM: Flowise: CSV Agent Remote Code Execution via Pyodide Code Injection — Root Shell Verified
9.2
1 hour ago
flowise<= 3.1.2
NPM: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
9.4
2 hours ago
flowise-components<= 3.1.2
NPM: Flowise: RCE via NodeVM Sandbox Escape in executeJavaScriptCode() nodeVMOptions Override
9.4
2 hours ago
flowise<= 3.1.2
NPM: Flowise Sandbox Escape to RCE
9
2 hours ago
flowise-components<= 3.1.2
NPM: Flowise Sandbox Escape to RCE
9
2 hours ago
flowise<= 3.1.2
NPM: Flowise: Missing authorization on `/api/v1/files` allows low-privileged API keys to list and delete files across workspaces within the same organization
7.2
2 hours ago
flowise<= 3.1.2
NPM: Flowise RCE via TypeORM DataSource
9
3 hours ago
flowise-components<= 3.1.2
NPM: Flowise RCE via TypeORM DataSource
9
3 hours ago
flowise<= 3.1.2
NPM: Flowise: Unauthenticated OAuth2 Refresh Enables Non-Blind SSRF and Secret Exfiltration
8.5
3 hours ago
flowise<= 3.1.2
NPM: Flowise: IDOR vulnerability exists at the GET /api/v1/organization/customer-default-source endpoint
6
3 hours ago