Vulnerability index

Browse CVEs

11 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-61461 Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by s… Dify 1.16.0+ Fix from $1,9502026-07-10 HIGH 7.5 CVE-2026-41949 Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up … Dify after 1.14.1 Fix from $1,9502026-05-18 CRITICAL 9.4 CVE-2026-41948EPSS 7% Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin D… Dify after 1.14.1 Fix from $2,3002026-05-18 CRITICAL 9.1 CVE-2026-41947EPSS 6% Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configuratio… Dify after 1.14.1 Fix from $2,3002026-05-18 MEDIUM 5.4 CVE-2026-21866 Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within… Dify 1.11.2+ Fix from $1,6002026-03-03 MEDIUM 5.3 CVE-2026-28288 Dify is an open-source LLM app development platform. Prior to 1.9.0, responses from the Dify API to existing and non-existent accounts differ, allowi… Dify 1.9.0+ Fix from $1,6002026-02-27 MEDIUM 6.1 CVE-2026-26023 Dify is an open-source LLM app development platform. Prior to 1.13.0, a cross site scripting vulnerability has been found in the web application chat… Dify after 1.11.4 Fix from $1,6002026-02-11 MEDIUM 6.5 CVE-2025-67732 Dify is an open-source LLM app development platform. Prior to version 1.11.0, the API key is exposed in plaintext to the frontend, allowing non-admin… Dify 1.11.0+ Fix from $1,6002026-01-05 MEDIUM 5.3 CVE-2025-56520 Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A … Dify No fix yet Fix from $1,6002025-09-30 HIGH 8.8 CVE-2025-0185 A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vuln… Dify No fix yet Fix from $1,9502025-03-20 HIGH 7.5 CVE-2024-11822 langgenius/dify version 0.9.1 contains a Server-Side Request Forgery (SSRF) vulnerability. The vulnerability exists due to improper handling of the a… Dify No fix yet Fix from $1,9502025-03-20