Vulnerability index

Browse CVEs

82 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.5 CVE-2025-57164 Flowise through v3.0.4 is vulnerable to remote code execution via unsanitized evaluation of user input in the "Supabase RPC Filter" field. Flowise No fix yet Fix from $1,6002025-10-17 CRITICAL 9.9 CVE-2025-34267EPSS 6% Flowise v3.0.1 < 3.0.8 and all versions after with 'ALLOW_BUILTIN_DEP' enabled contain an authenticated remote code execution vulnerability and node … Flowise 3.0.8+ Fix from $2,3002025-10-14 CRITICAL 9.9 CVE-2025-61913EPSS 12% Flowise is a drag & drop user interface to build a customized large language model flow. In versions prior to 3.0.8, WriteFileTool and ReadFileTool i… Flowise 3.0.8+ Fix from $2,3002025-10-08 HIGH 8.8 CVE-2025-61687EPSS 10% Flowise is a drag & drop user interface to build a customized large language model flow. A file upload vulnerability in version 3.0.7 of FlowiseAI al… Flowise No fix yet Fix from $1,9502025-10-06 MEDIUM 6.1 CVE-2025-29192 Flowise before 3.0.5 allows XSS via a FORM element and an INPUT element when an admin views the chat log. Flowise 3.0.5+ Fix from $1,6002025-10-06 MEDIUM 6.1 CVE-2025-50538EPSS 13% Flowise before 3.0.5 allows XSS via an IFRAME element when an admin views the chat log. Flowise 3.0.5+ Fix from $1,6002025-10-06 CRITICAL 10.0 CVE-2025-59528EPSS 90% Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execu… Flowise Mitigation only Fix from $2,3002025-09-22 HIGH 7.5 CVE-2025-59527 Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, a Server-Side Request Forgery (SSRF) vulne… Flowise No fix yet Fix from $1,9502025-09-22 CRITICAL 9.8 CVE-2025-58434EPSS 50% Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the `forgot-password` endpoint… Flowise 3.0.6+ Fix from $2,3002025-09-12 CRITICAL 9.8 CVE-2025-8943EPSS 72% The Custom MCPs feature is designed to execute OS commands, for instance, using tools like `npx` to spin up local MCP Servers. However, Flowise's inh… Flowise 3.0.1+ Fix from $2,3002025-08-14 HIGH 7.6 CVE-2025-29189 Flowise <= 2.2.3 is vulnerable to SQL Injection. via tableName parameter at Postgres_VectorStores. Flowise after 2.2.3 Fix from $1,9502025-04-09 CRITICAL 9.8 CVE-2025-26319EPSS 56% FlowiseAI Flowise v2.2.6 was discovered to contain an arbitrary file upload vulnerability in /api/v1/attachments. Flowise Patch available Fix from $2,3002025-03-04 MEDIUM 6.1 CVE-2024-9148 Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0. Embed 2.0.0 / 2.1.1+ Fix from $1,6002024-09-25 HIGH 7.5 CVE-2024-8182EPSS 14% An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulner… Flowise Mitigation only Fix from $1,9502024-08-27 HIGH 8.1 CVE-2024-8181EPSS 45% An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints a… Flowise Mitigation only Fix from $1,9502024-08-27 MEDIUM 6.1 CVE-2024-37146 Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin… Flowise after 1.4.3 Fix from $1,6002024-07-01 MEDIUM 6.1 CVE-2024-36423 Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin… Flowise after 1.4.3 Fix from $1,6002024-07-01 MEDIUM 6.1 CVE-2024-37145 Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin… Flowise after 1.4.3 Fix from $1,6002024-07-01 HIGH 7.5 CVE-2024-36420 Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-… Flowise No fix yet Fix from $1,9502024-07-01 HIGH 7.5 CVE-2024-36421EPSS 8% Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets th… Flowise No fix yet Fix from $1,9502024-07-01 MEDIUM 6.1 CVE-2024-36422 Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin… Flowise No fix yet Fix from $1,6002024-07-01 HIGH 7.6 CVE-2024-31621EPSS 60% An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component. Flowise after 1.6.5 Fix from $1,9502024-04-29