Vulnerability index

Browse CVEs

15 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2026-28797 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions 0.24.0 and prior, a Server-Side Template Injection (SSTI) vulnerab… Ragflow after 0.24.0 Fix from $1,9502026-04-03 CRITICAL 9.8 CVE-2026-24770 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In version 0.23.1 and possibly earlier versions, the MinerU parser contains a … Ragflow after 0.23.1 Fix from $2,3002026-01-27 CRITICAL 9.8 CVE-2025-69286 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.22.0, the use of an insecure key generation algorithm i… Ragflow 0.22.0+ Fix from $2,3002025-12-31 HIGH 8.8 CVE-2025-68700 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In versions prior to 0.23.0, a low-privileged authenticated user (normal login… Ragflow 0.23.0+ Fix from $1,9502025-12-31 MEDIUM 6.1 CVE-2025-51462 Stored Cross-site Scripting (XSS) vulnerability in api.apps.dialog_app.set_dialog in RAGFlow 0.17.2 allows remote attackers to execute arbitrary Java… Ragflow Patch available Fix from $1,6002025-07-22 CRITICAL 9.8 CVE-2025-48187 RAGFlow through 0.18.1 allows account takeover because it is possible to conduct successful brute-force attacks against email verification codes to p… Ragflow after 0.18.1 Fix from $2,3002025-05-17 MEDIUM 6.5 CVE-2024-12880 A vulnerability in infiniflow/ragflow version RAGFlow-0.13.0 allows for partial account takeover via insecure data querying. The issue arises from th… Ragflow No fix yet Fix from $1,6002025-03-20 MEDIUM 5.4 CVE-2024-12871 An XSS vulnerability in infiniflow/ragflow version 0.12.0 allows an attacker to upload a malicious PDF file to the knowledge base. When the file is v… Ragflow No fix yet Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-12779 A Server-Side Request Forgery (SSRF) vulnerability exists in infiniflow/ragflow version 0.12.0. The vulnerability is present in the `POST /v1/llm/add… Ragflow No fix yet Fix from $1,9502025-03-20 CRITICAL 9.8 CVE-2024-12433 A vulnerability in infiniflow/ragflow versions v0.12.0 allows for remote code execution. The RPC server in RagFlow uses a hard-coded AuthKey 'authkey… Ragflow 0.14.0+ Fix from $2,3002025-03-20 CRITICAL 9.8 CVE-2024-12450 In infiniflow/ragflow versions 0.12.0, the `web_crawl` function in `document_app.py` contains multiple vulnerabilities. The function does not filter … Ragflow Patch available Fix from $2,3002025-03-20 CRITICAL 9.8 CVE-2025-27135 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. Versions 0.15.1 and prior are vulnerable to SQL injection. The ExeSQL componen… Ragflow after 0.15.1 Fix from $2,3002025-02-25 HIGH 8.1 CVE-2025-25282 RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine based on deep document understanding. An authenticated user can exploit the Ins… Ragflow 0.14.1+ Fix from $1,9502025-02-21 HIGH 7.5 CVE-2024-53450 RAGFlow 0.13.0 suffers from improper access control in document-hooks.ts, allowing unauthorized access to user documents. Ragflow No fix yet Fix from $1,9502024-12-09 HIGH 8.8 CVE-2024-10131 The `add_llm` function in `llm_app.py` in infiniflow/ragflow version 0.11.0 contains a remote code execution (RCE) vulnerability. The function uses u… Ragflow No fix yet Fix from $1,9502024-10-19