Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Dify CRITICAL 9.1
CVE-2025-63388

A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoin…

Mitigation only
Fix from $2,300 2025-12-18
Dify MEDIUM 5.3
CVE-2025-11750

In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for n…

No fix yet
Fix from $1,600 2025-10-22
Dify MEDIUM 6.1
CVE-2025-49149

Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by web applications. Attackers c…

No fix yet
Fix from $1,600 2025-06-17
Dify HIGH 8.8
CVE-2025-1796

A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including administrator accounts, by exploiting a weak pseudo…

No fix yet
Fix from $1,950 2025-03-20
Dify HIGH 8.1
CVE-2024-12776

In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset the passwor…

No fix yet
Fix from $1,950 2025-03-20
Dify MEDIUM 6.5
CVE-2024-12775

langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool optio…

No fix yet
Fix from $1,600 2025-03-20
Dify HIGH 8.1
CVE-2024-12039

langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess attempts for password reset. T…

No fix yet
Fix from $1,950 2025-03-20
Dify MEDIUM 5.4
CVE-2024-11850

A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is due to improper validation an…

No fix yet
Fix from $1,600 2025-03-20