Vulnerability index

Browse CVEs

8 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2025-63388 A Cross-Origin Resource Sharing (CORS) misconfiguration vulnerability exists in Dify v1.9.1 in the /console/api/system-features endpoint. The endpoin… Dify Mitigation only Fix from $2,3002025-12-18 MEDIUM 5.3 CVE-2025-11750 In langgenius/dify-web version 1.6.0, the authentication mechanism reveals the existence of user accounts by returning different error messages for n… Dify No fix yet Fix from $1,6002025-10-22 MEDIUM 6.1 CVE-2025-49149 Dify is an open-source LLM app development platform. In version 1.2.0, there is insufficient filtering of user input by web applications. Attackers c… Dify No fix yet Fix from $1,6002025-06-17 HIGH 8.8 CVE-2025-1796 A vulnerability in langgenius/dify v0.10.1 allows an attacker to take over any account, including administrator accounts, by exploiting a weak pseudo… Dify No fix yet Fix from $1,9502025-03-20 HIGH 8.1 CVE-2024-12776 In langgenius/dify v0.10.1, the `/forgot-password/resets` endpoint does not verify the password reset code, allowing an attacker to reset the passwor… Dify No fix yet Fix from $1,9502025-03-20 MEDIUM 6.5 CVE-2024-12775 langgenius/dify version 0.10.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the test functionality for the Create Custom Tool optio… Dify No fix yet Fix from $1,6002025-03-20 HIGH 8.1 CVE-2024-12039 langgenius/dify version v0.10.1 contains a vulnerability where there are no limits applied to the number of code guess attempts for password reset. T… Dify No fix yet Fix from $1,9502025-03-20 MEDIUM 5.4 CVE-2024-11850 A stored cross-site scripting (XSS) vulnerability exists in the latest version of langgenius/dify. The vulnerability is due to improper validation an… Dify No fix yet Fix from $1,6002025-03-20