24h | 7d | 30d

Overview

  • FlowiseAI
  • Flowise

04 Aug 2026
Published
05 Aug 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
0.38%

KEV

Description

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the unauthenticated POST /api/v1/prediction/:id endpoint accepted an overrideConfig object and unconditionally spread it into internal flowConfig and flowData objects in packages/server/src/utils/buildChatflow.ts and packages/server/src/utils/index.ts without checking apiOverrideStatus. This allowed unauthenticated attackers to inject arbitrary properties into the flow execution context of any public chatflow, overwrite values such as chatId, sessionId, and chatHistory, and control values resolved through $flow.* template variables consumed by flow nodes. This issue is fixed in version 3.1.3.

Statistics

  • 3 Posts
  • 1 Interaction

Last activity: 13 hours ago

Fediverse

Profile picture fallback

The Spread Operator Is an Allowlist With Nothing In It: CVE-2026-69258 in Flowise | HackerNoon
hackernoon.com/the-spread-oper

Posted into Hacker Noon @hacker-noon-HackerNoon

  • 1
  • 0
  • 0
  • 13h ago
Profile picture fallback

CVE-2026-69258: two ungated spread operators let an unauthenticated caller write into the flow execution context of any public Flowise chatflow. hackernoon.com/the-spread-oper #flowisevulnerability

  • 0
  • 0
  • 1
  • 13h ago

Overview

  • NetScaler
  • ADC

30 Jun 2026
Published
27 Aug 2026
Updated

CVSS v4.0
HIGH (8.8)
EPSS
1.61%

Description

Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server

Statistics

  • 2 Posts

Last activity: 11 hours ago

Fediverse

Profile picture fallback

CISA impone un parche urgente por un fallo crítico en Citrix NetScaler con explotación activa

CISA ha metido CVE-2026-8452 en su catálogo Known Exploited Vulnerabilities y obliga a las agencias federales de EEUU a parchear Citrix NetScaler antes del 29 de agosto de 2026. La falla, que empezó describiéndose como un problema de denegación de servicio, ya se está aprovechando para lograr ejecución remota de código...

unaaldia.hispasec.com/cisa-imp

  • 0
  • 0
  • 0
  • 11h ago

Bluesky

Profile picture fallback
Previously patched Citrix NetScaler flaw exploited in the wild (CVE-2026-8452) - Help Net Security www.helpnetsecurity.com/2026/08/27/n...
  • 0
  • 0
  • 0
  • 15h ago

Overview

  • Pending

25 Oct 2022
Published
21 Oct 2025
Updated

CVSS
Pending
EPSS
13.56%

Description

The Arm Mali GPU kernel driver allows unprivileged users to access freed memory because GPU memory operations are mishandled. This affects Bifrost r0p0 through r38p1, and r39p0; Valhall r19p0 through r38p1, and r39p0; and Midgard r4p0 through r32p0.

Statistics

  • 1 Post
  • 13 Interactions

Last activity: 12 hours ago

Fediverse

Profile picture fallback

Amazon kept shutting down my tablet, so I spent $266 on four AI models to own it

"Owning a tablet Amazon kept shutting down: CVE-2022-38181, four AI models, five months"

Link: ericpardee.github.io/fire-hd-o

#linkdump #ai #llm #security #story

  • 4
  • 9
  • 0
  • 12h ago

Overview

  • Tenda
  • HG10

30 Aug 2026
Published
30 Aug 2026
Updated

CVSS v4.0
CRITICAL (10.0)
EPSS
Pending

KEV

Description

A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

Statistics

  • 1 Post
  • 4 Interactions

Last activity: 14 hours ago

Fediverse

Profile picture fallback

cve.org/CVERecord?id=CVE-2026-

sev:CRIT 10.0 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:P

A weakness has been identified in Tenda HG10 300001138. Affected by this issue is the function formIPv6Routing of the file /boaform/admin/formIPv6Routing of the component Boa Web Server. This manipulation of the argument destNet causes buffer overflow. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

  • 2
  • 2
  • 0
  • 14h ago

Overview

  • pac4j
  • pac4j

29 Aug 2026
Published
29 Aug 2026
Updated

CVSS v4.0
HIGH (8.6)
EPSS
0.19%

KEV

Description

pac4j-oidc before 6.5.6 fails to verify access token signatures, issuers, audiences, or expiry when extracting Keycloak realm and client roles. Attackers can forge access tokens with administrative roles paired with valid ID tokens to bypass authorization checks in applications relying on pac4j role validation.

Statistics

  • 1 Post
  • 3 Interactions

Last activity: 16 hours ago

Fediverse

Profile picture fallback

CVE-2026-82461 - Auth bypass in pac4j-oidc. Unverified access tokens allow forging admin roles. CVSS 8.1. Update to v6.5.6 now. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-824

  • 2
  • 1
  • 0
  • 16h ago

Overview

  • TangibleWP
  • MyHome Core

30 Aug 2026
Published
30 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.8)
EPSS
0.45%

KEV

Description

The MyHome Core plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 4.4.5. This is due to missing authorization in the send_link() AJAX handler and improper token validation in the activate() function. This makes it possible for unauthenticated attackers to generate an activation token for an unconfirmed user account and obtain a valid authentication cookie for that account, including administrators. Successful exploitation requires the MyHome theme to be configured in legacy/WPBakery mode with frontend registration and confirmation email enabled, and the target account must not already have the myhome_agent_confirmed user meta set.

Statistics

  • 1 Post
  • 2 Interactions

Last activity: 13 hours ago

Fediverse

Profile picture fallback

CVE-2026-15980 - Critical Auth Bypass in WordPress MyHome Core plugin (<= 4.4.5) allows unauthenticated admin account takeover. CVSS 9.8. Mitigate now. #CVE #WordPress #infosec

valtersit.com/cve/CVE-2026-159

  • 1
  • 1
  • 0
  • 13h ago

Overview

  • ruby
  • rubygems

29 Aug 2026
Published
29 Aug 2026
Updated

CVSS v4.0
MEDIUM (6.9)
EPSS
0.14%

KEV

Description

RubyGems fails to re-validate path containment after filesystem symlink resolution during gem extraction. When a pre-existing symlink inside the destination directory points outside the extraction root, extracted files that appear to be written under the destination directory can instead be written outside of it, breaking the extraction safety boundary. The fix resolves the real path of the parent directory before writing and raises Gem::Package::PathError if it escapes the destination directory.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 14 hours ago

Fediverse

Profile picture fallback

CVE-2026-82455 - Arbitrary file write flaw in RubyGems via symlink path traversal during extraction. CVSS 7.1. Update RubyGems immediately. #CVE #Ruby #infosec

valtersit.com/cve/CVE-2026-824

  • 0
  • 1
  • 0
  • 14h ago

Overview

  • Microsoft
  • Windows 10 Version 1607

14 Jul 2026
Published
28 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
1.79%

KEV

Description

Improper authorization in Active Directory Certificate Services (AD CS) allows an authorized attacker to elevate privileges over a network.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 11 hours ago

Fediverse

Profile picture fallback

Certighost: cuando un usuario de dominio puede acabar obteniendo un certificado de un Domain Controller (CVE-2026-54121)

Si durante los últimos años ha habido una tecnología de Active Directory que ha pasado de ser la gran olvidada a convertirse en uno de los objetivos favoritos de Red Teams y atacantes reales, esa es Active Directory Certificate Services (AD CS). Desde la publicación de Certified Pre-Owned...

hackplayers.com/2026/07/certig

  • 0
  • 1
  • 0
  • 11h ago

Overview

  • Skyvern-AI
  • skyvern

29 Aug 2026
Published
29 Aug 2026
Updated

CVSS v4.0
HIGH (8.7)
EPSS
0.45%

KEV

Description

Skyvern before 1.0.45 contains a sandbox escape vulnerability in TextPromptBlock that renders prompts twice, first through a sandboxed Jinja environment and then through an unsandboxed environment. Attackers can inject malicious Jinja template syntax through workflow parameters or upstream block output to execute arbitrary code with server process privileges.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 17 hours ago

Fediverse

Profile picture fallback

CVE-2026-82447 - RCE in Skyvern TextPromptBlock via Jinja sandbox escape. Attackers can execute code with server privileges. CVSS 8.8. Update immediately. #CVE #Skyvern #infosec

valtersit.com/cve/CVE-2026-824

  • 0
  • 1
  • 0
  • 17h ago

Overview

  • tw93
  • Pake

30 Aug 2026
Published
30 Aug 2026
Updated

CVSS v3.1
HIGH (8.8)
EPSS
Pending

KEV

Description

Pake before 3.13.1 joins the JavaScript-supplied filename for the download_file Tauri command onto the user's Downloads directory with no sanitization. A filename containing path traversal sequences (for example ../Library/LaunchAgents/com.evil.plist) or an absolute path resolves outside ~/Downloads. The command then fetches attacker-controlled content from the supplied URL (via Rust HTTP, not the browser) and writes it to that path. A script that can invoke the command can overwrite user-writable files and install persistence (macOS LaunchAgents, Linux autostart, Windows Startup), leading to code execution in the user account. All desktop apps generated from an affected Pake tree expose the same command.

Statistics

  • 1 Post
  • 1 Interaction

Last activity: 11 hours ago

Fediverse

Profile picture fallback

CVE-2026-82635 - Path Traversal in Pake allows arbitrary file write via unsanitized download paths. CVSS 8.8. Update to 3.13.1 now. #CVE #infosec #cybersecurity

valtersit.com/cve/CVE-2026-826

  • 0
  • 1
  • 0
  • 11h ago
Showing 1 to 10 of 21 CVEs