Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-12821: Path Traversal in FlowiseAI FlowiseCVE-2026-12821 0 FlowiseAI Flowise versions 3.1.0, 3.1.1, and 3.1.2 contain a path traversal vulnerability in the S3 Document Loader component. This vulnerability allows remote attackers to manipulate file paths, potentially accessing unauthorized files. The vendor has not responded to the disclosure. A patch is available, and since this is a cloud service, the vendor typically manages remediation server-side. Join the discussion | CVE Database V5 | 06/21/2026, 23:15:08 UTC Added: 06/21/2026, 23:24:27 UTC |
CVE-2026-46480: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46480 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment allows cross-workspace evaluator takeover. This issue has been patched in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:32:15 UTC Added: 06/08/2026, 15:49:01 UTC |
CVE-2026-46479: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46479 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeover. This issue has been patched in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:32:03 UTC Added: 06/08/2026, 15:49:01 UTC |
CVE-2026-46477: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46477 0 Flowise versions prior to 3.1.2 contain a vulnerability where mass-assignment in dataset creation and update allows cross-workspace dataset takeover. This issue has been addressed in version 3.1.2. The vulnerability involves improperly controlled modification of dynamically-determined object attributes, classified as CWE-915. Join the discussion | CVE Database V5 | 06/08/2026, 15:31:48 UTC Added: 06/08/2026, 15:48:56 UTC |
CVE-2026-46476: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46476 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows cross-workspace template takeover. This issue has been patched in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:31:32 UTC Added: 06/08/2026, 15:48:56 UTC |
CVE-2026-46475: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46475 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assistant create and update mass-assignment allows cross-workspace assistant takeover. This issue has been patched in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:31:09 UTC Added: 06/08/2026, 15:48:56 UTC |
CVE-2026-46444: CWE-862: Missing Authorization in FlowiseAI FlowiseCVE-2026-46444 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI Assistants Vector Store have no authentication middleware and the route path /api/v1/openai-assistants-vector-store is not in WHITELIST_URLS. However, it is also not protected by the main auth middleware when accessed via API key — the route requires API key auth (not whitelisted), but no permission checks exist on any operation. This issue has been patched in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:25:24 UTC Added: 06/08/2026, 15:48:56 UTC |
CVE-2026-46443: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in FlowiseAI FlowiseCVE-2026-46443 0 FlowiseAI Flowise versions prior to 3.1.2 have a vulnerability where the encryptedData field is exposed in credential fetch responses when using a credentialName filter. This exposure of sensitive information occurs because the encryptedData field is not properly omitted in filtered responses, unlike unfiltered ones. The issue has been fixed in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:30:59 UTC Added: 06/08/2026, 15:48:56 UTC |
CVE-2026-46441: CWE-284: Improper Access Control in FlowiseAI FlowiseCVE-2026-46441 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating an assistant resource. Due to missing server-side validation and authorization checks, an attacker can manipulate the workspaceId field and reassign assistants to arbitrary workspaces. This breaks tenant isolation in multi-workspace environments. This issue has been patched in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:30:36 UTC Added: 06/08/2026, 15:48:56 UTC |
CVE-2026-46440: CWE-522: Insufficiently Protected Credentials in FlowiseAI FlowiseCVE-2026-46440 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patched in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:29:40 UTC Added: 06/08/2026, 15:48:56 UTC |
Showing 1 to 10 of 13 results