Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-12821: Path Traversal in FlowiseAI FlowiseCVE-2026-12821
0

FlowiseAI Flowise versions 3.1.0, 3.1.1, and 3.1.2 contain a path traversal vulnerability in the S3 Document Loader component. This vulnerability allows remote attackers to manipulate file paths, potentially accessing unauthorized files. The vendor has not responded to the disclosure. A patch is available, and since this is a cloud service, the vendor typically manages remediation server-side.

Join the discussion
CVE-2026-46480: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46480
0

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment allows cross-workspace evaluator takeover. This issue has been patched in version 3.1.2.

Join the discussion
CVE-2026-46479: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46479
0

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeover. This issue has been patched in version 3.1.2.

Join the discussion
CVE-2026-46477: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46477
0

Flowise versions prior to 3.1.2 contain a vulnerability where mass-assignment in dataset creation and update allows cross-workspace dataset takeover. This issue has been addressed in version 3.1.2. The vulnerability involves improperly controlled modification of dynamically-determined object attributes, classified as CWE-915.

Join the discussion
CVE-2026-46476: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46476
0

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows cross-workspace template takeover. This issue has been patched in version 3.1.2.

Join the discussion
CVE-2026-46475: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46475
0

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assistant create and update mass-assignment allows cross-workspace assistant takeover. This issue has been patched in version 3.1.2.

Join the discussion
CVE-2026-46444: CWE-862: Missing Authorization in FlowiseAI FlowiseCVE-2026-46444
0

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI Assistants Vector Store have no authentication middleware and the route path /api/v1/openai-assistants-vector-store is not in WHITELIST_URLS. However, it is also not protected by the main auth middleware when accessed via API key — the route requires API key auth (not whitelisted), but no permission checks exist on any operation. This issue has been patched in version 3.1.2.

Join the discussion
CVE-2026-46443: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in FlowiseAI FlowiseCVE-2026-46443
0

FlowiseAI Flowise versions prior to 3.1.2 have a vulnerability where the encryptedData field is exposed in credential fetch responses when using a credentialName filter. This exposure of sensitive information occurs because the encryptedData field is not properly omitted in filtered responses, unlike unfiltered ones. The issue has been fixed in version 3.1.2.

Join the discussion
CVE-2026-46441: CWE-284: Improper Access Control in FlowiseAI FlowiseCVE-2026-46441
0

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. The endpoint allows authenticated users to modify server-controlled properties such as workspaceId, createdDate, and updatedDate when updating an assistant resource. Due to missing server-side validation and authorization checks, an attacker can manipulate the workspaceId field and reassign assistants to arbitrary workspaces. This breaks tenant isolation in multi-workspace environments. This issue has been patched in version 3.1.2.

Join the discussion
CVE-2026-46440: CWE-522: Insufficiently Protected Credentials in FlowiseAI FlowiseCVE-2026-46440
0

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting and with direct comparison. This issue has been patched in version 3.1.2.

Join the discussion

Showing 1 to 10 of 13 results

Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses