Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
GHSA-w4hm-rrxg-pxcfCVE-2026-56275 0 Flowise versions before 3.1.0 contain a server-side request forgery (SSRF) vulnerability in the Execute Flow node. This flaw allows attackers to bypass security validation by submitting intranet addresses via the base URL field, enabling unauthorized HTTP requests to internal network resources. The vulnerability arises from missing secureFetch verification in the httpSecurity.ts component. Join the discussion | GCVE Database | 06/23/2026, 15:32:36 UTC Added: 06/26/2026, 22:06:37 UTC |
GHSA-4pwq-xw7j-m297CVE-2025-71324 0 Flowise versions before 3.0.6 have an arbitrary file read vulnerability in the chatId parameter of two API endpoints. The chatId parameter is not properly validated, allowing path traversal beyond the intended storage directory. This enables unauthenticated attackers to read sensitive files such as the default database file, exposing all database content. Join the discussion | GCVE Database | 06/26/2026, 00:32:04 UTC Added: 06/26/2026, 22:06:12 UTC |
GHSA-f44q-84cr-v374CVE-2025-71328 0 Flowise versions before 3.0.10 have a vulnerability where authenticated users can change their account password without providing the current password or any additional verification. This lack of a current-password check in the account settings (Security) section allows potential full account takeover if an attacker gains access to an authenticated session. Join the discussion | GCVE Database | 06/26/2026, 00:32:04 UTC Added: 06/26/2026, 22:06:12 UTC |
GHSA-grch-cc26-w2fvCVE-2025-71333 0 Flowise versions through 2.2.4 have an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set to local. This vulnerability allows attackers to exploit path traversal in the chatId and chatflowId parameters to upload malicious files to arbitrary directories. Successful exploitation could lead to remote code execution and server compromise. Join the discussion | GCVE Database | 06/26/2026, 00:32:04 UTC Added: 06/26/2026, 22:06:12 UTC |
GHSA-289x-5mj7-xhg5CVE-2025-71335 0 Flowise versions 3.0.7 and earlier do not invalidate existing sessions or session tokens after a user changes their password. This allows an attacker with an active session, such as one obtained via a stolen token or a device left logged in, to remain authenticated despite the password change. This behavior undermines the security intent of password rotation by allowing continued unauthorized access. Join the discussion | GCVE Database | 06/26/2026, 00:32:05 UTC Added: 06/26/2026, 22:06:10 UTC |
GHSA-q2xp-j85q-883hCVE-2025-71336 0 Flowise versions 2.2.7-patch.1 and earlier contain a critical unsandboxed remote code execution vulnerability in the Custom MCP feature. This feature executes OS commands to launch local MCP servers. Due to minimal authentication and lack of role-based access control, and default installations running without authentication unless credentials are set, an attacker can send a crafted JSON payload with a specific header to execute arbitrary OS commands. This leads to complete compromise of the platform container or server. Join the discussion | GCVE Database | 06/26/2026, 00:32:05 UTC Added: 06/26/2026, 22:06:10 UTC |
GHSA-w5r9-j49j-2m55CVE-2025-71334 0 Flowise versions 2.2.8 and earlier contain an arbitrary file access vulnerability due to missing validation of chatflowId and chatId parameters. An unauthenticated attacker can exploit this by supplying path-traversal values to write and read arbitrary files via specific API endpoints. This arbitrary file write capability may lead to remote code execution. Join the discussion | GCVE Database | 06/26/2026, 00:32:05 UTC Added: 06/26/2026, 22:06:10 UTC |
Flowise: Mehrere Schwachstellen ermöglichen Umgehen von SicherheitsvorkehrungenCVE-2025-71337 0 Flowise ist eine Benutzeroberfläche zur Erstellung von LLMs (Large Language Model). Join the discussion | GCVE Database | 11/12/2025, 23:00:00 UTC Added: 06/24/2026, 16:59:32 UTC |
CVE-2026-12821: Path Traversal in FlowiseAI FlowiseCVE-2026-12821 0 A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the component S3 Document Loader. Executing a manipulation can lead to path traversal. It is possible to launch the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 06/21/2026, 23:15:08 UTC Added: 06/21/2026, 23:24:27 UTC |
CVE-2026-46480: CWE-915: Improperly Controlled Modification of Dynamically-Determined Object Attributes in FlowiseAI FlowiseCVE-2026-46480 0 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment allows cross-workspace evaluator takeover. This issue has been patched in version 3.1.2. Join the discussion | CVE Database V5 | 06/08/2026, 15:32:15 UTC Added: 06/08/2026, 15:49:01 UTC |
Showing 1 to 10 of 21 results