Loading HuntDB...

flowiseai

2 Products 10 CVEs

CVE Severity Distribution (All Time)

Critical
2
High
4
Medium
4
Low
0

Timeline Overview

Last 30 Days 0 CVEs
Last 6 Months 0 CVEs
Last Year 0 CVEs

Recent CVEs

CVE-2024-9148 CRITICAL 1 year, 1 month ago

Flowise < 2.1.1 suffers from a Stored Cross-Site vulnerability due to a lack of input sanitization in Flowise Chat Embed < 2.0.0.

CVE-2024-8181 CRITICAL 1 year, 2 months ago

An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints a…

CVE-2024-8182 HIGH 1 year, 2 months ago

An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulner…

CVE-2024-37146 MEDIUM 1 year, 4 months ago

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin…

CVE-2024-37145 MEDIUM 1 year, 4 months ago

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin…

CVE-2024-36423 MEDIUM 1 year, 4 months ago

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin…

CVE-2024-36422 MEDIUM 1 year, 4 months ago

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, a reflected cross-site scriptin…

CVE-2024-36421 HIGH 1 year, 4 months ago

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, A CORS misconfiguration sets th…

CVE-2024-36420 HIGH 1 year, 4 months ago

Flowise is a drag & drop user interface to build a customized large language model flow. In version 1.4.3 of Flowise, the `/api/v1/openai-assistants-…

CVE-2024-31621 HIGH 1 year, 6 months ago

An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.