Recent Advisories

Severity ID Title Vendor Product Date Type
CRITICAL 9.3 CVE-2025-71334

Flowise – Arbitrary File Access via Missing Chat Flow ID Validation_CVE-2025-71334

Flowise before 3.0.6 (affected versions 2.2.8 and earlier) contains an arbitrary file access vulnerability due to missing validation that the chatf...

Flowise Flowise CVE
CRITICAL 9.3 CVE-2025-71333

Flowise – Arbitrary File Upload via Unauthenticated /api/v1/attachments Endpoint_CVE-2025-71333

Flowise through 2.2.4 contains an unauthenticated arbitrary file upload vulnerability in the /api/v1/attachments endpoint when storageType is set t...

Flowise Flowise CVE
CRITICAL 9.3 CVE-2025-71327

Flowise – Authentication Bypass via Unprotected Registration Endpoint_CVE-2025-71327

Flowise contains an authentication bypass vulnerability in the unprotected /api/v1/account/register endpoint that allows unauthenticated attackers ...

Flowise Flowise 3.0.1 CVE
CRITICAL 10 MSF:EXPLOIT-LINUX-

Dalfox Found-Action Deserialization RCE_MSF:EXPLOIT-LINUX-HTTP-DALFOX_SERVER_RCE_CVE_2026_45087-

When dalfox version use exploit/linux/http/dalfoxserverrcecve202645087 msf exploitdalfoxserverrcecve202645087 show targets ...targets... msf exploi...

N/A N/A METASPLOIT
CRITICAL 9.3 CVE-2026-50549

Cursor Desktop sandbox escape via symlink and failed path canonicalization_CVE-2026-50549

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default. Before a Write, t...

cursor cursor < 3.0 CVE
CRITICAL 9.3 CVE-2026-50548

Cursor Desktop sandbox escape via agent-controlled working directory_CVE-2026-50548

Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox g...

cursor cursor < 3.0 CVE
CRITICAL 10 PACKETSTORM:224334

📄 Dalfox Found-Action Deserialization Remote Code Execution_PACKETSTORM:224334

When dalfox versions less than or equal to 2.12.0 is started in REST API server mode dalfox server, the server binds to 0.0.0.0:6664 by default and...

N/A N/A PACKETSTORM
CRITICAL 9.2 CVE-2026-56123

socat 1.8.0.0 – 1.8.1.1 Heap Buffer Overflow via SOCKS5 Reply Parser_CVE-2026-56123

socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite ...

socat socat 1.8.0.0 CVE
CRITICAL 9.4 CVE-2026-55413

ToolJet – Marketplace Plugin Poisoning Enables Instance-Wide Remote Code Execution_CVE-2026-55413

ToolJet is the open-source foundation am AI-native platform for building and deploying internal tools, workflows and AI agents. Prior to 3.20.178-l...

ToolJet ToolJet < 3.20.178-lts CVE
CRITICAL 10 CVE-2026-57700

WordPress OMGF Pro plugin <= 5.2.6 - Arbitrary File Upload vulnerability_CVE-2026-57700

Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files. This issue affects OMGF Pro: from...

Daan.dev OMGF Pro n/a CVE