|
2831
|
7.5 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, the text-to-speech generation endpoint (POST /api/v1/text-to-speech/generate) is whitelisted (…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-41279
|
2026-04-25 01:31 |
2026-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2832
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
mm: thp: deny THP for files on anonymous inodes
file_thp_enabled() incorrectly allows THP for files on anonymous inodes
(e.g. gue…
|
CWE-617
Reachable Assertion
|
CVE-2026-23375
|
2026-04-25 01:31 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2833
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
En el kernel de Linux, la siguiente vulnerabilidad ha sido resuelta:
mm: thp: denegar THP para archivos en inodos anónimos
file_thp_enabled() permite incorrectamente THP para archivos en inodos anó…
|
CWE-617
Reachable Assertion
|
CVE-2026-23375
|
2026-04-25 01:31 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2834
|
5.0 |
MEDIUM
Adjacent
|
-
|
-
|
A security vulnerability has been detected in OmniPEMF NeoRhythm up to 20260308. This affects an unknown function of the component BLE Interface. Such manipulation leads to missing authentication. Th…
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-2756
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2835
|
5.0 |
MEDIUM
Adjacent
|
-
|
-
|
Una vulnerabilidad de seguridad ha sido detectada en OmniPEMF NeoRhythm hasta el 20260308. Esto afecta una función desconocida del componente Interfaz BLE. Dicha manipulación conduce a la falta de au…
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-2756
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2836
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in trueleaf ApiFlow 0.9.7. The impacted element is the function validateUrlSecurity of the file packages/server/src/service/proxy/http_proxy.service.ts of the component…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-4528
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2837
|
7.3 |
HIGH
Network
|
-
|
-
|
Se determinó una vulnerabilidad en trueleaf ApiFlow 0.9.7. El elemento afectado es la función validateUrlSecurity del archivo packages/server/src/service/proxy/http_proxy.service.ts del componente Ge…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-4528
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2838
|
8.1 |
HIGH
Network
|
-
|
-
|
The Import and export users and customers plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.29.7. This is due to the 'save_extra_user_profile_fields' …
|
CWE-269
Improper Privilege Management
|
CVE-2026-3629
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2839
|
8.1 |
HIGH
Network
|
-
|
-
|
El plugin Importar y exportar usuarios y clientes para WordPress es vulnerable a escalada de privilegios en todas las versiones hasta, e incluyendo, la 1.29.7. Esto se debe a que la función 'save_ext…
|
CWE-269
Improper Privilege Management
|
CVE-2026-3629
|
2026-04-25 01:31 |
2026-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2840
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
tracing: Fix WARN_ON in tracing_buffers_mmap_close
When a process forks, the child process copies the parent's VMAs but the
user_…
|
CWE-617
Reachable Assertion
|
CVE-2026-23380
|
2026-04-25 01:28 |
2026-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|