-
Vulnerability Watch No26
Flowise Permission Flaw Enables Cross-Type Flow Deletion • Flowise SQLite Path Override Leads to Root Command Execution • Public Flowise Chatflows Exposed to Configuration Injection • Flowise IPv6 Parsing Bypass Opens the Door to SSRF • Flowise CSV Agent Pickle Bypass Enables Command Execution…
-
Vulnerability Watch No16
NoteGen Shell Permissions Enable Full Remote Code Execution • Unsanitized AI Responses Expose NoteGen Users to XSS • WordPress Membership Flaw Lets Visitors Claim Elevated Roles • Critical SQL Injection Hits WordPress Issue-Tracking Plugin • CAFEHAUS API Bug Enables Administrator Account Takeover…