Vulnerabilities (CVE)

Filtered by vendor Flowiseai Subscribe
Filtered by product Flowise
Total 22 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2024-8181 1 Flowiseai 1 Flowise 2024-09-06 N/A 9.8 CRITICAL
An Authentication Bypass vulnerability exists in Flowise version 1.8.2. This could allow a remote, unauthenticated attacker to access API endpoints as an administrator and allow them to access restricted functionality.
CVE-2024-8182 1 Flowiseai 1 Flowise 2024-08-30 N/A 7.5 HIGH
An Unauthenticated Denial of Service (DoS) vulnerability exists in Flowise version 1.8.2 leading to a complete crash of the instance running a vulnerable version due to improper handling of user supplied input to the “/api/v1/get-upload-file” api endpoint.