|
161
|
8.8 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment allows cross-workspace template takeo…
Update
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-46476
|
2026-06-15 23:04 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
162
|
5.4 |
MEDIUM
Network
|
splunk
|
splunk splunk_cloud_platform
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-20258
|
2026-06-15 23:03 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
163
|
8.8 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset create and update mass-assignment allows cross-workspace dataset takeover. Thi…
Update
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-46477
|
2026-06-15 23:02 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
164
|
8.8 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-assignment allows cross-workspace row takeover. This…
Update
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-46478
|
2026-06-15 22:58 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
165
|
8.8 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment allows cross-workspace evaluation takeove…
Update
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-46479
|
2026-06-15 22:56 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
166
|
7.8 |
HIGH
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter enabled (and the legacy pyth…
New
|
CWE-94 CWE-95 CWE-829
Code Injection Eval Injection Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-52858
|
2026-06-15 22:32 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
167
|
5.3 |
MEDIUM
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to version 9.2.0496, a code injection vulnerability exists in s:stepmatch() in the cucumber filetype plugin (runtime/ftplugin/cucumber.vim) on V…
New
|
CWE-94 CWE-95
Code Injection Eval Injection
|
CVE-2026-47167
|
2026-06-15 22:32 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
168
|
7.8 |
HIGH
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current buffer with exec() as p…
New
|
CWE-94
Code Injection
|
CVE-2026-52860
|
2026-06-15 22:24 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
169
|
8.2 |
HIGH
Network
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the scrollback buffer when a snaps…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-52859
|
2026-06-15 22:12 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
170
|
8.2 |
HIGH
Network
|
raszi
|
tmp
|
tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring ... It is bypassed when prefix, p…
Update
|
CWE-20 CWE-22
Improper Input Validation Path Traversal
|
CVE-2026-49982
|
2026-06-15 21:52 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|