A vulnerability identified as critical has been detected in Cisco AsyncOS. Affected by this vulnerability is an unknown functionality of the component Email Parsing. The manipulation leads to sql injection.
This vulnerability is documented as CVE-2026-76461. The attack can be initiated remotely. Additionally, an exploit exists.
You should upgrade the affected component.
A vulnerability was found in xnio and classified as critical. The impacted element is an unknown function of the component NotifierState. Such manipulation leads to stack-based buffer overflow.
This vulnerability is uniquely identified as CVE-2023-5685. The attack can only be initiated within the local network. No exploit exists.
A vulnerability, which was classified as problematic, has been found in UiPress Lite Plugin up to 3.5.08 on WordPress. This affects the function uip_save_ui_template. This manipulation causes cross site scripting.
This vulnerability is tracked as CVE-2025-11003. The attack is possible to be carried out remotely. No exploit exists.
A vulnerability has been found in Huginn up to 2022.08.18 and classified as problematic. Affected by this issue is the function fetch_url of the component ScenarioImport. Performing a manipulation results in server-side request forgery.
This vulnerability was named CVE-2026-63769. The attack may be initiated remotely. There is no available exploit.
A vulnerability, which was classified as critical, has been found in FlowiseAI Flowise up to 3.1.2. Impacted is an unknown function of the component OAuth2 Token Refresh Endpoint. The manipulation leads to server-side request forgery.
This vulnerability is documented as CVE-2026-69250. The attack can be initiated remotely. There is not any exploit available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, was found in FlowiseAI Flowise and Flowise Components up to 3.1.2. The affected element is an unknown function of the file packages/components/nodes/recordmanager/MySQLRecordManager/MySQLrecordManager.ts of the component Record Manager/Agent Memory. The manipulation of the argument additionalConfig results in code injection.
This vulnerability is reported as CVE-2026-69251. The attack can be launched remotely. No exploit exists.
You should upgrade the affected component.
A vulnerability was found in FlowiseAI Flowise up to 3.1.2. It has been rated as critical. Affected by this vulnerability is the function getAllFiles/deleteFile of the file /api/v1/files of the component File Management. The manipulation of the argument path leads to permission issues.
This vulnerability is uniquely identified as CVE-2026-69252. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
A vulnerability identified as critical has been detected in FlowiseAI Flowise up to 3.1.2. This affects the function isValidURL of the component AgentAsTool/ChatflowTool/ExecuteFlow. This manipulation of the argument baseURL causes code injection.
The identification of this vulnerability is CVE-2026-69253. It is possible to initiate the attack remotely. There is no exploit available.
You should upgrade the affected component.
A vulnerability labeled as very critical has been found in FlowiseAI Flowise up to 3.1.2. This vulnerability affects the function executeJavaScriptCode of the file packages/components/src/utils.ts of the component JavaScript Code Execution. Such manipulation of the argument nodeVMOptions leads to command injection.
This vulnerability is referenced as CVE-2026-69254. It is possible to launch the attack remotely. No exploit is available.
The affected component should be upgraded.
A vulnerability, which was classified as very critical, has been found in FlowiseAI Flowise up to 3.1.2. Affected by this vulnerability is the function validatePythonCodeForDataFrame of the file packages/components/nodes/agents/CSVAgent/CSVAgent.ts of the component CSVAgent. Performing a manipulation results in os command injection.
This vulnerability is cataloged as CVE-2026-69255. It is possible to initiate the attack remotely. There is no exploit available.
It is advisable to upgrade the affected component.
A vulnerability, which was classified as critical, was found in FlowiseAI Flowise up to 3.1.2. Affected by this issue is the function pandas.read_pickle of the file flowise-components/nodes/agents/CSVAgent/CSVAgent.ts of the component CSVAgent. Executing a manipulation of the argument customReadCSVFunc can lead to deserialization.
This vulnerability is registered as CVE-2026-69256. It is possible to launch the attack remotely. No exploit is available.
You should upgrade the affected component.
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]