CVE-2025-58434 Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the forgot-password endpoint in Flowise returns sensitive information inc ...

Continue Reading
CVE-2025-58434 Flowise Cloud and Local Deployments have Unauthenticated Password Reset Token Disclosure that Leads to Account Takeover

Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5 and earlier, the forgot-password endpoint in Flowise returns sensitive information inc ...

Continue Reading
CVE-2025-59034

Indico is an event management system that uses Flask-Multipass, a multi-backend authentication system for Flask. Prior to version 3.3.8, a legacy API to retrieve user details could be misused to retri ...

Continue Reading
CVE-2025-27234

creation_timestamp| type| source ---|---|--- 2025-09-12 14:56:32+00:00| seen|...Read More ...

Continue Reading
CVE-2025-27233

creation_timestamp| type| source ---|---|--- 2025-09-12 14:53:48+00:00| seen|...Read More ...

Continue Reading
CVE-2024-34343

creation_timestamp| type| source ---|---|--- 2025-09-12 15:01:41+00:00| seen|...Read More ...

Continue Reading
CVE-2025-6638

creation_timestamp| type| source ---|---|--- 2025-09-12 14:59:33+00:00| seen|...Read More ...

Continue Reading
CVE-2025-59058

creation_timestamp| type| source ---|---|--- 2025-09-12 15:10:56+00:00| seen|...Read More ...

Continue Reading

Back to Main

Subscribe for the latest news: