| Oct 312025 | Agno session state overwrites between different sessions/users agnoHigh7.1Oct 31, 2025 | agno | High7.1 | 2.2.2 |
| Oct 302025 | n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook n8nHigh8.8Oct 30, 2025 | n8n | High8.8 | 1.113.0 |
| Oct 302025 | Apache Airflow `/api/v2/dagReports` executes DAG Python in API Apache AirflowMedium5.4Oct 30, 2025 | Apache Airflow | Medium5.4 | 3.1.1 |
| Oct 302025 | Apache Airflow's create action can upsert existing Pools/Connections/Variables Apache AirflowMedium4.6Oct 30, 2025 | Apache Airflow | Medium4.6 | 3.1.1 |
| Oct 302025 | Apache Airflow has a command injection vulnerability in "example_dag_decorator" Apache AirflowMediumOct 30, 2025 | Apache Airflow | Medium | 3.0.5 |
| Oct 292025 | MLflow Tracking Server Model Creation Directory Traversal Remote Code Execution Vulnerability MLflowHigh8.1Oct 29, 2025 | MLflow | High8.1 | 2.22.4+1 more |
| Oct 292025 | MLflow Weak Password Requirements Authentication Bypass Vulnerability MLflowHigh8.1Oct 29, 2025 | MLflow | High8.1 | 2.22.0rc0 |
| Oct 292025 | FastMCP vulnerable to windows command injection in FastMCP Cursor installer via server_name fastmcpMediumOct 29, 2025 | fastmcp | Medium | 2.13.0 |
| Oct 292025 | FastMCP vulnerable to reflected XSS in client's callback page fastmcpMediumOct 29, 2025 | fastmcp | Medium | 2.13.0 |
| Oct 292025 | FastMCP Auth Integration Allows for Confused Deputy Account Takeover fastmcpHighOct 29, 2025 | fastmcp | High | 2.13.0 |
| Oct 292025 | Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery KerasMediumOct 29, 2025 | Keras | Medium | 3.12.0 |
| Oct 282025 | Consul key/value endpoint is vulnerable to denial of service ConsulMedium6.5Oct 28, 2025 | Consul | Medium6.5 | 1.22.0 |
| Oct 282025 | Consul event endpoint is vulnerable to denial of service ConsulMedium6.5Oct 28, 2025 | Consul | Medium6.5 | 1.22.0 |
| Oct 272025 | Python - Zip64 Locator Offset Vulnerability GoogleMediumOct 27, 2025 | Google | Medium | No fix yet |
| Oct 232025 | Hashicorp Vault and Vault Enterprise vulnerable to a denial of service when processing JSON VaultHigh7.5Oct 23, 2025 | Vault | High7.5 | 1.21.0 |
| Oct 232025 | HashiCorp Vault and Vault Enterprise's AWS Auth method may be susceptible to authentication bypass VaultHigh8.1Oct 23, 2025 | Vault | High8.1 | 1.21.0 |
| Oct 222025 | OpenBao and Vault Leak []byte Fields in Audit Logs OpenBaoMediumOct 22, 2025 | OpenBao | Medium | 0.0.0-20251022165510-cc2c476bac66 |
| Oct 222025 | OpenBao leaks HTTPRawBody in Audit Logs OpenBaoMediumOct 22, 2025 | OpenBao | Medium | 0.0.0-20251022165510-cc2c476bac66 |
| Oct 172025 | Keras framework vulnerable to deserialization of untrusted data KerasCritical9.8Oct 17, 2025 | Keras | Critical9.8 | 3.11.3 |
| Oct 172025 | OpenBao has potential Denial of Service vulnerability when processing malicious unauthenticated JSON requests OpenBaoHigh7.5Oct 17, 2025 | OpenBao | High7.5 | 2.4.1 |
| Oct 162025 | MinIO is Vulnerable to Privilege Escalation via Session Policy Bypass in Service Accounts and STS MinIOHigh8.1Oct 16, 2025 | MinIO | High8.1 | 0.0.0-20251015170045-c1a49490c78e |
| Oct 152025 | Apache Spark has Inadequate Encryption Strength Apache SparkLowOct 15, 2025 | Apache Spark | Low | 3.4.4+1 more |
| Oct 142025 | Flowise: Authenticated Command Execution and Sandbox Bypass via Puppeteer and Playwright Packages FlowiseHighOct 14, 2025 | Flowise | High | 3.0.8 |
| Oct 132025 | llama-index has Insecure Temporary File LlamaIndexHigh7.1Oct 13, 2025 | LlamaIndex | High7.1 | 0.13.0 |
| Oct 102025 | Flowise is vulnerable to arbitrary file exposure through its ReadFileTool FlowiseHigh7.7Oct 10, 2025 | Flowise | High7.7 | 3.0.8 |
| Oct 102025 | Elasticsearch: Insertion of Sensitive Information into Log File via reindex API ElasticsearchMedium5.7Oct 10, 2025 | Elasticsearch | Medium5.7 | 8.18.8+3 more |
| Oct 92025 | n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host n8nHigh8.8Oct 9, 2025 | n8n | High8.8 | No fix yet |
| Oct 92025 | Flowise is vulnerable to arbitrary file write through its WriteFileTool FlowiseCritical9.9Oct 9, 2025 | Flowise | Critical9.9 | 3.0.8 |
| Oct 82025 | FlowiseAI/Flosise has File Upload vulnerability FlowiseHigh8.3Oct 8, 2025 | Flowise | High8.3 | 3.0.8 |
| Oct 72025 | vLLM is vulnerable to Server-Side Request Forgery (SSRF) through `MediaConnector` class vLLMHigh7.1Oct 7, 2025 | vLLM | High7.1 | 0.11.0 |
| Oct 72025 | LLaMA Factory's Chat API Contains Critical SSRF and LFI Vulnerabilities LlamaFactoryHigh7.6Oct 7, 2025 | LlamaFactory | High7.6 | 0.9.4 |
| Oct 72025 | vLLM: Resource-Exhaustion (DoS) through Malicious Jinja Template in OpenAI-Compatible Server vLLMMedium6.5Oct 7, 2025 | vLLM | Medium6.5 | 0.11.0 |
| Oct 72025 | vLLM is vulnerable to timing attack at bearer auth vLLMHigh7.5Oct 7, 2025 | vLLM | High7.5 | 0.11.0 |
| Oct 62025 | SillyTavern Web Interface Vulnerable DNS Rebinding SillyTavernCritical9.6Oct 6, 2025 | SillyTavern | Critical9.6 | 1.13.4 |
| Oct 62025 | Flowise vulnerable to RCE via Dynamic function constructor injection FlowiseCritical9.8Oct 6, 2025 | Flowise | Critical9.8 | No fix yet |
| Oct 52025 | clearml is vulnerable to Path Traversal through its `safe_extract` function ClearMLMedium5.8Oct 5, 2025 | ClearML | Medium5.8 | 2.0.2 |
| Oct 52025 | ZenML is vulnerable to Path Traversal through its `PathMaterializer` class ZenMLMedium6.3Oct 5, 2025 | ZenML | Medium6.3 | 0.84.2 |
| Oct 32025 | Flowise Stored XSS vulnerability through logs in chatbot FlowiseMedium5.3Oct 3, 2025 | Flowise | Medium5.3 | 3.0.5 |
| Oct 32025 | Flowise is vulnerable to stored XSS via "View Messages" allows credential theft in FlowiseAI admin panel FlowiseCritical9.3Oct 3, 2025 | Flowise | Critical9.3 | 3.0.8 |
| Oct 32025 | Flowise vulnerable to XSS FlowiseMediumOct 3, 2025 | Flowise | Medium | 3.0.8 |
| Oct 32025 | Command execution prior to Claude Code startup trust dialog AnthropicHigh8.7Oct 3, 2025 | Anthropic | High8.7 | v1.0.111 |
| Oct 32025 | Permission deny bypass through symlink AnthropicLow2.3Oct 3, 2025 | Anthropic | Low2.3 | v1.0.120 |
| Oct 22025 | Apache Kylin Server-Side Request Forgery (SSRF) Vulnerability kylinHigh7.3Oct 2, 2025 | kylin | High7.3 | 5.0.3 |
| Oct 22025 | Apache Kylin Authentication Bypass Vulnerability kylinHigh7.5Oct 2, 2025 | kylin | High7.5 | 5.0.3 |
| Oct 22025 | Apache Kylin Files or Directories Accessible to External Parties kylinHigh7.5Oct 2, 2025 | kylin | High7.5 | 5.0.3 |
| Oct 22025 | Cursor CLI Agent - Sensitive File Overwrite Bypass CursorHigh7.1Oct 2, 2025 | Cursor | High7.1 | 2025.09.17-25b418f |
| Oct 22025 | Cursor IDE - Sensitive File Overwrite Bypass CursorHigh8.0Oct 2, 2025 | Cursor | High8.0 | 1.7 |
| Oct 22025 | Remote Code Execution in Cursor CLI via Cursor Agent MCP OAuth2 Communication CursorHigh8.8Oct 2, 2025 | Cursor | High8.8 | 2025.09.17-25b418f |
| Oct 22025 | Arbitrary code execution Permissive CLI Config in Cursor CLI CursorHigh8.8Oct 2, 2025 | Cursor | High8.8 | 2025.09.17-25b418f |
| Oct 22025 | RCE via .code-workspace files using Prompt Injection CursorHigh7.5Oct 2, 2025 | Cursor | High7.5 | 1.7 |
| Oct 22025 | Potential Information Leakage via Mermaid Diagram CursorMedium5.9Oct 2, 2025 | Cursor | Medium5.9 | 1.7 |
| Oct 12025 | Improper File Type Handling in Bulk User Import in Auth0 Wordpress plugin CVE-2025-58769... OktaUnratedOct 1, 2025 | Okta | Unrated | No fix yet |