CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV Catalog
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence…
A chain of three vulnerabilities in LiteLLM, a widely deployed open-source AI gateway, allows low-privilege users to escalate to full admin and…
CVE-2026-47101 is an authorization bypass vulnerability in LiteLLM where the allowed_routes field is not validated against user roles, allowing low-privilege users to…
A critical authorization bypass vulnerability (CVSS 9.1) in Dify that allows authenticated editor users to set and enable trace configurations for any…
An authorization bypass vulnerability (CVSS 7.5/5.9) in Dify's file preview endpoint that allows any authenticated user to read up to 3,000 characters…
An authorization bypass vulnerability (CVSS 6.5) in Dify that allows authenticated users to read the full contents of files uploaded by other…