Export limit exceeded: 400206 CVEs match your query. Please refine your search to export 10,000 CVEs or fewer.
Search
Search Results (5 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-96428 | 1 Flowring Technology Corp | 1 Agentflow 4.0 | 2026-09-30 | N/A |
| SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter. | ||||
| CVE-2026-96429 | 1 Flowring Technology Corp | 1 Agentflow 4.0 | 2026-09-30 | N/A |
| SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter. | ||||
| CVE-2026-96430 | 1 Flowring Technology Corp | 1 Agentflow 4.0 | 2026-09-30 | N/A |
| Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter. | ||||
| CVE-2026-96431 | 1 Flowring Technology Corp | 1 Agentflow 4.0 | 2026-09-30 | N/A |
| Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malicious file. | ||||
| CVE-2026-96440 | 1 Flowring Technology Corp | 1 Agentflow 4.0 | 2026-09-30 | N/A |
| Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to arbitrary locations outside the intended upload directory via the path parameter. | ||||
Page 1 of 1.