CVE Browser
Dify < 1.16.0-rc1 SQL Injection via MyScale Vector Store search_by_full_text
Dify < 1.14.2 Authorization Bypass via File Preview Endpoint
Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access
Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpoints
Dify has IDOR in deleting someone else's chat conversation
Dify - Stored XSS in chat
Dify has a user enumeration issue
Client‑side DOM XSS in the web chat app of Dify when using echarts
Dify Vulnerable to Plaintext API Key Exposure via Model Provider Configuration Endpoint
Dify v1.6.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component controllers.console.remote_files.RemoteFileUploadApi. A different…
Server-Side Request Forgery (SSRF) in langgenius/dify
Pandas Query Injection in langgenius/dify
Showing 1 to 12 CVEs · page 1