tag
Cwe-321
Critical
Flowise Enterprise Authentication Bypass via Hardcoded Default JWT Secrets (CVE-2026-56271)
CVE-2026-56271 (GHSA-cc4f-hjpj-g9p8)·
Flowise — open-source low-code LLM/agent orchestration platform (enterprise edition, passport authentication middleware)
patched
Critical
Gladinet CentreStack / Triofox Hardcoded AES Key Access-Ticket Forgery to Arbitrary File Read (CVE-2025-14611)
CVE-2025-14611·
Gladinet CentreStack and Triofox (GladCtrl64.dll / filesvr.dn file-download handler)
unpatched
High
Lansweeper lsrunase 2.0 / lsencrypt 2.0 — RC4 Password Recovery (CVE-2026-39031)
CVE-2026-39031·
Lansweeper lsrunase 2.0 / lsencrypt 2.0
unpatched
Critical
HAXcms Node.js Private Key Disclosure via Broken HMAC (CVE-2026-46395)
CVE-2026-46395·
HAXcms Node.js backend (elmsln/HAXcms, haxcms-nodejs) — src/lib/HAXCMS.js
patched