LIVE · cybersecurity feed
Live wire
vendor

Dify

3 CVEs published in the last four months and 2 stories. Exploited flaws first.

Critical2
High1
Medium0
Exploited (KEV)0

All recent CVEs

CVECVSSSeverityProductSummaryPublished
CVE-2026-419489.4criticaldifyDify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate110d ago
CVE-2026-419479.1criticaldifyDify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users t110d ago
CVE-2026-614618.8highdifyDify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows atta57d ago

Filter the full tracker by Dify

Our coverage of Dify

security

Meta Ran Ads for an App That Promised to Nudify Female Politicians

One advertisement featured a pornographic video with a deepfake closely resembling a prominent US politician. Apple removed the app from the App Store after an inquiry from WIRED.

CVE-2026-19478critical

Critical GitLab flaw allows attackers to modify or delete public projects (CVE-2026-19478)

GitLab has released patches for two vulnerabilities, including a critical-severity code injection flaw that can be exploited without authentication. The vulnerabilities affect GitLab Community Edition (CE) and Enterprise Edition (EE) versions from 18.2 before 18.11.11, 19.0 before 19.0.8, 19.1 before 19.1.6, and 19.2 before 19.2.4. The fixes are available in GitLab 19.2.4, 19.1.6, 19.0.8, and 18.1