VulnSea

Flowring Technology Corp has 5 CVEs on record. 5 were published in the last 90 days. The busiest recent month was September 2026 with 5. The median CVSS is 9.3 (critical), with 3 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
9.3
Publish → KEV
—
Last 90 days
5 prev 0

Products

  • Agentflow 4.0 5
Follow Flowring Technology Corp:RSS feedSave a search →Embed badge ↗
5
Total CVEs
3
Critical
0
CISA KEV
0
Exploited

Flowring Technology Corp vulnerabilities

CVEs affecting Flowring Technology Corp, newest first. Open any entry for full detail, references, and exploit status.

5 CVEsRSS

CVE-2026-96440High· 7.1
today

Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to ar…

Improper Limitation of a Pathname to a Restricted Directory(Path Traversal) in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to write files to ar…

▾ TwilightFlowring Technology Corp · Agentflow 4.0via NVD
CVE-2026-96431Critical· 9.3
today

Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malic…

Unrestricted Upload of File with Dangerous Type in the /WebAgenda/download/uploadFile.jsp API endpoint of Flowring Agentflow 4.0 version before 2023/03/24 allows remote authenticated users to execute arbitrary system commands via a malic…

▾ MidnightFlowring Technology Corp · Agentflow 4.0via NVD
CVE-2026-96430High· 8.7
today

Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter.

Exposed Dangerous Method or Function in the /WebAgenda/SQLWin.do API endpoint of Flowring Agentflow 4.0 version Before 2026/08/28 allows remote authenticated users to execute arbitrary SQL commands via the sql parameter.

▾ TwilightFlowring Technology Corp · Agentflow 4.0via NVD
CVE-2026-96429Critical· 9.3
today

SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter.

SQL Injection in the /WebAgenda/SMBAjaxConfigProcess.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the id parameter.

▾ MidnightFlowring Technology Corp · Agentflow 4.0via NVD
CVE-2026-96428Critical· 9.3
today

SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter.

SQL Injection in the /WebAgenda/SMBAjaxAutoComplete.do API endpoint of Flowring Agentflow 4.0 version before 2025/08/08 allows remote attackers to execute arbitrary SQL commands via the words parameter.

▾ MidnightFlowring Technology Corp · Agentflow 4.0via NVD
Flowring Technology Corp vulnerabilities (CVEs) · VulnSea