Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
53238
Total
4231
Critical
15843
High
15500
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-59219 | HIGH | 7.1 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 before 0.10.0 with Redis configured, Socket.IO connect, user-join, join-channels, join-note, and the … | Jul 09, 2026 |
| CVE-2026-59218 | MEDIUM | 5.3 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the /api/v1/auths/signin endpoint looked users up by email and only ran … | Jul 09, 2026 |
| CVE-2026-59217 | MEDIUM | 4.3 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, the file upload path accepted metadata.knowledge_id and auto-linked uploaded files to … | Jul 09, 2026 |
| CVE-2026-59216 | HIGH | 7.7 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, get_event_call delivered execute:python and execute:tool Socket.IO events to a client-supplied session_id … | Jul 09, 2026 |
| CVE-2026-59215 | LOW | 3.1 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, channel thread parent and reply handling did not bind parent_id to … | Jul 09, 2026 |
| CVE-2026-59214 | HIGH | 7.3 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.10.0, Open WebUI runs client-side Python with Pyodide in a same-origin web … | Jul 09, 2026 |
| CVE-2026-59213 | LOW | 3.5 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.27 before 0.10.0, get_all_models handlers in routers/openai.py and routers/ollama.py passed a lambda to … | Jul 09, 2026 |
| CVE-2026-59212 | MEDIUM | 5.4 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 before 0.10.0, _verify_knowledge_file_access only checked read access while file write and delete … | Jul 09, 2026 |
| CVE-2026-59209 | UNKNOWN | — | n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated member with use-only editor access to a shared workflow … | Jul 09, 2026 |
| CVE-2026-58459 | HIGH | 7.8 | gpsd through release-3.27.5, fixed at commit 4c06658, contains a command injection vulnerability in gpsprof that allows attackers who control the GPS device subtype value to … | Jul 09, 2026 |
| CVE-2026-53987 | MEDIUM | 6.4 | The Tag plugin for GLPI 11 before 2.14.4 stores the tag name without HTML sanitization and renders it into the Kanban badge markup via PluginTagTag::preKanbanContent() … | Jul 09, 2026 |
| CVE-2026-51606 | HIGH | 7.5 | An improper input handling vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) causes the device to abruptly terminate the TCP connection with … | Jul 09, 2026 |
| CVE-2026-51605 | HIGH | 7.5 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.991) allows an unauthenticated remote attacker to cause a denial of … | Jul 09, 2026 |
| CVE-2026-51604 | HIGH | 7.5 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of … | Jul 09, 2026 |
| CVE-2026-51603 | HIGH | 7.5 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of … | Jul 09, 2026 |
| CVE-2026-51602 | HIGH | 7.5 | A stack-based buffer overflow vulnerability in the RTSP service of Tenda CP3 V3.0 (firmware V31.1.9.91) allows an unauthenticated remote attacker to cause a denial of … | Jul 09, 2026 |
| CVE-2026-51601 | UNKNOWN | — | Tenda CP3 V3.0 firmware V31.1.9.91 contains a stack-based buffer overflow in the RTSP service. The device fails to validate the length of the clock= value … | Jul 09, 2026 |
| CVE-2026-51600 | HIGH | 7.5 | Tenda CP3 V3.0 firmware V31.1.9.91 does not validate the Content-Length header field in RTSP requests (including DESCRIBE, SETUP, and PLAY methods). When a request carrying … | Jul 09, 2026 |
| CVE-2026-51599 | UNKNOWN | — | An insufficient input validation vulnerability in the RTSP service of MERCURY MIPC252W v1.0.5 Build 230306 Rel.79931n allows an unauthenticated remote attacker to render an individual … | Jul 09, 2026 |
| CVE-2026-51598 | MEDIUM | 6.5 | An input validation vulnerability in the RTSP service of MERCURY MIPC252W IP Camera v1.0.5 Build 230306 Rel.79931n) allows an unauthenticated, network-adjacent attacker to cause a … | Jul 09, 2026 |
| CVE-2026-51597 | UNKNOWN | — | MERCURY MIPC252W IP camera v1.0.5 Build 230306 Rel.79931n does not implement nonce expiration in RTSP Digest authentication. An adjacent network attacker can capture a legitimate … | Jul 09, 2026 |
| CVE-2026-15308 | UNKNOWN | — | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated markup declarations when processing uncontrolled data. | Jul 09, 2026 |
| CVE-2026-15194 | LOW | 3.3 | A security flaw has been discovered in Open5GS 2.7.7. This affects the function amf_context_final of the file src/amf/context.c of the component AMF. Performing a manipulation … | Jul 09, 2026 |
| CVE-2026-15193 | MEDIUM | 5.3 | A vulnerability was determined in AidanPark openclaw-android up to 0.4.0. The affected element is an unknown function of the file android/app/src/main/java/com/openclaw/android/JsBridge.kt of the component Android … | Jul 09, 2026 |
| CVE-2026-15192 | MEDIUM | 6.5 | A vulnerability has been found in mettle sendportal up to 3.0.1. This issue affects the function sendgrid/postmark/postal/mailjet of the component APIv1 Webhooks. The manipulation leads … | Jul 09, 2026 |