Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49732
Total
4014
Critical
14766
High
14490
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-67862 | UNKNOWN | — | open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of service. | Aug 04, 2026 |
| CVE-2026-67861 | HIGH | 7.5 | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component | Aug 04, 2026 |
| CVE-2026-67860 | UNKNOWN | — | open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend. | Aug 04, 2026 |
| CVE-2026-67859 | HIGH | 7.5 | Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling. | Aug 04, 2026 |
| CVE-2026-67858 | HIGH | 7.5 | Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated … | Aug 04, 2026 |
| CVE-2026-67857 | HIGH | 7.5 | open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c. | Aug 04, 2026 |
| CVE-2026-67856 | UNKNOWN | — | An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions … | Aug 04, 2026 |
| CVE-2026-67855 | UNKNOWN | — | open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial … | Aug 04, 2026 |
| CVE-2026-52370 | UNKNOWN | — | A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the … | Aug 04, 2026 |
| CVE-2026-51144 | MEDIUM | 6.1 | Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First … | Aug 04, 2026 |
| CVE-2026-45103 | HIGH | 7.5 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header … | Aug 04, 2026 |
| CVE-2026-45100 | CRITICAL | 9.1 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} string transformation. The … | Aug 04, 2026 |
| CVE-2026-45084 | UNKNOWN | — | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. When the … | Aug 04, 2026 |
| CVE-2026-18817 | LOW | 2.2 | A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the … | Aug 04, 2026 |
| CVE-2026-18816 | MEDIUM | 5.0 | A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA … | Aug 04, 2026 |
| CVE-2026-18814 | HIGH | 7.2 | A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack … | Aug 04, 2026 |
| CVE-2026-70588 | MEDIUM | 5.0 | Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting … | Aug 04, 2026 |
| CVE-2026-70554 | CRITICAL | 9.8 | MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie … | Aug 04, 2026 |
| CVE-2026-70494 | HIGH | 8.1 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted … | Aug 04, 2026 |
| CVE-2026-70493 | MEDIUM | 6.5 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let … | Aug 04, 2026 |
| CVE-2026-70492 | HIGH | 8.7 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math … | Aug 04, 2026 |
| CVE-2026-70491 | MEDIUM | 6.5 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in … | Aug 04, 2026 |
| CVE-2026-70490 | MEDIUM | 6.3 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message … | Aug 04, 2026 |
| CVE-2026-70489 | MEDIUM | 6.5 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minutely and hourly rules … | Aug 04, 2026 |
| CVE-2026-70488 | MEDIUM | 4.3 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge … | Aug 04, 2026 |