Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

49853
Total
4028
Critical
14819
High
14575
Medium
CVE ID Severity Score Description Published
CVE-2026-67858 HIGH 7.5 Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauthenticated … Aug 04, 2026
CVE-2026-67857 HIGH 7.5 open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c. Aug 04, 2026
CVE-2026-67856 UNKNOWN An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, TransferSubscriptions, and DeleteSubscriptions … Aug 04, 2026
CVE-2026-67855 UNKNOWN open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial … Aug 04, 2026
CVE-2026-52370 UNKNOWN A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the … Aug 04, 2026
CVE-2026-51144 MEDIUM 6.1 Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First … Aug 04, 2026
CVE-2026-45103 HIGH 7.5 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header … Aug 04, 2026
CVE-2026-45100 CRITICAL 9.1 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} string transformation. The … Aug 04, 2026
CVE-2026-45084 UNKNOWN OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. When the … Aug 04, 2026
CVE-2026-18817 LOW 2.2 A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py of the … Aug 04, 2026
CVE-2026-18816 MEDIUM 5.0 A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA … Aug 04, 2026
CVE-2026-18814 HIGH 7.2 A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack … Aug 04, 2026
CVE-2026-70588 MEDIUM 5.0 Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting … Aug 04, 2026
CVE-2026-70554 CRITICAL 9.8 MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie … Aug 04, 2026
CVE-2026-70494 HIGH 8.1 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted … Aug 04, 2026
CVE-2026-70493 MEDIUM 6.5 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let … Aug 04, 2026
CVE-2026-70492 HIGH 8.7 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math … Aug 04, 2026
CVE-2026-70491 MEDIUM 6.5 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in … Aug 04, 2026
CVE-2026-70490 MEDIUM 6.3 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message … Aug 04, 2026
CVE-2026-70489 MEDIUM 6.5 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minutely and hourly rules … Aug 04, 2026
CVE-2026-70488 MEDIUM 4.3 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge … Aug 04, 2026
CVE-2026-70487 MEDIUM 5.3 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering … Aug 04, 2026
CVE-2026-67979 UNKNOWN Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a … Aug 04, 2026
CVE-2026-66902 UNKNOWN Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_source.executable.command … Aug 04, 2026
CVE-2026-66901 UNKNOWN Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the … Aug 04, 2026