Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
49853
Total
4028
Critical
14819
High
14575
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-65986 | UNKNOWN | — | CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be … | Aug 04, 2026 |
| CVE-2026-54020 | MEDIUM | 6.3 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, … | Aug 04, 2026 |
| CVE-2026-51401 | UNKNOWN | — | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c | Aug 04, 2026 |
| CVE-2026-51400 | UNKNOWN | — | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c | Aug 04, 2026 |
| CVE-2026-45538 | CRITICAL | 9.8 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 … | Aug 04, 2026 |
| CVE-2026-18813 | HIGH | 7.2 | A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads … | Aug 04, 2026 |
| CVE-2026-18812 | HIGH | 7.2 | A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the … | Aug 04, 2026 |
| CVE-2026-18811 | HIGH | 7.2 | A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the argument … | Aug 04, 2026 |
| CVE-2026-13227 | UNKNOWN | — | An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects … | Aug 04, 2026 |
| CVE-2026-70553 | CRITICAL | 9.8 | MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted … | Aug 04, 2026 |
| CVE-2026-70552 | CRITICAL | 9.8 | MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any … | Aug 04, 2026 |
| CVE-2026-70486 | HIGH | 8.2 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together … | Aug 04, 2026 |
| CVE-2026-70485 | HIGH | 7.1 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally … | Aug 04, 2026 |
| CVE-2026-70484 | MEDIUM | 4.3 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag … | Aug 04, 2026 |
| CVE-2026-70483 | LOW | 3.1 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether … | Aug 04, 2026 |
| CVE-2026-70482 | HIGH | 8.1 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and … | Aug 04, 2026 |
| CVE-2026-70481 | MEDIUM | 5.4 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any … | Aug 04, 2026 |
| CVE-2026-70480 | MEDIUM | 4.1 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in … | Aug 04, 2026 |
| CVE-2026-70479 | HIGH | 7.7 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level … | Aug 04, 2026 |
| CVE-2026-70478 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included … | Aug 04, 2026 |
| CVE-2026-70477 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a … | Aug 04, 2026 |
| CVE-2026-70476 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts … | Aug 04, 2026 |
| CVE-2026-70475 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts … | Aug 04, 2026 |
| CVE-2026-48154 | MEDIUM | 5.9 | GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a … | Aug 04, 2026 |
| CVE-2026-47682 | UNKNOWN | — | CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to … | Aug 04, 2026 |