Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50089
Total
4047
Critical
14897
High
14637
Medium
CVE ID Severity Score Description Published
CVE-2026-70494 HIGH 8.1 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowed a user granted … Aug 04, 2026
CVE-2026-70493 MEDIUM 6.5 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backend/open_webui/tools/builtin.py let … Aug 04, 2026
CVE-2026-70492 HIGH 8.7 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a chat message whose math … Aug 04, 2026
CVE-2026-70491 MEDIUM 6.5 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in … Aug 04, 2026
CVE-2026-70490 MEDIUM 6.3 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated its own first-message … Aug 04, 2026
CVE-2026-70489 MEDIUM 6.5 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minutely and hourly rules … Aug 04, 2026
CVE-2026-70488 MEDIUM 4.3 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge … Aug 04, 2026
CVE-2026-70487 MEDIUM 5.3 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filtering … Aug 04, 2026
CVE-2026-67979 UNKNOWN Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a … Aug 04, 2026
CVE-2026-66902 UNKNOWN Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_source.executable.command … Aug 04, 2026
CVE-2026-66901 UNKNOWN Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the … Aug 04, 2026
CVE-2026-65986 UNKNOWN CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be … Aug 04, 2026
CVE-2026-54020 MEDIUM 6.3 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, … Aug 04, 2026
CVE-2026-51401 UNKNOWN An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c Aug 04, 2026
CVE-2026-51400 UNKNOWN An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c Aug 04, 2026
CVE-2026-45538 CRITICAL 9.8 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 … Aug 04, 2026
CVE-2026-18813 HIGH 7.2 A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads … Aug 04, 2026
CVE-2026-18812 HIGH 7.2 A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the … Aug 04, 2026
CVE-2026-18811 HIGH 7.2 A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the argument … Aug 04, 2026
CVE-2026-13227 UNKNOWN An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doctype.prospect.prospect.get_opportunities. This issue affects … Aug 04, 2026
CVE-2026-70553 CRITICAL 9.8 MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted … Aug 04, 2026
CVE-2026-70552 CRITICAL 9.8 MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any … Aug 04, 2026
CVE-2026-70486 HIGH 8.2 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin together … Aug 04, 2026
CVE-2026-70485 HIGH 7.1 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally … Aug 04, 2026
CVE-2026-70484 MEDIUM 4.3 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation flag … Aug 04, 2026