Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

50089
Total
4047
Critical
14897
High
14637
Medium
CVE ID Severity Score Description Published
CVE-2026-70483 LOW 3.1 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether … Aug 04, 2026
CVE-2026-70482 HIGH 8.1 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw provider access token and … Aug 04, 2026
CVE-2026-70481 MEDIUM 5.4 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any … Aug 04, 2026
CVE-2026-70480 MEDIUM 4.1 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in … Aug 04, 2026
CVE-2026-70479 HIGH 7.7 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-level … Aug 04, 2026
CVE-2026-70478 UNKNOWN Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included … Aug 04, 2026
CVE-2026-70477 UNKNOWN Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a … Aug 04, 2026
CVE-2026-70476 UNKNOWN Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.route.ts … Aug 04, 2026
CVE-2026-70475 UNKNOWN Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts … Aug 04, 2026
CVE-2026-48154 MEDIUM 5.9 GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a … Aug 04, 2026
CVE-2026-47682 UNKNOWN CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to … Aug 04, 2026
CVE-2026-18810 HIGH 7.3 A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. … Aug 04, 2026
CVE-2026-18657 HIGH 7.8 An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a … Aug 04, 2026
CVE-2026-18656 HIGH 7.8 An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a … Aug 04, 2026
CVE-2026-16793 HIGH 8.8 An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an … Aug 04, 2026
CVE-2026-16792 MEDIUM 6.1 An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attacker to intercept sensitive … Aug 04, 2026
CVE-2026-16791 LOW 3.9 A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite … Aug 04, 2026
CVE-2026-70474 UNKNOWN Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look … Aug 04, 2026
CVE-2026-70473 UNKNOWN Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire server-wide upsert … Aug 04, 2026
CVE-2026-70472 UNKNOWN Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-controlled … Aug 04, 2026
CVE-2026-70471 UNKNOWN Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox … Aug 04, 2026
CVE-2026-69704 MEDIUM 6.5 Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsanitized input through a GET parameter to the supp() deletion … Aug 04, 2026
CVE-2026-69703 CRITICAL 9.8 Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ that allows unauthenticated attackers to bypass session-based authentication guards by sending raw … Aug 04, 2026
CVE-2026-69702 MEDIUM 6.5 SnailJob 1.7.0 contains a denial of service vulnerability in the FuryUtil.deserialize helper that allows authenticated attackers to crash the server by supplying a crafted Zstandard-compressed … Aug 04, 2026
CVE-2026-68743 MEDIUM 5.5 A flaw was found in SSSD. The extract_authtok_v1() function in the PAM responder does not validate the auth_token_length field against the remaining buffer size before … Aug 04, 2026