Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-66901 |
|
Vulnerability in CVE-2026-66901 (CVE-2026-66901)
vulnerability in CVE-2026-66901 (CVE-2026-66901). Confidential information can be exposed externally.
|
| CVE-2026-67979 |
|
Vulnerability in CVE-2026-67979 (CVE-2026-67979)
vulnerability in CVE-2026-67979 (CVE-2026-67979). Confidential information can be exposed externally.
|
| CVE-2026-66902 |
|
OS Command Injection in c (CVE-2026-66902)
OS command injection in c (CVE-2026-66902). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51400 |
|
Vulnerability in c (CVE-2026-51400)
vulnerability in c (CVE-2026-51400). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51401 |
|
Code Injection in c (CVE-2026-51401)
code injection in c (CVE-2026-51401). Confidential information can be exposed externally.
|
| CVE-2026-18812 |
|
Vulnerability in CVE-2026-18812 (CVE-2026-18812)
vulnerability in CVE-2026-18812 (CVE-2026-18812). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18813 |
|
Vulnerability in c (CVE-2026-18813)
vulnerability in c (CVE-2026-18813). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18811 |
|
Vulnerability in CVE-2026-18811 (CVE-2026-18811)
vulnerability in CVE-2026-18811 (CVE-2026-18811). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70590 |
|
Information Disclosure in ghost (CVE-2026-70590)
vulnerability in ghost (CVE-2026-70590). Data can be tampered with by attackers. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-45538 |
|
Vulnerability in c (CVE-2026-45538)
vulnerability in c (CVE-2026-45538). Successful exploitation can lead to full system takeover.
|
| CVE-2026-65986 |
|
Cross-Site Scripting (XSS) in CVE-2026-65986 (CVE-2026-65986)
cross-site scripting in CVE-2026-65986 (CVE-2026-65986). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-13227 |
|
Vulnerability in CVE-2026-13227 (CVE-2026-13227)
vulnerability in CVE-2026-13227 (CVE-2026-13227). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70589 |
|
Vulnerability in ghost (CVE-2026-70589)
vulnerability in ghost (CVE-2026-70589). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-70588 |
|
Cross-Site Scripting (XSS) in ghost (CVE-2026-70588)
cross-site scripting in ghost (CVE-2026-70588). Data can be tampered with by attackers. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-70494 |
|
Vulnerability in open-webui (CVE-2026-70494)
vulnerability in open-webui (CVE-2026-70494). Data can be tampered with by attackers. Exploitable via `DELETE /api/v1/folders/{id}`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70492 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-70492)
cross-site scripting in open-webui (CVE-2026-70492). Confidential information can be exposed externally. Exploitable via ``catch``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70491 |
|
Information Disclosure in open-webui (CVE-2026-70491)
vulnerability in open-webui (CVE-2026-70491). Confidential information can be exposed externally. Exploitable via `GET /api/v1/tools/`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70490 |
|
Authorization Flaw in open-webui (CVE-2026-70490)
vulnerability in open-webui (CVE-2026-70490). Risk of unauthorized operations or information disclosure. Exploitable via ``get_verified_user``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70489 |
|
Vulnerability in open-webui (CVE-2026-70489)
vulnerability in open-webui (CVE-2026-70489). Risk of unauthorized operations or information disclosure. Exploitable via ``USER_PERMISSIONS_FEATURES_AUTOMATIONS``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-54020 |
|
Vulnerability in open-webui (CVE-2026-54020)
vulnerability in open-webui (CVE-2026-54020). Confidential information can be exposed externally. Exploitable via ``image_url``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70487 |
|
Vulnerability in open-webui (CVE-2026-70487)
vulnerability in open-webui (CVE-2026-70487). Confidential information can be exposed externally. Exploitable via ``builtin_tools``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70488 |
|
Vulnerability in open-webui (CVE-2026-70488)
vulnerability in open-webui (CVE-2026-70488). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/knowledge/{id}/sync/cleanup`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-18656 |
|
Vulnerability in Amazon aws (CVE-2026-18656)
vulnerability in Amazon aws (CVE-2026-18656). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70553 |
|
Code Injection in CVE-2026-70553 (CVE-2026-70553)
code injection in CVE-2026-70553 (CVE-2026-70553). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70552 |
|
Vulnerability in CVE-2026-70552 (CVE-2026-70552)
vulnerability in CVE-2026-70552 (CVE-2026-70552). Successful exploitation can lead to full system takeover.
|
| CVE-2026-47682 |
|
Path Traversal in CVE-2026-47682 (CVE-2026-47682)
path traversal in CVE-2026-47682 (CVE-2026-47682). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18810 |
|
Authentication Bypass in CVE-2026-18810 (CVE-2026-18810)
authentication bypass in CVE-2026-18810 (CVE-2026-18810). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18657 |
|
Vulnerability in amazon (CVE-2026-18657)
vulnerability in amazon (CVE-2026-18657). Successful exploitation can lead to full system takeover.
|
| CVE-2026-16792 |
|
Vulnerability in c (CVE-2026-16792)
vulnerability in c (CVE-2026-16792). Confidential information can be exposed externally.
|
| CVE-2026-16793 |
|
Vulnerability in CVE-2026-16793 (CVE-2026-16793)
vulnerability in CVE-2026-16793 (CVE-2026-16793). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70486 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-70486)
cross-site scripting in open-webui (CVE-2026-70486). Confidential information can be exposed externally. Exploitable via ``TERMINAL_SERVER_CONNECTIONS``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70485 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-70485)
SSRF in open-webui (CVE-2026-70485). Confidential information can be exposed externally. Exploitable via `POST /api/v1/retrieval/process/web`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70484 |
|
Vulnerability in open-webui (CVE-2026-70484)
vulnerability in open-webui (CVE-2026-70484). Risk of unauthorized operations or information disclosure. Exploitable via ``features.image_generation``. Mitigation: upgrade to `897d69a` or later.
|
| CVE-2026-70480 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-70480)
SSRF in open-webui (CVE-2026-70480). Risk of unauthorized operations or information disclosure. Exploitable via ``vega``. Mitigation: upgrade to `5278eb906` or later.
|
| CVE-2026-70483 |
|
Vulnerability in open-webui (CVE-2026-70483)
vulnerability in open-webui (CVE-2026-70483). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /api/v1/chats/{id}`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70482 |
|
Authentication Bypass in open-webui (CVE-2026-70482)
authentication bypass in open-webui (CVE-2026-70482). Confidential information can be exposed externally. Exploitable via `POST /api/v1/auths/oauth/{provider}/token/exchange`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70481 |
|
Vulnerability in open-webui (CVE-2026-70481)
vulnerability in open-webui (CVE-2026-70481). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/channels/{id}/messages/{message_id}/update`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70479 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-70479)
SSRF in open-webui (CVE-2026-70479). Confidential information can be exposed externally. Exploitable via ``PLAYWRIGHT_WS_URL``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70478 |
|
Information Disclosure in flowise (CVE-2026-70478)
vulnerability in flowise (CVE-2026-70478). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/oauth2-credential/refresh/`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70477 |
|
Code Injection in flowise (CVE-2026-70477)
code injection in flowise (CVE-2026-70477). Risk of unauthorized operations or information disclosure. Exploitable via ``run``. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70476 |
|
Vulnerability in flowise (CVE-2026-70476)
vulnerability in flowise (CVE-2026-70476). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/organization/update-subscription-plan`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70475 |
|
Vulnerability in flowise (CVE-2026-70475)
vulnerability in flowise (CVE-2026-70475). Risk of unauthorized operations or information disclosure. Exploitable via `PUT /api/v1/executions/`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69704 |
|
SQL Injection in sqli (CVE-2026-69704)
SQL injection in sqli (CVE-2026-69704). Data can be tampered with by attackers.
|
| CVE-2026-69703 |
|
Vulnerability in CVE-2026-69703 (CVE-2026-69703)
vulnerability in CVE-2026-69703 (CVE-2026-69703). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68743 |
|
Out-of-Bounds Read in dos (CVE-2026-68743)
vulnerability in dos (CVE-2026-68743). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-49435 |
|
Vulnerability in CVE-2026-49435 (CVE-2026-49435)
vulnerability in CVE-2026-49435 (CVE-2026-49435). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66300 |
|
Cross-Site Scripting (XSS) in CVE-2026-66300 (CVE-2026-66300)
cross-site scripting in CVE-2026-66300 (CVE-2026-66300). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `10.12.2` or later.
|
| CVE-2026-13229 |
|
Vulnerability in CVE-2026-13229 (CVE-2026-13229)
vulnerability in CVE-2026-13229 (CVE-2026-13229). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-0163 |
|
Use-After-Free in c (CVE-2026-0163)
vulnerability in c (CVE-2026-0163). Successful exploitation can lead to full system takeover.
|
| CVE-2017-20241 |
|
Vulnerability in CVE-2017-20241 (CVE-2017-20241)
vulnerability in CVE-2017-20241 (CVE-2017-20241). Successful exploitation can lead to full system takeover.
|