Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-70553 — MaxSite CMS Unauthenticated RCE via Install Endpoint

MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST reques…

cms | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.8 CRITICAL
CVE-2026-70552 — MaxSite CMS 109.5 Unauthenticated AJAX Dispatcher Bypass via ajax.php

MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints by supplying any X-Requested…

cms | Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.2 HIGH
CVE-2026-70486 — Open WebUI: Same-origin XSS to account takeover via terminal file-preview iframe hardcodi…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always granted allow-same-origin togeth…

Remote | Cross-Site Scripting
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.1 HIGH
CVE-2026-70485 — Open WebUI: Any authenticated user can reach internal services and cloud metadata via NAT…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination was globally routable by appl…

Remote | Server-Side Request Forgery
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
4.3 MEDIUM
CVE-2026-70484 — Open WebUI: Users denied the image-generation permission can still generate images via ch…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-supplied image_generation fl…

Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
3.1 LOW
CVE-2026-70483 — Open WebUI: Any authenticated user can cancel another user's chat generation via the chat…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks before checking whether the…

Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.1 HIGH
CVE-2026-70482 — Open WebUI: Account takeover via OAuth token exchange accepting tokens issued to any clie…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/token/exchange accepts a raw pr…

Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.4 MEDIUM
CVE-2026-70481 — Open WebUI: Any member with write access to a standard channel can edit or delete other m…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accepted any caller holding writ…

Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
4.1 MEDIUM
CVE-2026-70480 — Open WebUI: Client-side SSRF via unrestricted external resource loading in Vega/Vega-Lite…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in chat content by building a …

Remote | Server-Side Request Forgery
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.7 HIGH
CVE-2026-70479 — Open WebUI: SSRF into internal services via unvalidated sub-resource requests in the Play…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader validates only the top-leve…

Remote | Server-Side Request Forgery
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.2 CRITICAL
CVE-2026-70478 — Flowise: Unauthenticated OAuth2 token refresh endpoint returns access tokens — enables to…

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint is included in WHITELIST_URL…

flowise | Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.5 CRITICAL
CVE-2026-70477 — Flowise: CSV Agent Prompt Injection Remote Code Execution Vulnerability

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can cause the LLM to respond with…

flowise | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.3 HIGH
CVE-2026-70476 — Flowise: Broken Access Control in Stripe Subscription Endpoints Allows Cross-Tenant Billi…

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enterprise/routes/organization.r…

flowise | Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.1 HIGH
CVE-2026-70475 — Flowise: Missing Authorization on Execution Update Endpoint

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/routes/executions/index.ts lack…

flowise | Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.9 MEDIUM
CVE-2026-48154 — GoRest: InMemorySecret2FA race condition allows process crash via concurrent map access

GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condition due to an unsynchronize…

Remote | Race Condition
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.1 HIGH
CVE-2026-47682 — CVAT: Missing path-containment validation in multiple entry points allows arbitrary path …

CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage that's been added to a CVAT …

Remote | Misconfiguration
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.5 HIGH
CVE-2026-18810 — H3C NX15 networkSetup missing authentication

A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing authentication. The attack ma…

nx15 | Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.5 HIGH
CVE-2026-18657 — Executable Resolution from Untrusted Project Directory in Kiro CLI on Windows

An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory conta…

kiro_cli | Path Traversal
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.5 HIGH
CVE-2026-18656 — Executable Resolution from Untrusted Project Directory in Kiro IDE on Windows

An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously crafted project directory cont…

kiro_ide | Path Traversal
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.8 HIGH
CVE-2026-16793 — Remote Command Injection via OS Profile Password in Lenovo XClarity Orchestrator

An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow an authenticated attacker t…

xclarity_orchestrator | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
Showing 20 of 9535 Results