Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-70590 — Ghost: Blind Password Hash Disclosure in Ghost Admin API

Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. An offline password-guessin…

| Information Disclosure
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-45084 — OpenSIPS: Denial of service in presence.handle_publish() from unchecked Content-Type state

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. When the presence module's handle…

| Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.8 HIGH
CVE-2026-70619 — Odysseus Missing Admin Authorization via Embedding Endpoint Routes

Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuration by invoking endpoint mana…

Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.0 MEDIUM
CVE-2026-70588 — Ghost: Cross-Site Scripting in Universal Import

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This…

Remote | Cross-Site Scripting
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.8 CRITICAL
CVE-2026-70554 — MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie …

cms | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.1 HIGH
CVE-2026-70494 — Open WebUI: A folder write-collaborator can permanently delete the owner's chats by delet…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowe…

Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.5 MEDIUM
CVE-2026-70493 — Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backe…

Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.7 HIGH
CVE-2026-70492 — Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a…

Remote | Cross-Site Scripting
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.5 MEDIUM
CVE-2026-70491 — Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpo…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in…

Remote | Information Disclosure
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.3 MEDIUM
CVE-2026-70490 — Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path miss…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated it…

Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.5 MEDIUM
CVE-2026-70489 — Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second p…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minute…

Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
4.3 MEDIUM
CVE-2026-70488 — Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but t…

Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.3 MEDIUM
CVE-2026-70487 — Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge …

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filt…

Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-67979 — NASA cFS Executive Services Arbitrary Code Execution

Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.

| Path Traversal
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-66902 — Google::Auth versions before 0.06 for Perl run a command named in an external_account cre…

Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_source.executable.command f…

| Misconfiguration
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-66901 — Google::Auth versions before 0.09 for Perl allow server side request forgery and credenti…

Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the library requests are read …

| Server-Side Request Forgery
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.5 HIGH
CVE-2026-65986 — CVAT has stored XSS via annotation guide assets

CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed through annotation guide assets.…

Remote | Cross-Site Scripting
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.3 MEDIUM
CVE-2026-54020 — Open WebUI: DNS Rebinding SSRF Bypass

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected private, loopback, and link-lo…

Remote | Server-Side Request Forgery
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-51401 — Vim Arbitrary Code Execution

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

| Memory Corruption
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-51400 — Vim Arbitrary Code Execution

An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c

| Memory Corruption
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
Showing 20 of 9568 Results