Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-67855 — open62541 GDS PushManagement Heap Use-After-Free

open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker to cause a denial of service.

| Memory Corruption
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-52370 — O2OA Forum Reflected Cross-Site Scripting

A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim's browser via a crafted UR…

| Cross-Site Scripting
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-51144 — Soliton Systems MailZen Management Portal Cross-Site Scripting Vulnerability

Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First Name, Last Name, and Usernam…

| Cross-Site Scripting
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
7.5 HIGH
CVE-2026-45103 — OpenSIPS: SIP Message Smuggling via TCP Content-Length Integer Overflow

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length header using unsigned int arit…

opensips | Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.1 CRITICAL
CVE-2026-45100 — OpenSIPS: Buffer Overflow in Base64 Encode Transformation

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0-beta through 3.6.5 and 4.0.0-beta contain a buffer overflow in the {s.b64encode} string transformation. The size …

opensips | Remote | Memory Corruption
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.7 HIGH
CVE-2026-45084 — OpenSIPS: Denial of service in presence.handle_publish() from unchecked Content-Type state

OpenSIPS is a Session Initiation Protocol (SIP) server implementation. Versions 3.4.0 through 3.6.5 contain a denial of service vulnerability in the presence module. When the presence module's handle…

opensips | Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
2.2 LOW
CVE-2026-18817 — Baserow Inactive Non-Staff User serializers.py BaserowImpersonateAuthTokenSerializer impr…

A security flaw has been discovered in Baserow up to 2.3.2. Affected by this issue is the function BaserowImpersonateAuthTokenSerializer of the file backend/src/baserow/api/admin/users/serializers.py…

baserow | Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.0 MEDIUM
CVE-2026-18816 — Baserow 2FA Verify Endpoint views.py verify improper authentication

A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of the component 2FA Verify E…

baserow | Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.3 HIGH
CVE-2026-18814 — H3C NX15 esps reload.reload_config command injection

A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The attack can be launched remotel…

nx15 | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.0 MEDIUM
CVE-2026-70588 — Ghost: Cross-Site Scripting in Universal Import

Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting in XSS in post content. This…

ghost | Remote | Cross-Site Scripting
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
9.8 CRITICAL
CVE-2026-70554 — MaxSite CMS Unauthenticated PHP Object Injection via maxsite_comuser Cookie

MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in the maxsite_comuser cookie …

cms | Remote | Injection
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.1 HIGH
CVE-2026-70494 — Open WebUI: A folder write-collaborator can permanently delete the owner's chats by delet…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webui/routers/folders.py allowe…

open_webui | Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.5 MEDIUM
CVE-2026-70493 — Open WebUI: Any authenticated user can stall a worker via a knowledge-search pattern that…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tools/knowledge_fs.py and backe…

open_webui | Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
8.7 HIGH
CVE-2026-70492 — Open WebUI: Stored XSS via unescaped KaTeX render-error fallback in rendered messages

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svelte could store and render a…

open_webui | Remote | Cross-Site Scripting
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.5 MEDIUM
CVE-2026-70491 — Open WebUI: Tool source code disclosed to read-only users via the tool list and get endpo…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1/tools/id/{id} endpoints in…

open_webui | Remote | Information Disclosure
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.3 MEDIUM
CVE-2026-70490 — Open WebUI: Unapproved accounts can open terminal sessions via a WebSocket auth path miss…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/terminals.py authenticated it…

open_webui | Remote | Authentication
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
6.5 MEDIUM
CVE-2026-70489 — Open WebUI: Instance-wide stall via automation recurrence rules that force multi-second p…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/automations.py anchored minute…

open_webui | Remote | Denial of Service
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
4.3 MEDIUM
CVE-2026-70488 — Open WebUI: Deletion of directories and file embeddings in other knowledge bases via sync…

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the knowledge base in the URL but t…

open_webui | Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
5.3 MEDIUM
CVE-2026-70487 — Open WebUI: Cross-user file content disclosure via request-scoped direct model knowledge …

Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowledge attachments without filt…

open_webui | Remote | Authorization
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
0.0 NA
CVE-2026-67979 — NASA cFS Executive Services Arbitrary Code Execution

Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shared object on target storage.

| Path Traversal
Aug 04, 2026 Aug 04, 2026
Aug 04, 2026
Aug 04, 2026
Showing 20 of 9597 Results