Search
283 CVEs · published 2026-08-04 to 2026-08-04
CVEs (283)
Showing 26–50 of 283
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-18816 | MEDIUM | 5.0 | 2026-08-04 | A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of… | |
| CVE-2026-18814 | HIGH | 7.2 | 2026-08-04 | A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The att… | |
| CVE-2026-70588 | MEDIUM | Patched | 5.0 | 2026-08-04 | Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting i… |
| CVE-2026-70554 | CRITICAL | 9.8 | 2026-08-04 | MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in … | |
| CVE-2026-70494 | HIGH | Patched | 8.1 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webu… |
| CVE-2026-70493 | MEDIUM | Patched | 6.5 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tool… |
| CVE-2026-70492 | HIGH | Patched | 8.7 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svel… |
| CVE-2026-70491 | MEDIUM | Patched | 6.5 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1… |
| CVE-2026-70490 | MEDIUM | Patched | 6.3 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/te… |
| CVE-2026-70489 | MEDIUM | Patched | 6.5 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/aut… |
| CVE-2026-70488 | MEDIUM | Patched | 4.3 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the know… |
| CVE-2026-70487 | MEDIUM | Patched | 5.3 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowled… |
| CVE-2026-67979 | CRITICAL | 9.1 | 2026-08-04 | Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows attackers to execute arbitrary code via placing a shar… | |
| CVE-2026-66902 | CRITICAL | Patched | 9.8 | 2026-08-04 | Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated system call. The Pluggable subclass reads credential_… |
| CVE-2026-66901 | HIGH | Patched | 7.5 | 2026-08-04 | Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the… |
| CVE-2026-65986 | NONE | Patched | — | 2026-08-04 | CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 contain a XSS vulnerability that can be accessed throu… |
| CVE-2026-54020 | MEDIUM | Patched | 6.3 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected pri… |
| CVE-2026-51401 | HIGH | 7.7 | 2026-08-04 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c | |
| CVE-2026-51400 | HIGH | 8.4 | 2026-08-04 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c | |
| CVE-2026-45538 | CRITICAL | 9.8 | 2026-08-04 | OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP message with a header name longer than 255 bytes causes… | |
| CVE-2026-18813 | HIGH | 7.2 | 2026-08-04 | A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads to com… | |
| CVE-2026-18812 | HIGH | 7.2 | 2026-08-04 | A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can … | |
| CVE-2026-18811 | HIGH | 7.2 | 2026-08-04 | A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the argument esps.filter.url… | |
| CVE-2026-13227 | NONE | Patched | — | 2026-08-04 | An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access control in the whitelisted API method erpnext.crm.doct… |
| CVE-2026-70553 | CRITICAL | 9.8 | 2026-08-04 | MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by sub… |