Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

283 CVEs · published 2026-08-04 to 2026-08-04

CVEs (283)

Showing 51–75 of 283

CVE ID Severity Patch CVSS Published Description
CVE-2026-70552 CRITICAL 9.8 2026-08-04 MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints b…
CVE-2026-70486 HIGH Patched 8.2 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always grant…
CVE-2026-70485 HIGH Patched 7.1 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination wa…
CVE-2026-70484 MEDIUM Patched 4.3 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-s…
CVE-2026-70483 LOW Patched 3.1 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks …
CVE-2026-70482 HIGH Patched 8.1 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/toke…
CVE-2026-70481 MEDIUM Patched 5.4 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accep…
CVE-2026-70480 MEDIUM Patched 4.1 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in …
CVE-2026-70479 HIGH Patched 7.7 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader …
CVE-2026-70478 NONE Patched — 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v1/oauth2-credential/refresh/:credentialId endpoint i…
CVE-2026-70477 NONE Patched — 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt injection sent to a chatflow using a CSV Agent node can ca…
CVE-2026-70476 NONE Patched — 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organization billing endpoints in packages/server/src/enter…
CVE-2026-70475 NONE Patched — 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1/executions/:id endpoint in packages/server/src/rout…
CVE-2026-48154 MEDIUM Patched 5.9 2026-08-04 GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condit…
CVE-2026-47682 NONE Patched — 2026-08-04 CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0, an attacker with write access to a cloud storage t…
CVE-2026-18810 HIGH 7.3 2026-08-04 A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing au…
CVE-2026-18657 HIGH Patched 7.8 2026-08-04 An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously craf…
CVE-2026-18656 HIGH Patched 7.8 2026-08-04 An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously cra…
CVE-2026-16793 HIGH 8.8 2026-08-04 An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo XClarity Orchestrator (LXCO) 2.2.0 that could allow …
CVE-2026-16792 MEDIUM 6.1 2026-08-04 An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attac…
CVE-2026-16791 LOW 3.9 2026-08-04 A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could allow a local low-privileged attacker to overwrite o…
CVE-2026-70474 NONE Patched — 2026-08-04 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise has three OAuth2 credential endpoints that look …
CVE-2026-70473 NONE Patched — 2026-08-04 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise GET /api/v1/upsert-history returns the entire se…
CVE-2026-70472 NONE Patched — 2026-08-04 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-assistants-vector-store endpoints accept a client-co…
CVE-2026-70471 NONE Patched — 2026-08-04 Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flowise injects $vars into the code execution sandbox wi…