Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

283 CVEs · published 2026-08-04 to 2026-08-04

CVEs (283)

Showing 1–25 of 283

CVE ID Severity Patch CVSS Published Description
CVE-2026-8508 MEDIUM 6.5 2026-08-04 An improper authentication vulnerability in the "social_login.cgi" CGI program in Zyxel WAX650S firmware versions through 7.10(ABRM.4)C0 could allow an attacker on the WLAN…
CVE-2026-70620 MEDIUM 6.8 2026-08-04 Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network re…
CVE-2026-70619 HIGH 8.8 2026-08-04 Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuratio…
CVE-2026-70594 MEDIUM Patched 6.7 2026-08-04 Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixati…
CVE-2026-70593 MEDIUM Patched 6.6 2026-08-04 Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads director…
CVE-2026-70592 MEDIUM Patched 5.5 2026-08-04 Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the dat…
CVE-2026-70591 MEDIUM Patched 4.1 2026-08-04 Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform …
CVE-2026-70590 MEDIUM Patched 4.8 2026-08-04 Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. …
CVE-2026-70589 MEDIUM Patched 4.8 2026-08-04 Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. T…
CVE-2026-70588 MEDIUM Patched 5.0 2026-08-04 Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting i…
CVE-2026-70554 CRITICAL 9.8 2026-08-04 MaxSite CMS contains a PHP object injection vulnerability that allows unauthenticated attackers to execute arbitrary code by passing attacker-controlled serialized data in …
CVE-2026-70553 CRITICAL 9.8 2026-08-04 MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by sub…
CVE-2026-70552 CRITICAL 9.8 2026-08-04 MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthenticated attackers to access admin-gated endpoints b…
CVE-2026-70494 HIGH Patched 8.1 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webu…
CVE-2026-70493 MEDIUM Patched 6.5 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tool…
CVE-2026-70492 HIGH Patched 8.7 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svel…
CVE-2026-70491 MEDIUM Patched 6.5 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1…
CVE-2026-70490 MEDIUM Patched 6.3 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/te…
CVE-2026-70489 MEDIUM Patched 6.5 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/aut…
CVE-2026-70488 MEDIUM Patched 4.3 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the know…
CVE-2026-70487 MEDIUM Patched 5.3 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowled…
CVE-2026-70486 HIGH Patched 8.2 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always grant…
CVE-2026-70485 HIGH Patched 7.1 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination wa…
CVE-2026-70484 MEDIUM Patched 4.3 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-s…
CVE-2026-70483 LOW Patched 3.1 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /api/v1/chats/{id} cancelled a chat's in-flight tasks …