Search

Published: All 7d 30d 90d 12m
Clear
Severity: All Critical High Medium Low

90 CVEs · published 2026-08-04 to 2026-08-04, High severity

CVEs (90)

Showing 1–25 of 90

CVE ID Severity Patch CVSS Published Description
CVE-2026-70619 HIGH 8.8 2026-08-04 Odysseus before commit bf325f6 contains a missing authorization vulnerability that allows authenticated non-admin users to manage server-wide embedding backend configuratio…
CVE-2026-67862 HIGH 7.5 2026-08-04 open62541 1.5.5 contains a buffer-overflow in the high-level attribute reading logic in src/client/ua_client_highlevel.c. This allows a remote attacker to cause a denial of…
CVE-2026-67861 HIGH 7.5 2026-08-04 An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via the UA_Client_getRemoteDataTypes component
CVE-2026-67860 HIGH 7.5 2026-08-04 open62541 1.5.5 contains a heap-based buffer overflow in the default HistoryRead path when the default history database is used with the memory backend.
CVE-2026-67859 HIGH 7.5 2026-08-04 Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote attacker to cause a denial of service via the Discovery/LDS handling.
CVE-2026-67858 HIGH 7.5 2026-08-04 Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local Discovery Server (LDS) is built with multicast discovery enabled through the MDNSD backend. An unauth…
CVE-2026-67857 HIGH 7.5 2026-08-04 open62541 1.5.5 contains an out-of-bounds read in the client-side function responseReadNamespacesArray() in src/client/ua_client_connect.c.
CVE-2026-67856 HIGH 7.5 2026-08-04 An issue in open62541 v.1.5.5 and before allows a remote attacker to cause a denial of service via crafted CreateSubscription, CreateMonitoredItems(Sampling), Publish, Tran…
CVE-2026-67855 HIGH 7.5 2026-08-04 open62541 contains a heap use-after-free in the GDS PushManagement certificate update workflow when UA_ENABLE_GDS_PUSHMANAGEMENT is enabled. This allows a remote attacker t…
CVE-2026-45103 HIGH Patched 7.5 2026-08-04 OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions prior to 3.6.6 and 4.0.0-rc1, the TCP message framing layer parses the Content-Length hea…
CVE-2026-18814 HIGH 7.2 2026-08-04 A vulnerability was found in H3C NX15 V100R017. This impacts the function reload.reload_config of the file /api/esps. The manipulation results in command injection. The att…
CVE-2026-70494 HIGH Patched 8.1 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELETE /api/v1/folders/{id} handler in backend/open_webu…
CVE-2026-70492 HIGH Patched 8.7 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/components/chat/Messages/Markdown/KatexRenderer.svel…
CVE-2026-66901 HIGH Patched 7.5 2026-08-04 Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated URLs taken from the credentials JSON. The URLs the…
CVE-2026-51401 HIGH 7.7 2026-08-04 An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c
CVE-2026-51400 HIGH 8.4 2026-08-04 An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c
CVE-2026-18813 HIGH 7.2 2026-08-04 A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipulation of the argument esps.apcm.version leads to com…
CVE-2026-18812 HIGH 7.2 2026-08-04 A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Executing a manipulation of the argument workMode can …
CVE-2026-18811 HIGH 7.2 2026-08-04 A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Performing a manipulation of the argument esps.filter.url…
CVE-2026-70486 HIGH Patched 8.2 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the terminal file-preview serveUrl iframe branch always grant…
CVE-2026-70485 HIGH Patched 7.1 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebUI checked whether a user-supplied URL destination wa…
CVE-2026-70482 HIGH Patched 8.1 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENABLE_OAUTH_TOKEN_EXCHANGE=True, /oauth/{provider}/toke…
CVE-2026-70479 HIGH Patched 7.7 2026-08-04 Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_LOADER_ENGINE=playwright, the Playwright web loader …
CVE-2026-18810 HIGH 7.3 2026-08-04 A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard/networkSetup. Such manipulation leads to missing au…
CVE-2026-18657 HIGH Patched 7.8 2026-08-04 An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated actor to execute arbitrary code via a maliciously craf…