Search
97 CVEs · published 2026-08-04 to 2026-08-04, Medium severity
CVEs (97)
Showing 1–25 of 97
| CVE ID | Severity | Patch | CVSS | Published ↓ | Description |
|---|---|---|---|---|---|
| CVE-2026-18819 | MEDIUM | 4.3 | 2026-08-04 | A security vulnerability has been detected in RackTables up to 0.22.0/e5fff9f8aab339798ed47e8c6d7d977ed97a82bd. This vulnerability affects unknown code. The manipulation le… | |
| CVE-2026-18818 | MEDIUM | 6.3 | 2026-08-04 | A weakness has been identified in Ehco1996 django-sspanel up to 2023.12.26. This affects the function TicketDetailView of the file apps/sspanel/views.py of the component Su… | |
| CVE-2026-70620 | MEDIUM | 6.8 | 2026-08-04 | Odysseus before commit 87babb5 contains a server-side request forgery vulnerability that allows admin-privileged attackers to direct the server to probe internal network re… | |
| CVE-2026-70594 | MEDIUM | Patched | 6.7 | 2026-08-04 | Ghost is a Node.js content management system. From 2.2.0 until 6.54.1, Ghost Admin did not invalidate existing sessions on login which could have allowed for session fixati… |
| CVE-2026-70593 | MEDIUM | Patched | 6.6 | 2026-08-04 | Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a vulnerability in custom themes allowed a staff user to write files outside of the uploads director… |
| CVE-2026-70592 | MEDIUM | Patched | 5.5 | 2026-08-04 | Ghost is a Node.js content management system. From 1.20.1 until 6.54.1, an Administrator-level user could remotely overwrite certain files on the filesystem through the dat… |
| CVE-2026-70591 | MEDIUM | Patched | 4.1 | 2026-08-04 | Ghost is a Node.js content management system. From 0.10.0 until 6.54.1, a Server-Side Request Forgery in Ghost Admin image fetching allowed any staff-level user to perform … |
| CVE-2026-70590 | MEDIUM | Patched | 4.8 | 2026-08-04 | Ghost is a Node.js content management system. Prior to 6.54.1, any staff-level user was able to leak the hashed passwords of other staff users through the Ghost Admin API. … |
| CVE-2026-70589 | MEDIUM | Patched | 4.8 | 2026-08-04 | Ghost is a Node.js content management system. From 4.22.0 until 6.54.1, a missing validation check allowed users to redeem subscription offers that were no longer active. T… |
| CVE-2026-52370 | MEDIUM | 6.1 | 2026-08-04 | A reflected cross-site scripting (XSS) vulnerability in the Forum posting function of O2OA v10 allows attackers to execute arbitrary Javascript in the context of the victim… | |
| CVE-2026-51144 | MEDIUM | 6.1 | 2026-08-04 | Cross Site Scripting vulnerability in Soliton Systems MailZen Management Protal v.2.62, v.2.63 allows a remote attacker to execute arbitrary code via the Role Name, First N… | |
| CVE-2026-18816 | MEDIUM | 5.0 | 2026-08-04 | A vulnerability was identified in Baserow up to 2.3.2. Affected by this vulnerability is the function verify of the file backend/src/baserow/api/two_factor_auth/views.py of… | |
| CVE-2026-70588 | MEDIUM | Patched | 5.0 | 2026-08-04 | Ghost is a Node.js content management system. From 5.26.0 until 6.54.1, the Universal Import feature in Ghost Admin failed to properly sanitize imported content resulting i… |
| CVE-2026-70493 | MEDIUM | Patched | 6.5 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built-in knowledge search path in backend/open_webui/tool… |
| CVE-2026-70491 | MEDIUM | Patched | 6.5 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /api/v1/tools/, GET /api/v1/tools/list, and GET /api/v1… |
| CVE-2026-70490 | MEDIUM | Patched | 6.3 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the terminal WebSocket route in backend/open_webui/routers/te… |
| CVE-2026-70489 | MEDIUM | Patched | 6.5 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automation recurrence parsing in backend/open_webui/utils/aut… |
| CVE-2026-70488 | MEDIUM | Patched | 4.3 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync cleanup endpoint authorized write access to the know… |
| CVE-2026-70487 | MEDIUM | Patched | 5.3 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline direct model metadata accepted client-supplied knowled… |
| CVE-2026-54020 | MEDIUM | Patched | 6.3 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolved a hostname during URL validation and rejected pri… |
| CVE-2026-70484 | MEDIUM | Patched | 4.3 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legacy chat-completions features block trusted a client-s… |
| CVE-2026-70481 | MEDIUM | Patched | 5.4 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the standard channel message update and delete handlers accep… |
| CVE-2026-70480 | MEDIUM | Patched | 4.1 | 2026-08-04 | Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open WebUI renders vega and vega-lite fenced code blocks in … |
| CVE-2026-48154 | MEDIUM | Patched | 5.9 | 2026-08-04 | GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions prior to 1.12.2 nMemorySecret2FA contains a race condit… |
| CVE-2026-16792 | MEDIUM | 6.1 | 2026-08-04 | An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 microservices that could allow an adjacent network attac… |