|
7051
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary …
|
CWE-94
Code Injection
|
CVE-2026-8838
|
2026-05-19 23:24 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7052
|
7.3 |
HIGH
Network
|
-
|
-
|
Net::Statsd::Lite versions through 0.10.0 for Perl allowed metric injections.
The values from the set_add method were not checked for newlines, colons or pipes. Metrics generated from untrusted sour…
|
CWE-93
CRLF Injection
|
CVE-2026-8788
|
2026-05-19 23:16 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7053
|
9.8 |
CRITICAL
Network
|
radare
|
radare2
|
radare2 6.1.5 contains a use-after-free vulnerability in the gdbr_pids_list() function within the GDB client core that allows remote attackers to cause a denial of service or potentially execute arbi…
|
CWE-416
Use After Free
|
CVE-2026-8696
|
2026-05-19 23:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7054
|
- |
-
|
-
|
-
|
Rejected reason: Voluntarily withdrawn
|
-
|
CVE-2026-6354
|
2026-05-19 23:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7055
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Net::Statsd::Lite versions before 0.9.0 for Perl allowed metric injections.
The metric names were not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inject add…
|
CWE-93
CRLF Injection
|
CVE-2026-46719
|
2026-05-19 23:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7056
|
- |
-
|
-
|
-
|
A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicio…
|
CWE-94
Code Injection
|
CVE-2026-45829
|
2026-05-19 23:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7057
|
8.1 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, he LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) patt…
|
CWE-269 CWE-362
Improper Privilege Management Race Condition
|
CVE-2026-45675
|
2026-05-19 23:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7058
|
4.3 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, Pin/Unpin is a write operation (modifies the message's is_pinned , pinned_by, pinned…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45386
|
2026-05-19 23:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7059
|
5.4 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, an internal-only bypass_filter parameter is exposed on the /openai/chat/completions…
|
CWE-285
Improper Authorization
|
CVE-2026-45365
|
2026-05-19 23:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7060
|
7.1 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a user just needs to use the API endpoint: /api/chat/completions with their own API …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45349
|
2026-05-19 23:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7061
|
7.7 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.5, through the HTML rendering view, scripts can be injected and executed. The frontend …
|
CWE-79
Cross-site Scripting
|
CVE-2026-45303
|
2026-05-19 23:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7062
|
7.3 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a stored cross-site scripting (XSS) vulnerability that allows any authenticated user…
|
CWE-79
Cross-site Scripting
|
CVE-2026-44721
|
2026-05-19 23:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7063
|
7.3 |
HIGH
Network
|
-
|
-
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.1.124, when attaching files to a promp, the name of the file is derived from the original…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2026-44566
|
2026-05-19 23:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7064
|
5.4 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the channel router does not call filter_allowed_access_grants on either create or up…
|
CWE-862
Missing Authorization
|
CVE-2026-44558
|
2026-05-19 23:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7065
|
8.1 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, administrative role changes and user deletions do not iterate SESSION_POOL to discon…
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-44553
|
2026-05-19 23:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7066
|
5.3 |
MEDIUM
Network
|
-
|
-
|
An issue in Intelbras VIP-1230-D-G4 Version V2.800.00IB00C.0.T allows a remote attacker to obtain sensitive information via password reset functionality under /OutsideCmd
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2026-36438
|
2026-05-19 23:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7067
|
9.1 |
CRITICAL
Network
|
freertos
|
coremqtt
|
Missing bounds validation in the MQTT v5.0 property parser in coreMQTT before 5.0.1 allows an MQTT broker to cause a denial of service by sending a crafted packet.
To remediate this issue, users s…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-8686
|
2026-05-19 23:01 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7068
|
9.8 |
CRITICAL
Network
|
lmsys
|
sglang
|
SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the intern…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-7301
|
2026-05-19 22:49 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7069
|
9.1 |
CRITICAL
Network
|
lmsys
|
sglang
|
SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by …
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2026-7302
|
2026-05-19 22:43 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7070
|
9.8 |
CRITICAL
Network
|
lmsys
|
sglang
|
SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-7304
|
2026-05-19 22:38 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7071
|
7.0 |
HIGH
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in
runtime/autoload/tar.vim when decompressing .tgz archives on Unix-lik…
|
CWE-78 CWE-88
OS Command Argument Injection
|
CVE-2026-46483
|
2026-05-19 21:27 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7072
|
5.8 |
MEDIUM
Network
|
traefik
|
traefik
|
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.44, 3.6.15, and 3.7.0-rc.3, there is an information disclosure vulnerability in Traefik's errors (custom error pages) middleware. Whe…
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-41181
|
2026-05-19 21:24 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7073
|
9.9 |
CRITICAL
Network
|
traefik
|
traefik
|
Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.46, 3.6.17, and 3.7.1, Traefik's Kubernetes Gateway API provider allows a tenant with HTTPRoute creation permissions to expose the RE…
|
CWE-284
Improper Access Control
|
CVE-2026-44774
|
2026-05-19 21:22 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7074
|
5.4 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the POST /api/v1/evaluations/feedback endpoint in Open WebUI v0.9.2 is vulnerable to…
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-45396
|
2026-05-19 21:20 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7075
|
5.3 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, GET /api/v1/retrieval/ returns live RAG pipeline configuration to any unauthenticate…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-45397
|
2026-05-19 21:19 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7076
|
7.5 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, _validate_collection_access() checks the user-memory-* and file-* collection name pr…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45398
|
2026-05-19 21:18 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7077
|
8.5 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, a parsing difference between the urlparse and requests libraries led to an SSRF bypa…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45400
|
2026-05-19 21:08 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7078
|
8.5 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the validate_url() function in backend/open_webui/retrieval/web/utils.py only valida…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45401
|
2026-05-19 21:07 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7079
|
8.8 |
HIGH
Network
|
huggingface
|
diffusers
|
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hu…
|
CWE-94
Code Injection
|
CVE-2026-44827
|
2026-05-19 12:20 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7080
|
8.8 |
HIGH
Network
|
huggingface
|
diffusers
|
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user p…
|
CWE-94
Code Injection
|
CVE-2026-44513
|
2026-05-19 12:18 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7081
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Downloads in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page…
|
CWE-416
Use After Free
|
CVE-2026-8551
|
2026-05-19 12:15 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7082
|
4.3 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the _validate_collection_access function uses an incomplete allowlist that only enfo…
|
CWE-863
Incorrect Authorization
|
CVE-2026-44557
|
2026-05-19 12:13 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7083
|
7.1 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /responses endpoint in the OpenAI router accepts any authenticated user and forw…
|
CWE-284 CWE-862
Improper Access Control Missing Authorization
|
CVE-2026-44556
|
2026-05-19 12:12 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7084
|
7.6 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI supports model composition via base_model_id: a user-defined model (e.g.,…
|
CWE-862
Missing Authorization
|
CVE-2026-44555
|
2026-05-19 12:12 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7085
|
8.1 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/retrieval/process/web endpoint accepts a user-supplied collection_n…
|
CWE-862
Missing Authorization
|
CVE-2026-44554
|
2026-05-19 12:12 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7086
|
5.0 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, FolderForm uses model_config = ConfigDict(extra='allow'), which permits arbitrary fi…
|
CWE-862
Missing Authorization
|
CVE-2026-44550
|
2026-05-19 12:12 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7087
|
5.4 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the ydoc:document:update Socket.IO event handler checks whether the sender is a memb…
|
CWE-863
Incorrect Authorization
|
CVE-2026-44564
|
2026-05-19 12:11 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7088
|
5.4 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /api/generate, /api/embed, /api/embeddings, and /api/show endpoints accept any m…
|
CWE-862
Missing Authorization
|
CVE-2026-44563
|
2026-05-19 12:11 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7089
|
6.5 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import endpoint allows users with the workspace.models_impor…
|
CWE-283 CWE-862
Unverified Ownership Missing Authorization
|
CVE-2026-44562
|
2026-05-19 12:10 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7090
|
5.4 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the is_user_channel_member function checks whether a ChannelMember row exists but do…
|
CWE-863
Incorrect Authorization
|
CVE-2026-44561
|
2026-05-19 12:10 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7091
|
6.5 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the type: "file" (non-full-context), type: "text" with collection_name, and bare col…
|
CWE-862
Missing Authorization
|
CVE-2026-44560
|
2026-05-19 12:09 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7092
|
4.3 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the GET /api/v1/channels/{id}/members endpoint only checks membership for group and …
|
CWE-862
Missing Authorization
|
CVE-2026-44559
|
2026-05-19 12:09 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7093
|
8.0 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user can permanently delete files owned by other users via DELETE …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45671
|
2026-05-19 12:08 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7094
|
7.1 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user with low privileges can enumerate active background tasks acr…
|
CWE-862
Missing Authorization
|
CVE-2026-45399
|
2026-05-19 12:08 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7095
|
6.5 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI allows admins to restrict which API endpoints an API key can access. When…
|
CWE-863
Incorrect Authorization
|
CVE-2026-45339
|
2026-05-19 12:07 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7096
|
8.5 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, validate_url() in backend/open_webui/retrieval/web/utils.py calls validators.ipv6(ip…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45331
|
2026-05-19 12:06 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7097
|
4.8 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the AccountPending.svelte component renders the admin-configured "Pending User Overl…
|
CWE-79
Cross-site Scripting
|
CVE-2026-44568
|
2026-05-19 12:06 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7098
|
4.3 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, when setting model permissions so that a group has read access to it, intending for …
|
CWE-200
Information Exposure
|
CVE-2026-45387
|
2026-05-19 12:05 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7099
|
7.2 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the tool update endpoint (POST /api/v1/tools/id/{id}/update) is missing the workspac…
|
CWE-269 CWE-862
Improper Privilege Management Missing Authorization
|
CVE-2026-45395
|
2026-05-19 12:05 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7100
|
4.3 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, an IDOR vulnerability exists in the Channels feature of Open WebUI, allowing any cha…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45385
|
2026-05-19 10:45 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|