|
1531
|
5.3 |
MEDIUM
Network
|
ni
|
instrumentstudio ni_grpc_device_server
|
There is an incorrect conversion between numeric types vulnerability in NI grpc-device due to missing range checks in CodeGen. This may silently discard high bits if a size value exceeded the target…
|
CWE-681
Incorrect Conversion between Numeric Types
|
CVE-2026-9143
|
2026-06-25 23:39 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1532
|
4.3 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, a path traversal vulnerability exists in open-webui's cache file serving endpoint th…
|
CWE-22
Path Traversal
|
CVE-2026-54014
|
2026-06-25 23:36 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1533
|
6.4 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI's prompt version-history endpoints authorize the prompt_id in the URL but…
|
CWE-284 CWE-639
Improper Access Control Authorization Bypass Through User-Controlled Key
|
CVE-2026-54015
|
2026-06-25 23:35 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1534
|
4.3 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI has a Broken Object Level Authorization (BOLA) vulnerability in the built…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-54016
|
2026-06-25 23:31 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1535
|
7.7 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the SafePlaywrightURLLoader implements a validate_url function to prevent SSRF attac…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-54018
|
2026-06-25 23:30 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1536
|
7.8 |
HIGH
Local
|
-
|
-
|
Warp is an agentic development environment. From 0.2025.04.09.08.11.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command execution policy bypass in Agent code search tools. The affec…
|
CWE-78
OS Command
|
CVE-2026-48703
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1537
|
8.8 |
HIGH
Network
|
-
|
-
|
Warp is an agentic development environment. From 0.2023.10.24.08.03.stable_00 until 0.2026.05.06.15.42.stable_01, Warp may open executable local files through the operating system default file handle…
|
CWE-20
Improper Input Validation
|
CVE-2026-48704
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1538
|
8.0 |
HIGH
Network
|
-
|
-
|
Warp is an agentic development environment. From 0.2025.08.06.08.12.stable_00 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection in the prompt branch selector. A user who can publi…
|
CWE-78
OS Command
|
CVE-2026-48719
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1539
|
8.1 |
HIGH
Network
|
-
|
-
|
Warp is an agentic development environment. From 0.2021.04.25.23.05.stable_00 until 0.2026.05.06.15.42.stable_01, Warp allows terminal output to request access to the local system clipboard. A malici…
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-48725
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1540
|
7.8 |
HIGH
Local
|
-
|
-
|
Warp is an agentic development environment. From 0.2024.02.20.08.01.stable_01 until 0.2026.05.06.15.42.stable_01, Warp contains a command injection issue in the Linux external editor launcher. Warp e…
|
CWE-78
OS Command
|
CVE-2026-48731
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|