Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| MINI-wq6w-wj7h-36pq |
|
MINI-wq6w-wj7h-36pq |
| UBUNTU-CVE-2026-49268 |
|
Vulnerability in shiro (UBUNTU-CVE-2026-49268)
vulnerability in shiro (UBUNTU-CVE-2026-49268). Confidential information can be exposed externally.
|
| CVE-2026-54015 |
|
Vulnerability in open-webui (CVE-2026-54015)
vulnerability in open-webui (CVE-2026-54015). Confidential information can be exposed externally. Exploitable via `GET /api/v1/prompts/id/{prompt_id}/history/diff`. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-54014 |
|
Path Traversal in open-webui (CVE-2026-54014)
path traversal in open-webui (CVE-2026-54014). Risk of unauthorized operations or information disclosure. Exploitable via `GET /cache/{{path}}`. Mitigation: upgrade to `0.9.6` or later.
|
| MINI-j8w6-3fp3-jr35 |
|
MINI-j8w6-3fp3-jr35 |
| CVE-2026-54013 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-54013)
cross-site scripting in open-webui (CVE-2026-54013). Confidential information can be exposed externally. Exploitable via `GET /api/v1/models/model/profile/image`. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-54012 |
|
Vulnerability in open-webui (CVE-2026-54012)
vulnerability in open-webui (CVE-2026-54012). Confidential information can be exposed externally. Exploitable via `GET /api/v1/files/{id}/content`. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-54011 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-54011)
cross-site scripting in open-webui (CVE-2026-54011). Confidential information can be exposed externally. Exploitable via ``innerHTML``. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-54010 |
|
Vulnerability in open-webui (CVE-2026-54010)
vulnerability in open-webui (CVE-2026-54010). Confidential information can be exposed externally. Exploitable via `GET /api/v1/files/{id}/content`. Mitigation: upgrade to `>= 0.9.6` or later.
|
| CVE-2026-54009 |
|
Vulnerability in open-webui (CVE-2026-54009)
vulnerability in open-webui (CVE-2026-54009). Confidential information can be exposed externally. Exploitable via `POST /api/chat/completions`. Mitigation: upgrade to `0.9.6` or later.
|
| CVE-2026-54008 |
|
SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-54008)
SSRF in open-webui (CVE-2026-54008). Confidential information can be exposed externally. Exploitable via `GET /api/v1/auths/`. Mitigation: upgrade to `0.9.0` or later.
|
| MINI-qwx5-g7cg-446v |
|
MINI-qwx5-g7cg-446v |
| CVE-2026-54007 |
|
Vulnerability in open-webui (CVE-2026-54007)
vulnerability in open-webui (CVE-2026-54007). Data can be tampered with by attackers. Exploitable via `POST /api/v1/chats/new`. Mitigation: upgrade to `0.9.6` or later.
|
| MINI-773g-5mgw-4hch |
|
MINI-773g-5mgw-4hch |
| CVE-2026-54006 |
|
Vulnerability in open-webui (CVE-2026-54006)
vulnerability in open-webui (CVE-2026-54006). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/calendars/events/{event_id}/update`. Mitigation: upgrade to `0.9.6` or later.
|
| MINI-c8j7-c5hw-c3jf |
|
MINI-c8j7-c5hw-c3jf |
| MINI-6wwc-2j74-987w |
|
MINI-6wwc-2j74-987w |
| MINI-qwrc-cv87-qwpg |
|
MINI-qwrc-cv87-qwpg |
| CVE-2026-53931 |
|
Vulnerability in nocodb (CVE-2026-53931)
vulnerability in nocodb (CVE-2026-53931). Risk of unauthorized operations or information disclosure. Exploitable via ``axiosRequestMake``.
|
| MINI-9hrr-r285-fpj6 |
|
MINI-9hrr-r285-fpj6 |
| MINI-2j59-3p2v-p3jx |
|
MINI-2j59-3p2v-p3jx |
| MINI-w5vp-7cxm-5qfj |
|
MINI-w5vp-7cxm-5qfj |
| MINI-w2v5-qm7x-592x |
|
MINI-w2v5-qm7x-592x |
| MINI-3cvq-rfvw-mjgh |
|
MINI-3cvq-rfvw-mjgh |
| CVE-2026-53930 |
|
SSRF (Server-Side Request Forgery) in nocodb (CVE-2026-53930)
SSRF in nocodb (CVE-2026-53930). Risk of unauthorized operations or information disclosure. Exploitable via ``migrate``.
|
| MINI-gwfp-5qrp-wm6m |
|
MINI-gwfp-5qrp-wm6m |
| CVE-2026-53929 |
|
Cross-Site Scripting (XSS) in nocodb (CVE-2026-53929)
cross-site scripting in nocodb (CVE-2026-53929). Risk of unauthorized operations or information disclosure. Exploitable via ``ResponseContentDisposition``.
|
| CVE-2026-53928 |
|
Vulnerability in nocodb (CVE-2026-53928)
vulnerability in nocodb (CVE-2026-53928). Risk of unauthorized operations or information disclosure. Exploitable via ``passwordChange``.
|
| MINI-c227-m969-wrch |
|
MINI-c227-m969-wrch |
| ROOT-APP-MAVEN-CVE-2019-0231 |
|
Vulnerability in io.root.org.apache.mina:mina-core (ROOT-APP-MAVEN-CVE-2019-0231)
vulnerability in io.root.org.apache.mina:mina-core (ROOT-APP-MAVEN-CVE-2019-0231). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.0-RC1-root.io.2, 2.0.0-RC1-root.io.3` or later.
|
| MINI-qrq6-pm8c-vmxq |
|
MINI-qrq6-pm8c-vmxq |
| CVE-2026-53927 |
|
SSRF (Server-Side Request Forgery) in nocodb (CVE-2026-53927)
SSRF in nocodb (CVE-2026-53927). Risk of unauthorized operations or information disclosure. Exploitable via ``axiosRequestMake``.
|
| MINI-wvf9-w23q-5pvc |
|
MINI-wvf9-w23q-5pvc |
| MINI-2ffq-pqq7-45cm |
|
MINI-2ffq-pqq7-45cm |
| CVE-2026-54233 |
|
Vulnerability in vllm (CVE-2026-54233)
vulnerability in vllm (CVE-2026-54233). Risk of unauthorized operations or information disclosure. Exploitable via ``SpeechToTextProcessor``. Mitigation: upgrade to `0.24.0` or later.
|
| MINI-8jpj-8c3p-9p4x |
|
MINI-8jpj-8c3p-9p4x |
| CVE-2026-54236 |
|
Vulnerability in vllm (CVE-2026-54236)
vulnerability in vllm (CVE-2026-54236). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/messages`. Mitigation: upgrade to `0.24.0` or later.
|
| CVE-2026-53923 |
|
Information Disclosure in vllm (CVE-2026-53923)
vulnerability in vllm (CVE-2026-53923). Confidential information can be exposed externally. Exploitable via ``to_cuda_ggml_t``. Mitigation: upgrade to `0.24.0` or later.
|
| GHSA-8jr5-v98p-w75m |
|
Vulnerability in vllm (GHSA-8jr5-v98p-w75m)
vulnerability in vllm (GHSA-8jr5-v98p-w75m). Risk of unauthorized operations or information disclosure. Exploitable via ``ImageOps.exif_transpose``.
|
| CVE-2026-54235 |
|
Vulnerability in vllm (CVE-2026-54235)
vulnerability in vllm (CVE-2026-54235). Risk of unauthorized operations or information disclosure. Exploitable via ``False``. Mitigation: upgrade to `0.24.0` or later.
|
| CVE-2026-54761 |
|
Vulnerability in github.com/traefik/traefik/v3 (CVE-2026-54761)
vulnerability in github.com/traefik/traefik/v3 (CVE-2026-54761). Confidential information can be exposed externally. Mitigation: upgrade to `3.6.21, 3.7.5` or later.
|
| CVE-2026-53765 |
|
Vulnerability in chrome-devtools-mcp (CVE-2026-53765)
vulnerability in chrome-devtools-mcp (CVE-2026-53765). Data can be tampered with by attackers. Exploitable via ``O_NOFOLLOW``. Mitigation: upgrade to `1.1.0` or later.
|
| GHSA-664h-gpgq-h6xx |
|
Authorization Flaw in n8n (GHSA-664h-gpgq-h6xx)
vulnerability in n8n (GHSA-664h-gpgq-h6xx). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.25.7` or later.
|
| CVE-2026-54325 |
|
Vulnerability in @earendil-works/pi-coding-agent (CVE-2026-54325)
vulnerability in @earendil-works/pi-coding-agent (CVE-2026-54325). Risk of unauthorized operations or information disclosure. Exploitable via ``project_trust``. Mitigation: upgrade to `0.79.0` or later.
|
| CVE-2026-54328 |
|
Vulnerability in @earendil-works/pi-coding-agent (CVE-2026-54328)
vulnerability in @earendil-works/pi-coding-agent (CVE-2026-54328). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `>= 0.78.1` or later.
|
| CGA-2fjg-j4jj-x26w |
|
CGA-2fjg-j4jj-x26w |
| CVE-2026-54327 |
|
Vulnerability in @mariozechner/pi-coding-agent (CVE-2026-54327)
vulnerability in @mariozechner/pi-coding-agent (CVE-2026-54327). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.78.1` or later.
|
| GHSA-crmm-hgp2-wgrp |
|
Vulnerability in laravel/framework (GHSA-crmm-hgp2-wgrp)
vulnerability in laravel/framework (GHSA-crmm-hgp2-wgrp). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.61.1` or later.
|
| GHSA-5vg9-5847-vvmq |
|
Vulnerability in laravel/framework (GHSA-5vg9-5847-vvmq)
vulnerability in laravel/framework (GHSA-5vg9-5847-vvmq). Confidential information can be exposed externally. Mitigation: upgrade to `12.60.0` or later.
|
| USN-8447-1 |
|
Vulnerability in golang-go.crypto (USN-8447-1)
vulnerability in golang-go.crypto (USN-8447-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:0.0~git20151201.0.7b85b09-2ubuntu0.1~esm2` or later.
|