Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
MINI-wq6w-wj7h-36pq MINI-wq6w-wj7h-36pq
UBUNTU-CVE-2026-49268 Vulnerability in shiro (UBUNTU-CVE-2026-49268)
vulnerability in shiro (UBUNTU-CVE-2026-49268). Confidential information can be exposed externally.
CVE-2026-54015 Vulnerability in open-webui (CVE-2026-54015)
vulnerability in open-webui (CVE-2026-54015). Confidential information can be exposed externally. Exploitable via `GET /api/v1/prompts/id/{prompt_id}/history/diff`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54014 Path Traversal in open-webui (CVE-2026-54014)
path traversal in open-webui (CVE-2026-54014). Risk of unauthorized operations or information disclosure. Exploitable via `GET /cache/{{path}}`. Mitigation: upgrade to `0.9.6` or later.
MINI-j8w6-3fp3-jr35 MINI-j8w6-3fp3-jr35
CVE-2026-54013 Cross-Site Scripting (XSS) in open-webui (CVE-2026-54013)
cross-site scripting in open-webui (CVE-2026-54013). Confidential information can be exposed externally. Exploitable via `GET /api/v1/models/model/profile/image`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54012 Vulnerability in open-webui (CVE-2026-54012)
vulnerability in open-webui (CVE-2026-54012). Confidential information can be exposed externally. Exploitable via `GET /api/v1/files/{id}/content`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54011 Cross-Site Scripting (XSS) in open-webui (CVE-2026-54011)
cross-site scripting in open-webui (CVE-2026-54011). Confidential information can be exposed externally. Exploitable via ``innerHTML``. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54010 Vulnerability in open-webui (CVE-2026-54010)
vulnerability in open-webui (CVE-2026-54010). Confidential information can be exposed externally. Exploitable via `GET /api/v1/files/{id}/content`. Mitigation: upgrade to `>= 0.9.6` or later.
CVE-2026-54009 Vulnerability in open-webui (CVE-2026-54009)
vulnerability in open-webui (CVE-2026-54009). Confidential information can be exposed externally. Exploitable via `POST /api/chat/completions`. Mitigation: upgrade to `0.9.6` or later.
CVE-2026-54008 SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-54008)
SSRF in open-webui (CVE-2026-54008). Confidential information can be exposed externally. Exploitable via `GET /api/v1/auths/`. Mitigation: upgrade to `0.9.0` or later.
MINI-qwx5-g7cg-446v MINI-qwx5-g7cg-446v
CVE-2026-54007 Vulnerability in open-webui (CVE-2026-54007)
vulnerability in open-webui (CVE-2026-54007). Data can be tampered with by attackers. Exploitable via `POST /api/v1/chats/new`. Mitigation: upgrade to `0.9.6` or later.
MINI-773g-5mgw-4hch MINI-773g-5mgw-4hch
CVE-2026-54006 Vulnerability in open-webui (CVE-2026-54006)
vulnerability in open-webui (CVE-2026-54006). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/calendars/events/{event_id}/update`. Mitigation: upgrade to `0.9.6` or later.
MINI-c8j7-c5hw-c3jf MINI-c8j7-c5hw-c3jf
MINI-6wwc-2j74-987w MINI-6wwc-2j74-987w
MINI-qwrc-cv87-qwpg MINI-qwrc-cv87-qwpg
CVE-2026-53931 Vulnerability in nocodb (CVE-2026-53931)
vulnerability in nocodb (CVE-2026-53931). Risk of unauthorized operations or information disclosure. Exploitable via ``axiosRequestMake``.
MINI-9hrr-r285-fpj6 MINI-9hrr-r285-fpj6
MINI-2j59-3p2v-p3jx MINI-2j59-3p2v-p3jx
MINI-w5vp-7cxm-5qfj MINI-w5vp-7cxm-5qfj
MINI-w2v5-qm7x-592x MINI-w2v5-qm7x-592x
MINI-3cvq-rfvw-mjgh MINI-3cvq-rfvw-mjgh
CVE-2026-53930 SSRF (Server-Side Request Forgery) in nocodb (CVE-2026-53930)
SSRF in nocodb (CVE-2026-53930). Risk of unauthorized operations or information disclosure. Exploitable via ``migrate``.
MINI-gwfp-5qrp-wm6m MINI-gwfp-5qrp-wm6m
CVE-2026-53929 Cross-Site Scripting (XSS) in nocodb (CVE-2026-53929)
cross-site scripting in nocodb (CVE-2026-53929). Risk of unauthorized operations or information disclosure. Exploitable via ``ResponseContentDisposition``.
CVE-2026-53928 Vulnerability in nocodb (CVE-2026-53928)
vulnerability in nocodb (CVE-2026-53928). Risk of unauthorized operations or information disclosure. Exploitable via ``passwordChange``.
MINI-c227-m969-wrch MINI-c227-m969-wrch
ROOT-APP-MAVEN-CVE-2019-0231 Vulnerability in io.root.org.apache.mina:mina-core (ROOT-APP-MAVEN-CVE-2019-0231)
vulnerability in io.root.org.apache.mina:mina-core (ROOT-APP-MAVEN-CVE-2019-0231). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.0.0-RC1-root.io.2, 2.0.0-RC1-root.io.3` or later.
MINI-qrq6-pm8c-vmxq MINI-qrq6-pm8c-vmxq
CVE-2026-53927 SSRF (Server-Side Request Forgery) in nocodb (CVE-2026-53927)
SSRF in nocodb (CVE-2026-53927). Risk of unauthorized operations or information disclosure. Exploitable via ``axiosRequestMake``.
MINI-wvf9-w23q-5pvc MINI-wvf9-w23q-5pvc
MINI-2ffq-pqq7-45cm MINI-2ffq-pqq7-45cm
CVE-2026-54233 Vulnerability in vllm (CVE-2026-54233)
vulnerability in vllm (CVE-2026-54233). Risk of unauthorized operations or information disclosure. Exploitable via ``SpeechToTextProcessor``. Mitigation: upgrade to `0.24.0` or later.
MINI-8jpj-8c3p-9p4x MINI-8jpj-8c3p-9p4x
CVE-2026-54236 Vulnerability in vllm (CVE-2026-54236)
vulnerability in vllm (CVE-2026-54236). Risk of unauthorized operations or information disclosure. Exploitable via `POST /v1/messages`. Mitigation: upgrade to `0.24.0` or later.
CVE-2026-53923 Information Disclosure in vllm (CVE-2026-53923)
vulnerability in vllm (CVE-2026-53923). Confidential information can be exposed externally. Exploitable via ``to_cuda_ggml_t``. Mitigation: upgrade to `0.24.0` or later.
GHSA-8jr5-v98p-w75m Vulnerability in vllm (GHSA-8jr5-v98p-w75m)
vulnerability in vllm (GHSA-8jr5-v98p-w75m). Risk of unauthorized operations or information disclosure. Exploitable via ``ImageOps.exif_transpose``.
CVE-2026-54235 Vulnerability in vllm (CVE-2026-54235)
vulnerability in vllm (CVE-2026-54235). Risk of unauthorized operations or information disclosure. Exploitable via ``False``. Mitigation: upgrade to `0.24.0` or later.
CVE-2026-54761 Vulnerability in github.com/traefik/traefik/v3 (CVE-2026-54761)
vulnerability in github.com/traefik/traefik/v3 (CVE-2026-54761). Confidential information can be exposed externally. Mitigation: upgrade to `3.6.21, 3.7.5` or later.
CVE-2026-53765 Vulnerability in chrome-devtools-mcp (CVE-2026-53765)
vulnerability in chrome-devtools-mcp (CVE-2026-53765). Data can be tampered with by attackers. Exploitable via ``O_NOFOLLOW``. Mitigation: upgrade to `1.1.0` or later.
GHSA-664h-gpgq-h6xx Authorization Flaw in n8n (GHSA-664h-gpgq-h6xx)
vulnerability in n8n (GHSA-664h-gpgq-h6xx). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `2.25.7` or later.
CVE-2026-54325 Vulnerability in @earendil-works/pi-coding-agent (CVE-2026-54325)
vulnerability in @earendil-works/pi-coding-agent (CVE-2026-54325). Risk of unauthorized operations or information disclosure. Exploitable via ``project_trust``. Mitigation: upgrade to `0.79.0` or later.
CVE-2026-54328 Vulnerability in @earendil-works/pi-coding-agent (CVE-2026-54328)
vulnerability in @earendil-works/pi-coding-agent (CVE-2026-54328). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `>= 0.78.1` or later.
CGA-2fjg-j4jj-x26w CGA-2fjg-j4jj-x26w
CVE-2026-54327 Vulnerability in @mariozechner/pi-coding-agent (CVE-2026-54327)
vulnerability in @mariozechner/pi-coding-agent (CVE-2026-54327). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `0.78.1` or later.
GHSA-crmm-hgp2-wgrp Vulnerability in laravel/framework (GHSA-crmm-hgp2-wgrp)
vulnerability in laravel/framework (GHSA-crmm-hgp2-wgrp). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `12.61.1` or later.
GHSA-5vg9-5847-vvmq Vulnerability in laravel/framework (GHSA-5vg9-5847-vvmq)
vulnerability in laravel/framework (GHSA-5vg9-5847-vvmq). Confidential information can be exposed externally. Mitigation: upgrade to `12.60.0` or later.
USN-8447-1 Vulnerability in golang-go.crypto (USN-8447-1)
vulnerability in golang-go.crypto (USN-8447-1). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1:0.0~git20151201.0.7b85b09-2ubuntu0.1~esm2` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →