Vulnerabilities

Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.

ID Title
GHSA-gxhx-2686-5h9g Vulnerability in github.com/slack-go/slack (GHSA-gxhx-2686-5h9g)
vulnerability in github.com/slack-go/slack (GHSA-gxhx-2686-5h9g). Risk of unauthorized operations or information disclosure. Exploitable via ``SecretsVerifier``. Mitigation: upgrade to `0.23.1` or later.
CVE-2026-45288 SQL Injection in Marten (CVE-2026-45288)
SQL injection in Marten (CVE-2026-45288). Successful exploitation can lead to full system takeover. Exploitable via ``regConfig``. Mitigation: upgrade to `8.37.0` or later.
MINI-q63h-6xrg-f42w MINI-q63h-6xrg-f42w
MINI-5488-h8vx-jg8x MINI-5488-h8vx-jg8x
MINI-f6wv-p938-9gvf MINI-f6wv-p938-9gvf
MINI-w9f3-pwp2-74h2 MINI-w9f3-pwp2-74h2
MINI-3m5x-fm49-44p3 MINI-3m5x-fm49-44p3
MINI-wgv2-jxpc-x9pc MINI-wgv2-jxpc-x9pc
MINI-9524-4vwp-pfm2 MINI-9524-4vwp-pfm2
GHSA-wf8q-wvv8-p8jf Vulnerability in @samanhappy/mcphub (GHSA-wf8q-wvv8-p8jf)
vulnerability in @samanhappy/mcphub (GHSA-wf8q-wvv8-p8jf). Confidential information can be exposed externally. Exploitable via ``sseUserContextMiddleware``. Mitigation: upgrade to `0.12.15` or later.
MAL-2026-3743 Vulnerability in sol-batch-transfer-sdk (MAL-2026-3743)
vulnerability in sol-batch-transfer-sdk (MAL-2026-3743). Risk of unauthorized operations or information disclosure.
MINI-vh5p-vc4p-ph5v MINI-vh5p-vc4p-ph5v
MINI-fp7c-9852-9mqf MINI-fp7c-9852-9mqf
MINI-qh32-frhv-8gqq MINI-qh32-frhv-8gqq
MINI-w624-qg29-9v23 MINI-w624-qg29-9v23
MINI-pvgq-q9qg-2wp2 MINI-pvgq-q9qg-2wp2
MINI-qrfm-chff-q8m6 MINI-qrfm-chff-q8m6
MINI-cfmg-jpcr-7q7m MINI-cfmg-jpcr-7q7m
MINI-q3c8-jwfj-vh59 MINI-q3c8-jwfj-vh59
MINI-jqw7-rhh8-pr3w MINI-jqw7-rhh8-pr3w
MINI-54pw-jcp9-qjv2 MINI-54pw-jcp9-qjv2
MINI-9wgm-74m9-p5r2 MINI-9wgm-74m9-p5r2
MINI-fh2f-77f6-jhv7 MINI-fh2f-77f6-jhv7
MINI-4f7g-vrj8-7542 MINI-4f7g-vrj8-7542
MINI-f29x-4pj4-746w MINI-f29x-4pj4-746w
MINI-f9f6-4rxf-mfcj MINI-f9f6-4rxf-mfcj
MINI-v4fh-v5gm-3pmq MINI-v4fh-v5gm-3pmq
MINI-cvmh-mhf7-29c6 MINI-cvmh-mhf7-29c6
MINI-3pw3-frhj-pv3p MINI-3pw3-frhj-pv3p
MINI-9m2m-m449-7wpg MINI-9m2m-m449-7wpg
MINI-35vj-ghhj-773q MINI-35vj-ghhj-773q
MINI-8vxv-3rj4-v7xr MINI-8vxv-3rj4-v7xr
GHSA-f3cj-j4f6-wq85 Cross-Site Scripting (XSS) in svelte (GHSA-f3cj-j4f6-wq85)
cross-site scripting in svelte (GHSA-f3cj-j4f6-wq85). Risk of unauthorized operations or information disclosure. Exploitable via ``hydratable``. Mitigation: upgrade to `5.55.7` or later.
CVE-2026-45787 Vulnerability in electerm (CVE-2026-45787)
vulnerability in electerm (CVE-2026-45787). Confidential information can be exposed externally. Mitigation: upgrade to `3.9.5` or later.
CVE-2026-45353 Vulnerability in electerm (CVE-2026-45353)
vulnerability in electerm (CVE-2026-45353). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `3.9.0` or later.
CVE-2026-45374 Code Injection in deepseek-tui (CVE-2026-45374)
code injection in deepseek-tui (CVE-2026-45374). Successful exploitation can lead to full system takeover. Exploitable via ``task_create``. Mitigation: upgrade to `0.8.26` or later.
CVE-2026-45373 SSRF (Server-Side Request Forgery) in deepseek-tui (CVE-2026-45373)
SSRF in deepseek-tui (CVE-2026-45373). Confidential information can be exposed externally. Mitigation: upgrade to `0.8.26` or later.
CVE-2026-45311 Code Injection in deepseek-tui (CVE-2026-45311)
code injection in deepseek-tui (CVE-2026-45311). Successful exploitation can lead to full system takeover. Exploitable via ``run_tests``. Mitigation: upgrade to `0.8.23` or later.
CVE-2026-45310 SSRF (Server-Side Request Forgery) in deepseek-tui (CVE-2026-45310)
SSRF in deepseek-tui (CVE-2026-45310). Confidential information can be exposed externally. Exploitable via ``fetch_url``. Mitigation: upgrade to `0.8.22` or later.
CVE-2026-42573 Cross-Site Scripting (XSS) in svelte (CVE-2026-42573)
cross-site scripting in svelte (CVE-2026-42573). Risk of unauthorized operations or information disclosure. Exploitable via ``name``. Mitigation: upgrade to `5.55.7` or later.
CVE-2026-42567 Vulnerability in svelte (CVE-2026-42567)
vulnerability in svelte (CVE-2026-42567). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `5.55.7` or later.
CVE-2026-45675 Privilege Escalation in open-webui (CVE-2026-45675)
vulnerability in open-webui (CVE-2026-45675). Successful exploitation can lead to full system takeover. Exploitable via ``signup_handler``. Mitigation: upgrade to `0.9.0` or later.
CVE-2026-45672 Authorization Flaw in open-webui (CVE-2026-45672)
vulnerability in open-webui (CVE-2026-45672). Successful exploitation can lead to full system takeover. Mitigation: upgrade to `0.8.12` or later.
CVE-2026-45671 Vulnerability in open-webui (CVE-2026-45671)
vulnerability in open-webui (CVE-2026-45671). Successful exploitation can lead to full system takeover. Exploitable via `DELETE /api/v1/files/{id}`. Mitigation: upgrade to `0.9.0` or later.
CVE-2026-45667 Vulnerability in open-webui (CVE-2026-45667)
vulnerability in open-webui (CVE-2026-45667). Risk of unauthorized operations or information disclosure. Exploitable via `Authorization header`. Mitigation: upgrade to `0.8.0` or later.
CVE-2026-45666 Vulnerability in open-webui (CVE-2026-45666)
vulnerability in open-webui (CVE-2026-45666). Confidential information can be exposed externally. Exploitable via `GET /api/config.`. Mitigation: upgrade to `0.8.11` or later.
CVE-2026-45665 Cross-Site Scripting (XSS) in open-webui (CVE-2026-45665)
cross-site scripting in open-webui (CVE-2026-45665). Confidential information can be exposed externally. Exploitable via ``marked.parse``. Mitigation: upgrade to `0.8.0` or later.
CVE-2026-45402 Vulnerability in open-webui (CVE-2026-45402)
vulnerability in open-webui (CVE-2026-45402). Confidential information can be exposed externally. Exploitable via `POST /api/v1/folders/{id}/update`. Mitigation: upgrade to `0.9.5` or later.
GHSA-3wgj-c2hg-vm6q Vulnerability in open-webui (GHSA-3wgj-c2hg-vm6q)
vulnerability in open-webui (GHSA-3wgj-c2hg-vm6q). Confidential information can be exposed externally. Exploitable via `GET /api/v1/users/{id}/profile/image`. Mitigation: upgrade to `0.9.5` or later.
CVE-2026-45401 SSRF (Server-Side Request Forgery) in open-webui (CVE-2026-45401)
SSRF in open-webui (CVE-2026-45401). Confidential information can be exposed externally. Exploitable via ``requests``. Mitigation: upgrade to `0.9.5` or later.

🍪 About cookies

We use cookies to keep you logged in, remember your language, and improve the service.

Details →