Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-45809 |
|
Vulnerability in dos (CVE-2026-45809)
vulnerability in dos (CVE-2026-45809). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45705 |
|
Out-of-Bounds Read in CVE-2026-45705 (CVE-2026-45705)
vulnerability in CVE-2026-45705 (CVE-2026-45705). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45537 |
|
Vulnerability in CVE-2026-45537 (CVE-2026-45537)
vulnerability in CVE-2026-45537 (CVE-2026-45537). Data can be tampered with by attackers.
|
| CVE-2026-70620 |
|
SSRF (Server-Side Request Forgery) in CVE-2026-70620 (CVE-2026-70620)
SSRF in CVE-2026-70620 (CVE-2026-70620). Confidential information can be exposed externally.
|
| CVE-2026-70619 |
|
Vulnerability in CVE-2026-70619 (CVE-2026-70619)
vulnerability in CVE-2026-70619 (CVE-2026-70619). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67862 |
|
Vulnerability in c (CVE-2026-67862)
vulnerability in c (CVE-2026-67862). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67861 |
|
Vulnerability in dos (CVE-2026-67861)
vulnerability in dos (CVE-2026-67861). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67860 |
|
Vulnerability in CVE-2026-67860 (CVE-2026-67860)
vulnerability in CVE-2026-67860 (CVE-2026-67860). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67859 |
|
Vulnerability in dos (CVE-2026-67859)
vulnerability in dos (CVE-2026-67859). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67858 |
|
Vulnerability in dos (CVE-2026-67858)
vulnerability in dos (CVE-2026-67858). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67857 |
|
Out-of-Bounds Read in c (CVE-2026-67857)
vulnerability in c (CVE-2026-67857). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67856 |
|
Vulnerability in dos (CVE-2026-67856)
vulnerability in dos (CVE-2026-67856). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67855 |
|
Vulnerability in dos (CVE-2026-67855)
vulnerability in dos (CVE-2026-67855). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-52370 |
|
Cross-Site Scripting (XSS) in CVE-2026-52370 (CVE-2026-52370)
cross-site scripting in CVE-2026-52370 (CVE-2026-52370). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-51144 |
|
Cross-Site Scripting (XSS) in CVE-2026-51144 (CVE-2026-51144)
cross-site scripting in CVE-2026-51144 (CVE-2026-51144). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45103 |
|
Vulnerability in CVE-2026-45103 (CVE-2026-45103)
vulnerability in CVE-2026-45103 (CVE-2026-45103). Data can be tampered with by attackers.
|
| CVE-2026-45100 |
|
Vulnerability in c (CVE-2026-45100)
vulnerability in c (CVE-2026-45100). Data can be tampered with by attackers.
|
| CVE-2026-45084 |
|
Vulnerability in dos (CVE-2026-45084)
vulnerability in dos (CVE-2026-45084). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18817 |
|
Vulnerability in CVE-2026-18817 (CVE-2026-18817)
vulnerability in CVE-2026-18817 (CVE-2026-18817). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18816 |
|
Authentication Bypass in CVE-2026-18816 (CVE-2026-18816)
authentication bypass in CVE-2026-18816 (CVE-2026-18816). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18814 |
|
Vulnerability in CVE-2026-18814 (CVE-2026-18814)
vulnerability in CVE-2026-18814 (CVE-2026-18814). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70594 |
|
Vulnerability in ghost (CVE-2026-70594)
vulnerability in ghost (CVE-2026-70594). Confidential information can be exposed externally. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-70593 |
|
Path Traversal in ghost (CVE-2026-70593)
path traversal in ghost (CVE-2026-70593). Data can be tampered with by attackers. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-70592 |
|
Path Traversal in ghost (CVE-2026-70592)
path traversal in ghost (CVE-2026-70592). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-70591 |
|
SSRF (Server-Side Request Forgery) in ghost (CVE-2026-70591)
SSRF in ghost (CVE-2026-70591). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-70554 |
|
Unsafe Deserialization in CVE-2026-70554 (CVE-2026-70554)
vulnerability in CVE-2026-70554 (CVE-2026-70554). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66902 |
|
OS Command Injection in c (CVE-2026-66902)
OS command injection in c (CVE-2026-66902). Successful exploitation can lead to full system takeover.
|
| CVE-2026-66901 |
|
Vulnerability in CVE-2026-66901 (CVE-2026-66901)
vulnerability in CVE-2026-66901 (CVE-2026-66901). Confidential information can be exposed externally.
|
| CVE-2026-67979 |
|
Vulnerability in CVE-2026-67979 (CVE-2026-67979)
vulnerability in CVE-2026-67979 (CVE-2026-67979). Confidential information can be exposed externally.
|
| CVE-2026-51401 |
|
Code Injection in c (CVE-2026-51401)
code injection in c (CVE-2026-51401). Confidential information can be exposed externally.
|
| CVE-2026-18811 |
|
Vulnerability in CVE-2026-18811 (CVE-2026-18811)
vulnerability in CVE-2026-18811 (CVE-2026-18811). Successful exploitation can lead to full system takeover.
|
| CVE-2026-51400 |
|
Vulnerability in c (CVE-2026-51400)
vulnerability in c (CVE-2026-51400). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18813 |
|
Vulnerability in c (CVE-2026-18813)
vulnerability in c (CVE-2026-18813). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18812 |
|
Vulnerability in CVE-2026-18812 (CVE-2026-18812)
vulnerability in CVE-2026-18812 (CVE-2026-18812). Successful exploitation can lead to full system takeover.
|
| CVE-2026-70590 |
|
Information Disclosure in ghost (CVE-2026-70590)
vulnerability in ghost (CVE-2026-70590). Data can be tampered with by attackers. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-65986 |
|
Cross-Site Scripting (XSS) in CVE-2026-65986 (CVE-2026-65986)
cross-site scripting in CVE-2026-65986 (CVE-2026-65986). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-45538 |
|
Vulnerability in c (CVE-2026-45538)
vulnerability in c (CVE-2026-45538). Successful exploitation can lead to full system takeover.
|
| CVE-2026-13227 |
|
Vulnerability in CVE-2026-13227 (CVE-2026-13227)
vulnerability in CVE-2026-13227 (CVE-2026-13227). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70589 |
|
Vulnerability in ghost (CVE-2026-70589)
vulnerability in ghost (CVE-2026-70589). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-70588 |
|
Cross-Site Scripting (XSS) in ghost (CVE-2026-70588)
cross-site scripting in ghost (CVE-2026-70588). Data can be tampered with by attackers. Mitigation: upgrade to `6.54.1` or later.
|
| CVE-2026-70494 |
|
Vulnerability in open-webui (CVE-2026-70494)
vulnerability in open-webui (CVE-2026-70494). Data can be tampered with by attackers. Exploitable via `DELETE /api/v1/folders/{id}`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70493 |
|
Vulnerability in open-webui (CVE-2026-70493)
vulnerability in open-webui (CVE-2026-70493). Risk of unauthorized operations or information disclosure. Exploitable via ``ENABLE_KB_EXEC``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70492 |
|
Cross-Site Scripting (XSS) in open-webui (CVE-2026-70492)
cross-site scripting in open-webui (CVE-2026-70492). Confidential information can be exposed externally. Exploitable via ``catch``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70491 |
|
Information Disclosure in open-webui (CVE-2026-70491)
vulnerability in open-webui (CVE-2026-70491). Confidential information can be exposed externally. Exploitable via `GET /api/v1/tools/`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70490 |
|
Authorization Flaw in open-webui (CVE-2026-70490)
vulnerability in open-webui (CVE-2026-70490). Risk of unauthorized operations or information disclosure. Exploitable via ``get_verified_user``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70489 |
|
Vulnerability in open-webui (CVE-2026-70489)
vulnerability in open-webui (CVE-2026-70489). Risk of unauthorized operations or information disclosure. Exploitable via ``USER_PERMISSIONS_FEATURES_AUTOMATIONS``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-54020 |
|
Vulnerability in open-webui (CVE-2026-54020)
vulnerability in open-webui (CVE-2026-54020). Confidential information can be exposed externally. Exploitable via ``image_url``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70487 |
|
Vulnerability in open-webui (CVE-2026-70487)
vulnerability in open-webui (CVE-2026-70487). Confidential information can be exposed externally. Exploitable via ``builtin_tools``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70488 |
|
Vulnerability in open-webui (CVE-2026-70488)
vulnerability in open-webui (CVE-2026-70488). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/knowledge/{id}/sync/cleanup`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-18656 |
|
Vulnerability in Amazon aws (CVE-2026-18656)
vulnerability in Amazon aws (CVE-2026-18656). Successful exploitation can lead to full system takeover.
|