Vulnerabilities
Aggregated CVE / GHSA / KEV / OSV — filter by tag and category.
| ID | Title | |
|---|---|---|
| CVE-2026-71247 |
|
Authorization Flaw in CVE-2026-71247 (CVE-2026-71247)
vulnerability in CVE-2026-71247 (CVE-2026-71247). Data can be tampered with by attackers.
|
| CVE-2026-71234 |
|
Authorization Flaw in CVE-2026-71234 (CVE-2026-71234)
vulnerability in CVE-2026-71234 (CVE-2026-71234). Confidential information can be exposed externally. Exploitable via ``secure``.
|
| CVE-2026-71201 |
|
Authorization Flaw in CVE-2026-71201 (CVE-2026-71201)
vulnerability in CVE-2026-71201 (CVE-2026-71201). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71192 |
|
Authorization Flaw in CVE-2026-71192 (CVE-2026-71192)
vulnerability in CVE-2026-71192 (CVE-2026-71192). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-71191 |
|
Authorization Flaw in CVE-2026-71191 (CVE-2026-71191)
vulnerability in CVE-2026-71191 (CVE-2026-71191). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-55707 |
|
Authorization Flaw in CVE-2026-55707 (CVE-2026-55707)
vulnerability in CVE-2026-55707 (CVE-2026-55707). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70494 |
|
Vulnerability in open-webui (CVE-2026-70494)
vulnerability in open-webui (CVE-2026-70494). Data can be tampered with by attackers. Exploitable via `DELETE /api/v1/folders/{id}`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70490 |
|
Authorization Flaw in open-webui (CVE-2026-70490)
vulnerability in open-webui (CVE-2026-70490). Risk of unauthorized operations or information disclosure. Exploitable via ``get_verified_user``. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70488 |
|
Vulnerability in open-webui (CVE-2026-70488)
vulnerability in open-webui (CVE-2026-70488). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/knowledge/{id}/sync/cleanup`. Mitigation: upgrade to `0.11.0` or later.
|
| CVE-2026-70484 |
|
Vulnerability in open-webui (CVE-2026-70484)
vulnerability in open-webui (CVE-2026-70484). Risk of unauthorized operations or information disclosure. Exploitable via ``features.image_generation``. Mitigation: upgrade to `897d69a` or later.
|
| CVE-2026-64630 |
|
Authorization Flaw in CVE-2026-64630 (CVE-2026-64630)
vulnerability in CVE-2026-64630 (CVE-2026-64630). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-70474 |
|
Authorization Flaw in flowise (CVE-2026-70474)
vulnerability in flowise (CVE-2026-70474). Risk of unauthorized operations or information disclosure. Exploitable via `POST /api/v1/oauth2-credential/authorize/`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70472 |
|
Vulnerability in flowise (CVE-2026-70472)
vulnerability in flowise (CVE-2026-70472). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v1/openai-assistants-vector-store`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-70471 |
|
Authorization Flaw in flowise (CVE-2026-70471)
vulnerability in flowise (CVE-2026-70471). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-69262 |
|
Authorization Flaw in flowise (CVE-2026-69262)
vulnerability in flowise (CVE-2026-69262). Risk of unauthorized operations or information disclosure. Exploitable via `DELETE /api/v1/chatflows/`. Mitigation: upgrade to `3.1.3` or later.
|
| CVE-2026-18773 |
|
Vulnerability in CVE-2026-18773 (CVE-2026-18773)
vulnerability in CVE-2026-18773 (CVE-2026-18773). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-62927 |
|
Authorization Flaw in eclipse (CVE-2026-62927)
vulnerability in eclipse (CVE-2026-62927). Data can be tampered with by attackers.
|
| CVE-2026-48333 |
|
Authorization Flaw in privilege-escalation (CVE-2026-48333)
vulnerability in privilege-escalation (CVE-2026-48333). Successful exploitation can lead to full system takeover.
|
| CVE-2026-68980 |
|
Authorization Flaw in apache (CVE-2026-68980)
vulnerability in apache (CVE-2026-68980). Confidential information can be exposed externally.
|
| CVE-2026-58139 |
|
Authorization Flaw in CVE-2026-58139 (CVE-2026-58139)
vulnerability in CVE-2026-58139 (CVE-2026-58139). Confidential information can be exposed externally.
|
| CVE-2026-62354 |
|
Authorization Flaw in apache (CVE-2026-62354)
vulnerability in apache (CVE-2026-62354). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-68930 |
|
Vulnerability in russh (CVE-2026-68930)
vulnerability in russh (CVE-2026-68930). Data can be tampered with by attackers. Exploitable via ``russh``. Mitigation: upgrade to `0.62.5` or later.
|
| CVE-2026-15254 |
|
Authorization Flaw in wordpress (CVE-2026-15254)
vulnerability in wordpress (CVE-2026-15254). Confidential information can be exposed externally.
|
| CVE-2026-68581 |
|
Authorization Flaw in CVE-2026-68581 (CVE-2026-68581)
vulnerability in CVE-2026-68581 (CVE-2026-68581). Confidential information can be exposed externally.
|
| CVE-2026-16540 |
|
Authorization Flaw in wordpress (CVE-2026-16540)
vulnerability in wordpress (CVE-2026-16540). Confidential information can be exposed externally.
|
| CVE-2026-18572 |
|
Authorization Flaw in redhat (CVE-2026-18572)
vulnerability in redhat (CVE-2026-18572). Data can be tampered with by attackers.
|
| CVE-2026-16064 |
|
Authorization Flaw in wordpress (CVE-2026-16064)
vulnerability in wordpress (CVE-2026-16064). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-15939 |
|
Authorization Flaw in wordpress (CVE-2026-15939)
vulnerability in wordpress (CVE-2026-15939). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67341 |
|
Authorization Flaw in CVE-2026-67341 (CVE-2026-67341)
vulnerability in CVE-2026-67341 (CVE-2026-67341). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67310 |
|
Authorization Flaw in CVE-2026-67310 (CVE-2026-67310)
vulnerability in CVE-2026-67310 (CVE-2026-67310). Risk of unauthorized operations or information disclosure. Mitigation: upgrade to `1.27.0` or later.
|
| CVE-2026-2411 |
|
Authorization Flaw in c (CVE-2026-2411)
vulnerability in c (CVE-2026-2411). Confidential information can be exposed externally.
|
| CVE-2026-18394 |
|
Authorization Flaw in Amazon aws (CVE-2026-18394)
vulnerability in Amazon aws (CVE-2026-18394). Confidential information can be exposed externally. Exploitable via `Authorization header`.
|
| CVE-2026-54707 |
|
Authorization Flaw in onionshare-cli (CVE-2026-54707)
vulnerability in onionshare-cli (CVE-2026-54707). Risk of unauthorized operations or information disclosure. Exploitable via `POST /upload`. Mitigation: upgrade to `2.6.4` or later.
|
| CVE-2026-18203 |
|
Authorization Flaw in redhat (CVE-2026-18203)
vulnerability in redhat (CVE-2026-18203). Data can be tampered with by attackers.
|
| CVE-2026-14929 |
|
Authorization Flaw in wordpress (CVE-2026-14929)
vulnerability in wordpress (CVE-2026-14929). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-14538 |
|
Vulnerability in google (CVE-2026-14538)
vulnerability in google (CVE-2026-14538). Confidential information can be exposed externally.
|
| CVE-2026-14537 |
|
Authorization Flaw in google (CVE-2026-14537)
vulnerability in google (CVE-2026-14537). Successful exploitation can lead to full system takeover.
|
| CVE-2026-10031 |
|
Authorization Flaw in CVE-2026-10031 (CVE-2026-10031)
vulnerability in CVE-2026-10031 (CVE-2026-10031). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-67528 |
|
Authorization Flaw in CVE-2026-67528 (CVE-2026-67528)
vulnerability in CVE-2026-67528 (CVE-2026-67528). Risk of unauthorized operations or information disclosure. Exploitable via `GET /api/v3/custom_options/`. Mitigation: upgrade to `17.6.0` or later.
|
| CVE-2026-65835 |
|
Privilege Escalation in github.com/projectcapsule/capsule (CVE-2026-65835)
vulnerability in github.com/projectcapsule/capsule (CVE-2026-65835). Risk of unauthorized operations or information disclosure. Exploitable via ``ClusterRole``. Mitigation: upgrade to `0.13.8` or later.
|
| CVE-2026-67347 |
|
Authorization Flaw in CVE-2026-67347 (CVE-2026-67347)
vulnerability in CVE-2026-67347 (CVE-2026-67347). Data can be tampered with by attackers.
|
| CVE-2026-41187 |
|
Vulnerability in tigera (CVE-2026-41187)
vulnerability in tigera (CVE-2026-41187). Data can be tampered with by attackers.
|
| CVE-2026-14923 |
|
Authorization Flaw in wordpress (CVE-2026-14923)
vulnerability in wordpress (CVE-2026-14923). Confidential information can be exposed externally.
|
| CVE-2026-48449 |
|
Authorization Flaw in adobe (CVE-2026-48449)
vulnerability in adobe (CVE-2026-48449). Successful exploitation can lead to full system takeover.
|
| CVE-2026-67439 |
|
Authorization Flaw in github.com/OliveTin/OliveTin (CVE-2026-67439)
vulnerability in github.com/OliveTin/OliveTin (CVE-2026-67439). Risk of unauthorized operations or information disclosure. Exploitable via ``StartActionAndWait``. Mitigation: upgrade to `0.0.0-20260708085316-e421780c9885` or later.
|
| CVE-2026-65975 |
|
Authorization Flaw in pydantic (CVE-2026-65975)
vulnerability in pydantic (CVE-2026-65975). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-6336 |
|
Authorization Flaw in gitlab (CVE-2026-6336)
vulnerability in gitlab (CVE-2026-6336). Risk of unauthorized operations or information disclosure.
|
| CVE-2025-14562 |
|
Authorization Flaw in gitlab (CVE-2025-14562)
vulnerability in gitlab (CVE-2025-14562). Risk of unauthorized operations or information disclosure.
|
| CVE-2026-18255 |
|
Authorization Flaw in CVE-2026-18255 (CVE-2026-18255)
vulnerability in CVE-2026-18255 (CVE-2026-18255). Successful exploitation can lead to full system takeover.
|
| CVE-2026-18236 |
|
Authorization Flaw in CVE-2026-18236 (CVE-2026-18236)
vulnerability in CVE-2026-18236 (CVE-2026-18236). Risk of unauthorized operations or information disclosure.
|