Total CVEs

131,648

Critical Severity

2,801

High Severity

10,044

Last 7 Days

1,211
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 2,021 - 2,040 of 28,053 CVEs

OneDev is a Git server with CI/CD, kanban, and packages. Prior to 15.0.2, there is behavior that breaks the expected boundary between repository-controlled LFS metadata and server-local filesystem paths. A repository object can steer raw blob reads to arbitrary local files that the server account ca...

Vendor: theonedev
Product: onedev
Published: May 14, 2026
Source: NVD

ClipBucket v5 is an open source video sharing platform. Prior to 5.5.3 - #122, there is a critical SQL Injection (SQLi) vulnerability in ClipBucket, exploitable through the type parameter on the authenticated admin endpoint admin_area/action_logs.php. The endpoint admin_area/action_logs.php reads $_...

Vendor: MacWarrior
Product: clipbucket-v5
Published: May 14, 2026
Source: NVD
CVE-2026-46509 HIGH - 8.2

Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in @ranfdev/deepobj

Vendor: npm
Product: @ranfdev/deepobj
Published: May 14, 2026
Source: GitHub
CVE-2026-45366 MEDIUM - 4.7

@utcp/http: SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communication protocol

Vendor: npm
Product: @utcp/http
Published: May 14, 2026
Source: GitHub
CVE-2026-45288 CRITICAL - 9.8

Marten has an injection vulnerability in its full-text search regConfig parameter

Vendor: nuget
Product: Marten
Published: May 14, 2026
Source: GitHub

electerm's encrypt method not safe enough

Vendor: npm
Product: electerm
Published: May 14, 2026
Source: GitHub

Electerm Local code through electerm's single-instance socket

Vendor: npm
Product: electerm
Published: May 14, 2026
Source: GitHub
CVE-2026-45374 CRITICAL - 9.6

DeepSeek TUI: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files

Vendor: rust
Product: deepseek-tui
Published: May 14, 2026
Source: GitHub
CVE-2026-45373 HIGH - 7.4

DeepSeek TUI has SSRFโ€Œ IPV6 bypass

Vendor: rust
Product: deepseek-tui
Published: May 14, 2026
Source: GitHub
CVE-2026-45311 CRITICAL - 9.6

DeepSeek TUI: run_tests Tool Enables RCE via Malicious Repository Without Approval

Vendor: rust
Product: deepseek-tui
Published: May 14, 2026
Source: GitHub
CVE-2026-45310 HIGH - 7.4

DeepSeek TUI has SSRF via HTTP Redirect Bypass in fetch_url Tool

Vendor: rust
Product: deepseek-tui
Published: May 14, 2026
Source: GitHub

Svelte Vulnerable to XSS via DOM Clobbering of Internal Framework State

Vendor: npm
Product: svelte
Published: May 14, 2026
Source: GitHub

Svelte: ReDoS in `<svelte:element>` Tag Validation

Vendor: npm
Product: svelte
Published: May 14, 2026
Source: GitHub
CVE-2026-45675 HIGH - 8.1

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, he LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) pattern for first-user admin role assignment. The regular signup handler (signup_handler in auths.py, lin...

Vendor: pip
Product: open-webui
Published: May 14, 2026
Source: GitHub
CVE-2026-45672 HIGH - 8.8

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.12, the /api/v1/utils/code/execute endpoint executes arbitrary Python code via Jupyter for any verified user, even when the admin has set ENABLE_CODE_EXECUTION=false. The feature gate is n...

Vendor: pip
Product: open-webui
Published: May 14, 2026
Source: GitHub
CVE-2026-45671 HIGH - 8.0

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user can permanently delete files owned by other users via DELETE /api/v1/files/{id} when the target file is referenced in any shared chat. The has_access_to_file() au...

Vendor: pip
Product: open-webui
Published: May 14, 2026
Source: GitHub
CVE-2026-45667 MEDIUM - 6.5

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, GET /api/v1/memories/ef is accessible without authentication and executes request.app.state.EMBEDDING_FUNCTION(...). This allows any unauthenticated caller to trigger embedding generati...

Vendor: pip
Product: open-webui
Published: May 14, 2026
Source: GitHub
CVE-2026-45666 MEDIUM - 6.5

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the API /api/v1/notes/{note_id} endpoint lacks proper authorization checks, allowing authenticated users to retrieve notes belonging to other users by guessing or enumerating UUIDs. Th...

Vendor: pip
Product: open-webui
Published: May 14, 2026
Source: GitHub
CVE-2026-45665 HIGH - 8.1

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component due to an improper sanitization order (specifically, DOMPurify is executed before the marked library). T...

Vendor: npm
Product: open-webui
Published: May 14, 2026
Source: GitHub
CVE-2026-45402 HIGH - 8.1

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, multiple endpoints accept a user-supplied file_id and attach the referenced file to a resource the caller controls (folder knowledge, knowledge-base contents) without verifying that the...

Vendor: pip
Product: open-webui
Published: May 14, 2026
Source: GitHub