Total CVEs

130,823

Critical Severity

2,726

High Severity

9,741

Last 7 Days

738
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,341 - 1,360 of 27,228 CVEs
CVE-2026-45301 HIGH - 8.1

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.3.16, a missing permission check in all files related API endpoints allows any authenticated user to list, access and delete every file uploaded by every user to the platform. This vulnerabi...

Vendor: pip
Product: open-webui
Published: May 14, 2026
Source: GitHub

Electerm: Importing unsafe bookmark data could lead to unsafe operation when clicking local type bookmark

Vendor: npm
Product: electerm
Published: May 14, 2026
Source: GitHub
CVE-2026-45299 MEDIUM - 5.4

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, the profile_image_url field on the user profile update form accepted arbitrary data: URI values without MIME-type validation, resulting in a XSS vulnerability. This vulnerability is fix...

Vendor: pip
Product: open-webui
Published: May 14, 2026
Source: GitHub

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin

Vendor: go
Product: github.com/kumahq/kuma
Published: May 14, 2026
Source: GitHub
CVE-2026-8621 HIGH - 8.8

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attackers can inject malicious X-Crabbox-Owner and X-Crabbox-Org headers in requests authenticated with a sha...

Published: May 14, 2026
Source: NVD
CVE-2026-44633 HIGH - 8.1

Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in a department they cannot read. The endpoint accepts arbitrary chat object fields, so the user can cha...

Vendor: LiveHelperChat
Product: livehelperchat
Published: May 14, 2026
Source: NVD
CVE-2026-44592 CRITICAL - 9.4

Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone who can reach /proto can register as a worker without any credentials by sending a fresh, never-registered worker UUID. The resulting session has PeerA...

Vendor: wavelens
Product: gradient
Published: May 14, 2026
Source: NVD
CVE-2026-44586 HIGH - 8.3

SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML without escaping. In the desktop app this becomes stored XSS, and because SiYuan's Electron wi...

Vendor: siyuan-note
Product: siyuan
Published: May 14, 2026
Source: NVD

mdserver-web is a simple Linux panel. From 0.18.0 to 0.18.4, mdserver-web has a front-end unauthorized remote command execution vulnerability. Due to the lack of authentication on the /modify_crond and /start_task interfaces, it is possible to modify the default built-in scheduled tasks and start th...

Vendor: midoks
Product: mdserver-web
Published: May 14, 2026
Source: NVD
CVE-2026-38740 MEDIUM - 5.3

Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The device transmits sensitive Session Description Protocol (SDP), including ICE credentials and candidates, in cleartext over network interfaces. An attacker with network visibility can i...

Published: May 14, 2026
Source: NVD

Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the application. When a user accesses or clicks the affected page, the injected CSS is executed. As a result,...

Vendor: SAP_SE
Product: SAP NetWeaver Application Server ABAP
Published: May 14, 2026
Source: NVD

ethyca-fides has a DOM-based XSS vulnerability in fides.js via fides_description override

Vendor: pip
Product: ethyca-fides
Published: May 14, 2026
Source: GitHub
CVE-2026-45011 HIGH - 7.3

Apostrophe has stored XSS via javascript: URL in Image Widget Link

Vendor: npm
Product: apostrophe
Published: May 14, 2026
Source: GitHub
CVE-2026-45013 HIGH - 8.1

Apostrophe has a Weak Password Recovery Mechanism for Forgotten Password and Improper Input Validation

Vendor: npm
Product: apostrophe
Published: May 14, 2026
Source: GitHub
CVE-2026-45012 HIGH - 7.6

Apostrophe has authenticated SSRF in rich-text widget import via @apostrophecms/area/validate-widget

Vendor: npm
Product: apostrophe
Published: May 14, 2026
Source: GitHub
CVE-2026-44990 CRITICAL - 9.3

Apostrophe has default XSS via `xmp` raw-text passthrough in `sanitize-html`

Vendor: npm
Product: sanitize-html
Published: May 14, 2026
Source: GitHub
CVE-2026-44973 HIGH - 8.1

go-billy has path traversal vulnerabilities

Vendor: go
Product: github.com/go-git/go-billy/v5
Published: May 14, 2026
Source: GitHub

dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction

Vendor: pip
Product: dbt-mcp
Published: May 14, 2026
Source: GitHub

dbt MCP Server Logs Tool Arguments Including SQL Queries and Credentials in Plaintext Without Redaction When File Logging Is Enabled

Vendor: pip
Product: dbt-mcp
Published: May 14, 2026
Source: GitHub
CVE-2026-44968 MEDIUM - 6.3

dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters

Vendor: pip
Product: dbt-mcp
Published: May 14, 2026
Source: GitHub