CVE Vulnerability Database

Search and browse 377,766 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-70485HIGH7.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebU...
CVE-2026-70484MEDIUM4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legac...
CVE-2026-70483LOW3.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, DELETE /a...
CVE-2026-70482HIGH8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.0 until 0.11.0, when ENAB...
CVE-2026-70481MEDIUM5.4Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.0, the stand...
CVE-2026-70480MEDIUM4.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.6.34 until 0.11.0, Open Web...
CVE-2026-70479HIGH7.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, with WEB_...
CVE-2026-70478CRITICAL9.2Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the POST /api/v...
CVE-2026-70477CRITICAL9.5Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, a prompt inject...
CVE-2026-70476HIGH8.3Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, several organiz...
CVE-2026-70475HIGH7.1Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the PUT /api/v1...
CVE-2026-48154MEDIUM5.9GoRest is a Golang starter kit built with the Gin framework for prototyping and developing RESTful APIs. In versions pri...
CVE-2026-47682HIGH7.1CVAT is an open source interactive video and image annotation tool for computer vision. In versions 1.6.0 through 2.64.0...
CVE-2026-18810HIGH7.3A security vulnerability has been detected in H3C NX15 V100R017. Impacted is an unknown function of the file /api/wizard...
CVE-2026-18657HIGH8.5An uncontrolled search path element in Kiro CLI before version 2.10.0 on Windows might allow a remote unauthenticated ac...
CVE-2026-18656HIGH8.5An uncontrolled search path element in Kiro IDE before version 1.0.228 on Windows might allow a remote unauthenticated a...
CVE-2026-16793HIGH8.8An improper neutralization of special elements used in an operating system command vulnerability was reported in Lenovo ...
CVE-2026-16792HIGH7An improper certificate validation vulnerability was reported in multiple Lenovo XClarity Orchestrator (LXCO) 2.2.0 micr...
CVE-2026-16791LOW3.9A temporary file creation vulnerability in the Linux version of Lenovo XClarity Essentials OneCLI 5.5.0 and below could ...
CVE-2026-70474HIGH7.6Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow...
CVE-2026-70473HIGH8.3Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow...
CVE-2026-70472HIGH7.1Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise openai-...
CVE-2026-70471HIGH7.1Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to 3.1.3, Flow...
CVE-2026-69704HIGH7Atals-Livre contains a SQL injection vulnerability that allows attackers to manipulate database queries by passing unsan...
CVE-2026-69703CRITICAL9.8Atlas-Livre contains an improper access control vulnerability in the admin controllers under Espace_admin/controleur/ th...