CVE Vulnerability Database

Search and browse 380,738 CVE records with CVSS scores, EPSS exploit predictions, and CISA KEV status.

CVE IDSeverityCVSSDescription
CVE-2026-70494HIGH8.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, the DELE...
CVE-2026-70493MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the built...
CVE-2026-70492HIGH8.7Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.0, src/lib/...
CVE-2026-70491MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. In 0.10.2 and earlier, the GET /ap...
CVE-2026-70490MEDIUM6.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, the termi...
CVE-2026-70489MEDIUM6.5Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, automatio...
CVE-2026-70488MEDIUM4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.6 until 0.11.0, the sync ...
CVE-2026-70487MEDIUM5.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.8.8 until 0.11.0, inline di...
CVE-2026-67979CRITICAL9.1Incorrect access control in the Executive Services dynamic application start path component of NASA cFS v7.0.1 allows at...
CVE-2026-66902CRITICAL9.8Google::Auth versions before 0.06 for Perl run a command named in an external_account credentials JSON via an ungated sy...
CVE-2026-66901HIGH7.5Google::Auth versions before 0.09 for Perl allow server side request forgery and credential exfiltration via unvalidated...
CVE-2026-65986HIGH8.5CVAT is an open source interactive video and image annotation tool for computer vision. Versions 2.5.0 through 2.66.0 co...
CVE-2026-54020MEDIUM6.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. Prior to 0.11.0, Open WebUI resolv...
CVE-2026-51401HIGH7.7An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename(...
CVE-2026-51400HIGH8.4An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename(...
CVE-2026-45538CRITICAL9.8OpenSIPS is a Session Initiation Protocol (SIP) server implementation. In versions 4.0.0 and prior, processing a SIP mes...
CVE-2026-18813HIGH7.3A vulnerability has been found in H3C NX15 V100R017. This affects the function delete of the file /api/esps. The manipul...
CVE-2026-18812HIGH7.3A flaw has been found in H3C NX15 V100R017. The impacted element is the function esps.ipv6.wan of the file /api/esps. Ex...
CVE-2026-18811HIGH7.3A vulnerability was detected in H3C NX15 V100R017. The affected element is the function Add of the file /api/esps. Perfo...
CVE-2026-13227HIGH7.1An Improper Authorization vulnerability exists in ERPNext version <v16.25.0 and <15.115.0 due to insufficient access co...
CVE-2026-70553CRITICAL9.8MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP...
CVE-2026-70552CRITICAL9.8MaxSite CMS 109.5 and earlier contains an authentication bypass vulnerability in the AJAX dispatcher that allows unauthe...
CVE-2026-70486HIGH8.2Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, the termi...
CVE-2026-70485HIGH7.1Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.0 until 0.11.0, Open WebU...
CVE-2026-70484MEDIUM4.3Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.7.0 until 0.11.0, the legac...