Daily digest
Thursday 14 May 2026
63 new CVEs this day, in line with the recent average. Of those, 1 critical and 27 high. 5 arrived with exploitation evidence or public exploit code already attached. open-webui was the most-affected vendor with 32.
New this day, ranked by depth score
The 12 that matter most of the 63 published.
CVE-2026-20224High· 8.6PoCA vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system
A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system. The attacker does not need to have va…
CVE-2026-45401High· 8.5PoCOpen WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
CVE-2026-44673High· 7.5PoClibyang is a YANG data modeling language library
libyang is a YANG data modeling language library. Prior to SO 5.2.15, lyb_read_string() in src/parser_lyb.c contains an integer overflow that results in a heap buffer overflow when parsing a maliciously crafted LYB binary blob. An attack…
CVE-2026-8634Critical· 9.1Crabbox: environment variable exposure vulnerability
Crabbox: environment variable exposure vulnerability
CVE-2026-6473High· 8.8Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds
Integer wraparound in multiple PostgreSQL server features allows an unprivileged database user to cause the server to undersize an allocation and write out-of-bounds. This may execute arbitrary code as the operating system user running …
CVE-2026-45672High· 8.8Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
CVE-2026-44513High· 8.8Diffusers is the a library for pretrained diffusion models
Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omi…
CVE-2026-6477High· 8.8Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-l…
Use of inherently dangerous function PQfn(..., result_is_int=0, ...) in PostgreSQL libpq lo_export(), lo_read(), lo_lseek64(), and lo_tell64() functions allows the server superuser to overwrite a client stack buffer with an arbitrarily-l…
CVE-2026-45348High· 8.7pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
pyLoad is vulnerable to stored XSS in Downloads view via unsanitized link URL in packages.js template literal
CVE-2026-45315High· 8.7Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions
CVE-2026-45400High· 8.5Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
CVE-2026-45331High· 8.5Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
Open WebUI has a full SSRF Vulnerability in the RAG Web Search Feature
Most-affected vendors
By CVEs published in the period.