opencve vulnerabilities
CVEs whose affected-version data names the opencve package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-62282Medium· 6.5PoCOpenCVE is a vulnerability intelligence platform
OpenCVE is a vulnerability intelligence platform. Prior to 3.0.0, OpenCVE notification testing for Webhook and Slack integrations does not sufficiently validate user-supplied HTTP or HTTPS destinations. An authenticated user with permiss…
▾ Twilightopencve · opencveEPSS 0.33%via NVD
CVE-2026-92764Medium· 4.3OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships
OpenCVE before 3.1.0 fails to properly scope the organizations API endpoint to the token's organization, instead returning the token creator's memberships. Attackers with organization-scoped tokens can list and retrieve every organizatio…
▾ Sunlitopencve · opencveEPSS 0.30%via NVD