VulnSea

Tagged “osv”

CVEs tagged osv, newest first.

5683 CVEsRSS

CVE-2026-8754Medium· 6.3
4mo ago

AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py

AstrBot: File upload vulnerability in the function post_file of the file astrbot/dashboard/routes/chat.py

▾ Sunlitastrbot · astrbotEPSS 0.43%via OSV
CVE-2026-46383Medium· 5.5
4mo ago

Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`

Microsoft APM: Windows absolute-path tar member overwrite during legacy-bundle probing in `apm install`

▾ Sunlitapm-cli · apm-cliEPSS 0.90%via OSV
CVE-2026-2652High· 8.6PoC
4mo ago

MLflow: unauthenticated access to certain FastAPI routes

MLflow: unauthenticated access to certain FastAPI routes

▾ Midnightmlflow · mlflowEPSS 1.4%via OSV
CVE-2026-45106Medium· 4.6
4mo ago

Weblate: Stored HTML injection in editor search preview

Weblate: Stored HTML injection in editor search preview

▾ Sunlitweblate · weblateEPSS 0.29%via OSV
CVE-2026-44716High· 7.5
4mo ago

Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator

Pipecat: Path Traversal in Pipecat Runner `/files` Endpoint — Arbitrary File Read via `%2F`-Encoded Separator

▾ Twilightpipecat-ai · pipecat-aiEPSS 0.56%via OSV
CVE-2026-45078Medium· 5.5
4mo ago

Synapse CPU starvation (Denial of Service)

Synapse CPU starvation (Denial of Service)

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.13%via OSV
CVE-2026-45076Medium
4mo ago

Synapse pagination Denial of Service

Synapse pagination Denial of Service

▾ Sunlitmatrix-synapse · matrix-synapseEPSS 0.39%via OSV
CVE-2026-44513High· 8.8
4mo ago

Diffusers is the a library for pretrained diffusion models

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user passing trust_remote_code=False (or omi…

▾ Twilighthuggingface · diffusersEPSS 0.89%via NVD
CVE-2026-18676Medium
4mo ago

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin

▾ Sunlitkumahq · github.com/kumahq/kumaEPSS 0.30%via OSV
CVE-2026-44283Medium· 4.3⚖ disputed
4mo ago

etcd: etcd: Authenticated user can bypass RBAC for unauthorized data access (CVE-2026-44283)

A flaw was found in etcd, a distributed key-value store. An authenticated user, without sufficient read or lease-related permissions, could bypass Role-Based Access Control (RBAC) authorization checks. This bypass occurs during transaction…

▾ SunlitRed Hat · Red Hat OpenStack Platform 16.2EPSS 0.27%via CSAF
CVE-2026-45021Medium
4mo ago

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin

Default kuma-cp leaks admin token cross-origin via CORS wildcard + LocalhostIsAdmin

▾ Sunlitkumahq · github.com/kumahq/kumaEPSS 0.30%via OSV
CVE-2026-45339Medium· 6.5
4mo ago

Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints

Open WebUI's API key endpoint restrictions bypassed via `x-api-key` header — full message processing on restricted endpoints

▾ Sunlitopen-webu · open-webuEPSS 0.44%via OSV
CVE-2026-46428None
4mo ago

TLS hostname verification disabled when using Boring TLS backend

TLS hostname verification disabled when using Boring TLS backend

▾ Sunlitlettre · lettreEPSS 0.32%via OSV
CVE-2026-8634Critical· 9.1
4mo ago

Crabbox: environment variable exposure vulnerability

Crabbox: environment variable exposure vulnerability

▾ Midnightopenclaw · github.com/openclaw/crabboxEPSS 1.0%via OSV
CVE-2026-56398High· 7.3
4mo ago

Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url

Open WebUI vulnerable to stored XSS via OAuth picture claim stored as SVG data URI in profile_image_url

▾ Twilightopen-webui · open-webuiEPSS 0.64%via OSV
CVE-2026-44968Medium· 6.3
4mo ago

dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters

dbt MCP Server has an Argument Injection in dbt CLI Tool Wrappers via node_selection and resource_type Parameters

▾ Sunlitdbt-mcp · dbt-mcpEPSS 0.21%via OSV
CVE-2026-45666Medium· 6.5
4mo ago

Open WebUI has an Indirect Object Reference (IDOR) in user notes

Open WebUI has an Indirect Object Reference (IDOR) in user notes

▾ Sunlitopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-45385Medium· 4.3
4mo ago

Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint

Open WebUI has an IDOR vulnerability in the update_message_by_id API endpoint

▾ Sunlitopen-webui · open-webuiEPSS 0.29%via OSV
CVE-2026-45306Medium· 6.5
4mo ago

pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad

pyLoad Has Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory in pyLoad

▾ Sunlitpyload-ng · pyload-ngEPSS 0.41%via OSV
CVE-2026-45365Medium· 5.4
4mo ago

Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]

Open WebUI: Authenticated users can bypass model access control via exposed query parameter [AI-ASSISTED]

▾ Sunlitopen-webui · open-webuiEPSS 0.27%via OSV
CVE-2026-45396Medium· 5.4
4mo ago

Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation

Open WebUI: Mass Assignment via FeedbackForm extra=allow Allows Feedback User ID Spoofing and Evaluation Data Manipulation

▾ Sunlitopen-webui · open-webuiEPSS 0.36%via OSV
CVE-2026-45401High· 8.5PoC
4mo ago

Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)

Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)

▾ Midnightopen-webui · open-webuiEPSS 0.33%via OSV
CVE-2026-45301High· 8.1
4mo ago

Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file

Open WebUI: Missing permission check in files API allows authenticated users to list, access and delete every uploaded file

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-45402High· 8.1
4mo ago

Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints

Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints

▾ Twilightopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-45315High· 8.7
4mo ago

Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions

Open WebUI has stored XSS via attacker-controlled file extension in /api/v1/audio/transcriptions

▾ Twilightopen-webui · open-webuiEPSS 0.19%via OSV
CVE-2026-45667Medium· 6.5
4mo ago

Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)

Open WebUI: Unauthenticated endpoint can trigger embedding generation (cost/DoS)

▾ Sunlitopen-webui · open-webuiEPSS 0.43%via OSV
CVE-2026-45316Low· 3.5PoC
4mo ago

Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)

Open WebUI: Read-Only Users Can Toggle Note Pin Status via Incorrect Permission Check (Write via Read-Only Access)

▾ Twilightopen-webui · open-webuiEPSS 0.26%via OSV
CVE-2026-44970Low· 3.1
4mo ago

dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction

dbt MCP Server Transmits All MCP Tool Arguments Including Raw SQL and --vars Credentials to dbt Labs Telemetry by Default Without Redaction

▾ Sunlitdbt-mcp · dbt-mcpEPSS 0.37%via OSV
CVE-2026-45351Medium· 6.5
4mo ago

Open WebUI Exposes System Prompt to Regular User [Non-Admin]

Open WebUI Exposes System Prompt to Regular User [Non-Admin]

▾ Sunlitopen-webui · open-webuiEPSS 0.39%via OSV
CVE-2026-45317Medium· 4.6
4mo ago

Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation

Open WebUI Vulnerable to Cross-Site Request Forgery (CSRF) via Image URL Manipulation

▾ Sunlitopen-webui · open-webuiEPSS 0.15%via OSV
CVEs tagged “osv” — page 62 · VulnSea