VulnSea

nesquena has 4 CVEs on record. The busiest recent month was June 2026 with 4. The median CVSS is 6.5 (medium).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
0 prev 4

Products

  • hermes-webui 4
4
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

nesquena vulnerabilities

CVEs affecting nesquena, newest first. Open any entry for full detail, references, and exploit status.

4 CVEsRSS

CVE-2026-55205Medium· 5.3PoC
3mo ago

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads

Hermes WebUI before 0.51.468 contains a resource exhaustion vulnerability in the unauthenticated POST /api/onboarding/oauth/start endpoint that allows unbounded accumulation of in-memory flow state and daemon threads. Attackers can send …

Twilightnesquena · hermes-webuiEPSS 0.37%via NVD
CVE-2026-55198Medium· 6.5PoC
3mo ago

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles

Hermes WebUI before 0.51.443 contains an authorization bypass vulnerability in the session export endpoint that allows authenticated users to access sessions from other profiles. The _handle_session_export handler in api/routes.py fails …

Twilightnesquena · hermes-webuiEPSS 0.27%via NVD
CVE-2026-55197Medium· 6.5PoC
3mo ago

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts

Hermes WebUI before 0.51.443 contains a broken access control vulnerability in the /api/session endpoint that allows authenticated users to disclose cross-profile session transcripts. Attackers can bypass profile boundary checks by direc…

Twilightnesquena · hermes-webuiEPSS 0.27%via NVD
CVE-2026-53871High· 8.1
3mo ago

Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie

Hermes WebUI before 0.51.368 contains an authorization bypass vulnerability in the get_profile_cookie() function that accepts unauthenticated profile names from the hermes_profile cookie. An authenticated attacker can forge the hermes_pr…

Twilightnesquena · hermes-webuiEPSS 0.36%via NVD
nesquena vulnerabilities (CVEs) · VulnSea