|
791
|
6.5 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, GET /api/v1/memories/ef is accessible without authentication and executes request.ap…
Update
|
CWE-862
Missing Authorization
|
CVE-2026-45667
|
2026-05-19 10:28 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
792
|
6.5 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.11, the API /api/v1/notes/{note_id} endpoint lacks proper authorization checks, allowin…
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45666
|
2026-05-19 10:28 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
793
|
8.1 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component due…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-45665
|
2026-05-19 10:28 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
794
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based …
Update
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-8733
|
2026-05-19 06:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
795
|
4.7 |
MEDIUM
Network
|
-
|
-
|
SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redire…
New
|
CWE-601
Open Redirect
|
CVE-2025-65954
|
2026-05-19 06:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
796
|
- |
|
-
|
-
|
* Countermeasures for DPA within SYMCRYPTO
engine on SixG301xxx devices are not sufficiently random and will
eventually repeat.
* KSU keys using SYMCRYPTO will be
impacted by this vulnerability.
Update
|
CWE-331
Insufficient Entropy
|
CVE-2025-14972
|
2026-05-19 05:27 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
797
|
8.2 |
HIGH
Network
|
-
|
-
|
A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control fu…
Update
|
CWE-124
Buffer Underflow
|
CVE-2026-34253
|
2026-05-19 05:23 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
798
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-38728
|
2026-05-19 05:23 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
799
|
4.6 |
MEDIUM
Network
|
-
|
-
|
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-21789
|
2026-05-19 05:23 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
800
|
8.2 |
HIGH
Local
|
-
|
-
|
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
Update
|
CWE-346
Origin Validation Error
|
CVE-2026-46728
|
2026-05-19 05:23 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|