|
1021
|
6.5 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, POST /api/chat/completions accepts an image_url.url value that, when it does NOT sta…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-54009
|
2026-06-25 22:35 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1022
|
8.3 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets an authenticated user attach arbitrary file_id values to their own c…
New
|
CWE-284 CWE-639 CWE-862
Improper Access Control Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2026-54010
|
2026-06-25 22:34 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1023
|
5.4 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6,Open WebUI renders Mermaid blocks from Markdown files in the file preview panel and i…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-54011
|
2026-06-25 22:33 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1024
|
8.8 |
HIGH
Network
|
-
|
-
|
The Email Address Encoder WordPress plugin before 1.0.25, email-encoder-premium WordPress plugin before 0.3.12 does not properly handle email replacement, which could allow unauthenticated users to p…
New
|
-
|
CVE-2026-5305
|
2026-06-25 22:28 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1025
|
7.5 |
HIGH
Network
|
-
|
-
|
The InPost PL WordPress plugin before 1.9.1 does not verify that the request originates from the legitimate buyer before allowing the WooCommerce order parcel-locker destination to be updated, allowi…
New
|
-
|
CVE-2026-9702
|
2026-06-25 22:28 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1026
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may a…
New
|
CWE-782
Exposed IOCTL with Insufficient Access Control
|
CVE-2026-56129
|
2026-06-25 22:28 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1027
|
- |
|
-
|
-
|
Improper Handling of Insufficient Permissions or Privileges vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: 2.8.0.
Users are recommended to upgrade to version 2.16.0, which fixe…
New
|
CWE-280
Improper Handling of Insufficient Permissions or Privileges
|
CVE-2026-41566
|
2026-06-25 22:27 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1028
|
- |
|
-
|
-
|
Relative Path Traversal vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from 1.0.0 through 2.15.0.
Users are recommended to upgrade to version 2.16.0, which fixes the issue.
New
|
CWE-23
Relative Path Traversal
|
CVE-2026-45188
|
2026-06-25 22:27 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1029
|
- |
|
-
|
-
|
A vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from 2.2.0 through 2.15.0.
Users are recommended to upgrade to version 2.16.0, which fixes the issue.
New
|
-
|
CVE-2026-46751
|
2026-06-25 22:27 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1030
|
- |
|
-
|
-
|
Redis Lua HEAP overflow in cjson library vulnerability in Apache Kvrocks.
This issue affects Apache Kvrocks: from 2.0.4 through 2.15.0.
Users are recommended to upgrade to version 2.16.0, which fix…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-46752
|
2026-06-25 22:27 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|