2026-05-17
2026-05-17 13:16Z
CRIT

CVE-2018-25320 — ACL: Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2018-25320

ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can use bitsadmin to download malicious PowerShell scripts and execute them with system privileges to establish reverse shells and gain complete system control. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94VNDAclTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-17
2026-05-17 04:16Z
HIGH

CVE-2026-8719 — Engine: The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8719

The AI Engine – The Chatbot, AI Framework & MCP for WordPress plugin for WordPress is vulnerable to Privilege Escalation in version 3.4.9. This is due to missing WordPress capability enforcement in the MCP OAuth bearer-token authorization path, where any valid OAuth token causes MCP access to be granted without verifying administrator privileges. This makes it possible for authenticated (Subscriber+) attackers to invoke admin-level MCP tools and escalate privileges to Adminis CVSSv3.1 8.8 (HIGH)

CWECWE 269VNDEngineTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-16
2026-05-16 22:16Z
HIGH

CVE-2026-46728 — Das: U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-46728

Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash. CVSSv3.1 8.2 (HIGH)

CWECWE 346VNDDasTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-16
2026-05-16 16:16Z
HIGH

CVE-2021-47979 — WordPress: Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-47979

WordPress Plugin Backup and Restore 1.0.3 contains an arbitrary file deletion vulnerability that allows authenticated attackers to delete files by manipulating parameters in AJAX requests. Attackers can send POST requests to admin-ajax.php with crafted file_name and folder_name parameters to delete arbitrary files from the WordPress installation directory. CVSSv3.1 8.8 (HIGH)

CWECWE 22VNDWordpressTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-16
2026-05-16 16:16Z
HIGH

CVE-2021-47976 — TextPattern: CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-47976

TextPattern CMS 4.9.0-dev contains a remote code execution vulnerability that allows authenticated attackers to upload arbitrary PHP files by exploiting the plugin upload functionality. Attackers can authenticate, retrieve a CSRF token from the plugin event page, and upload malicious PHP files to the textpattern/tmp/ directory for code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 352VNDTextpatternTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-16
2026-05-16 16:16Z
HIGH

CVE-2021-47956 — EgavilanMedia: PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-47956

EgavilanMedia PHPCRUD 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the firstname parameter. Attackers can send POST requests to insert.php with malicious firstname values to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDEgavilanmediaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-16
2026-05-16 16:16Z
HIGH

CVE-2021-47954 — LayerBB: 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-47954

LayerBB 1.1.4 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the search_query parameter. Attackers can send POST requests to /search.php with malicious search_query values using CASE WHEN statements to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDLayerbbTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-05-16
2026-05-16 16:16Z
CRIT

CVE-2021-47952 — python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2021-47952

python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py/repr directives that invoke the eval function during deserialization to execute system commands and arbitrary code. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-16
2026-05-16 16:16Z
HIGH

CVE-2020-37244 — Supsystic: Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2020-37244

Supsystic Membership 1.4.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'search' and 'sidx' parameters. Attackers can send GET requests to the badges module with crafted payloads to extract sensitive database information using time-based blind or UNION-based SQL injection techniques. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDSupsysticTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-16
2026-05-16 16:16Z
HIGH

CVE-2020-37243 — Supsystic: Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2020-37243

Supsystic Pricing Table 1.8.7 contains an SQL injection vulnerability in the 'sidx' GET parameter that allows unauthenticated attackers to execute arbitrary SQL queries through the getListForTbl action. The plugin also contains stored cross-site scripting vulnerabilities in the 'Edit name' and 'Edit HTML' fields that execute malicious scripts when viewing pricing tables. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDSupsysticTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-16
2026-05-16 16:16Z
HIGH

CVE-2020-37242 — Supsystic: Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2020-37242

Supsystic Ultimate Maps 1.1.12 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the 'sidx' GET parameter. Attackers can send crafted requests to the getListForTbl action with boolean-based blind or time-based blind SQL injection payloads to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDSupsysticTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-16
2026-05-16 16:16Z
CRIT

CVE-2020-37239 — libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2020-37239

libbabl 0.1.62 contains a broken double free detection vulnerability that allows attackers to bypass memory safety checks by exploiting signature overwriting in freed chunks. Attackers can call babl_free() twice on the same pointer without triggering detection, as libc's malloc metadata overwrites babl's signature field upon freeing, enabling potential memory corruption and code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 415TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-16
2026-05-16 16:16Z
CRIT

CVE-2020-37228 — DSSPro: iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2020-37228

iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retrieve valid CAPTCHA codes via the login endpoint and use them to perform brute-force attacks against user accounts. CVSSv3.1 9.8 (CRITICAL)

CWECWE 307VNDDssproTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-16
2026-05-16 16:16Z
HIGH

CVE-2020-37227 — Brand: HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2020-37227

HS Brand Logo Slider 2.1 contains an unrestricted file upload vulnerability that allows authenticated users to bypass client-side file extension validation by uploading arbitrary files. Attackers can intercept upload requests to the logoupload parameter in the admin interface and rename files to executable extensions .php to achieve remote code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 434VNDBrandTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-16
2026-05-16 10:38Z
HIGH

Pwn2Own Berlin 2026: Day Three Results and Master of Pwn

Zero Day Initiative·thezdi.com0day

Pwn2Own Berlin 2026 Day Three concluded with multiple zero-day exploits demonstrated against Windows 11, Red Hat Linux, and ESXi. Researchers earned $908,750+ across 39 unique zero days, with notable wins including an integer overflow privilege escalation on Windows 11 by Viettel Cyber Security and a Red Hat Linux exploit by Summoning Team.

SRFOsOSLinuxOSWindowsVNDMicrosoftVNDVmwareTYPVulnerabilityTYPNewsEXPPrivilege Escalation
62
Edit Score
2026-05-16
2026-05-16 06:16Z
HIGH

CVE-2026-8657 — Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-8657

Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform prototype pollution by supplying crafted delta or JSON Patch documents, as attacker-controlled property names and path segments are used to traverse and modify objects without restricting access to special properties like __proto__ or constructor.prototype, allowing modification of O CVSSv3.1 8.2 (HIGH)

CWECWE 1321TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-05-15
2026-05-15 22:16Z
HIGH

CVE-2026-45665 — Open: Prior to 0.8.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45665

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in the Banner component due to an improper sanitization order (specifically, DOMPurify is executed before the marked library). This vulnerability allows a compromised or malicious administrator to plant a malicious payload in the global banner. Crucially, this vector enables Privilege Escalation, as the mal CVSSv3.1 8.1 (HIGH)

CWECWE 79TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-15
2026-05-15 22:16Z
HIGH

CVE-2026-45315 — Open: Prior to 0.9.3, the audio transcription upload endpoint takes the file extension from the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45315

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the audio transcription upload endpoint takes the file extension from the user-supplied filename and saves the file under CACHE_DIR/audio/transcriptions/.. The /cache/{path} route serves these files via FileResponse, which sets Content-Type from the on-disk extension and emits no Content-Disposition. A verified user with the default-on chat.stt permission can upl CVSSv3.1 8.7 (HIGH)

CWECWE 434CWECWE 79CWECWE 646TYPVulnerability
8.7
CVSS v3.1
94
Edit Score
2026-05-15
2026-05-15 22:16Z
HIGH

CVE-2026-45301 — Open: Prior to 0.3.16, a missing permission check in all files related API endpoints allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45301

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.3.16, a missing permission check in all files related API endpoints allows any authenticated user to list, access and delete every file uploaded by every user to the platform. This vulnerability is fixed in 0.3.16. CVSSv3.1 8.1 (HIGH)

CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-15
2026-05-15 22:16Z
HIGH

CVE-2026-44570 — Open: Similarly, even if a non-admin user cannot modify another user's memory data via POST

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44570

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.19, authorization controls surrounding the memories API were inconsistent, resulting in the ability of a standard user to delete, restore, and view the contents of other users' memories. Using a newly created non-admin user with no existing memories, it is possible to view existing memories via POST /api/v1/memories/query. Similarly, even if a non-admin user cannot CVSSv3.1 8.3 (HIGH)

CWECWE 639TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-05-15
2026-05-15 22:16Z
HIGH

CVE-2026-44565 — Open: This allows for users to upload files with names containing dot-segments in the file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44565

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.6.10, when uploading an audio file, the name of the file is derived from the original HTTP upload request and is not validated or sanitized. This allows for users to upload files with names containing dot-segments in the file path and traverse out of the intended uploads directory. Effectively, users can upload files anywhere on the filesystem the user running the web CVSSv3.1 8.1 (HIGH)

CWECWE 22TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-15
2026-05-15 21:16Z
HIGH

CVE-2026-45672 — Open: Prior to 0.8.12, the /api/v1/utils/code/execute endpoint executes arbitrary Python code via Jupyter for any

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45672

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.8.12, the /api/v1/utils/code/execute endpoint executes arbitrary Python code via Jupyter for any verified user, even when the admin has set ENABLE_CODE_EXECUTION=false. The feature gate is not enforced on the API endpoint — the configuration says "disabled" but code still executes. This vulnerability is fixed in 0.8.12. CVSSv3.1 8.8 (HIGH)

CWECWE 863TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-15
2026-05-15 21:16Z
HIGH

CVE-2026-45402 — Open: Prior to 0.9.5, multiple endpoints accept a user-supplied file_id and attach the referenced file

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45402

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, multiple endpoints accept a user-supplied file_id and attach the referenced file to a resource the caller controls (folder knowledge, knowledge-base contents) without verifying that the caller owns or has been granted access to the file. The file's content then becomes reachable through the downstream RAG / file-content paths, allowing any authenticated user to e CVSSv3.1 8.1 (HIGH)

CWECWE 639TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-15
2026-05-15 21:16Z
HIGH

CVE-2026-45401 — Open: Prior to 0.9.5, the validate_url() function in backend/open_webui/retrieval/web/utils.py only validates the initial URL submitted

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45401

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, the validate_url() function in backend/open_webui/retrieval/web/utils.py only validates the initial URL submitted by the caller. The HTTP clients used downstream (sync requests, async aiohttp, langchain's WebBaseLoader) follow HTTP 3xx redirects by default and do not re-validate the redirect target against the private-IP / metadata-IP block list. Any authenticate CVSSv3.1 8.5 (HIGH)

CWECWE 918TYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-05-15
2026-05-15 21:16Z
HIGH

CVE-2026-45400 — Open: Prior to 0.9.5, a parsing difference between the urlparse and requests libraries led to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45400

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.5, a parsing difference between the urlparse and requests libraries led to an SSRF bypass vulnerability. This vulnerability is fixed in 0.9.5. CVSSv3.1 8.5 (HIGH)

CWECWE 918TYPVulnerability
8.5
CVSS v3.1
93
Edit Score