Vendor Intelligence
pip
114 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.
CVE-2026-33760 · CVSS 8.8
Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints
View CVE report →
CVE-2026-40217 · CVSS 8.8
LiteLLM has a sandbox escape in custom-code guardrail
View CVE report →
CVE-2026-42305 · CVSS 8.8
Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows
View CVE report →
CVE-2026-44513 · CVSS 8.8
Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components
View CVE report →
CVE-2026-45672 · CVSS 8.8
Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed
View CVE report →
CVE-2026-47399 · CVSS 8.8
PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID
View CVE report →
CVE-2026-47405 · CVSS 8.8
PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership
View CVE report →
CVE-2026-48169 · CVSS 8.8
PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API
View CVE report →
CVE-2026-48508 · CVSS 8.8
Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission
View CVE report →
CVE-2026-54449 · CVSS 8.8
LangBot: Authenticated RCE Via MCP Configuration
View CVE report →
CVE-2026-44552 · CVSS 8.7
Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning
View CVE report →
CVE-2026-54011 · CVSS 8.7
Open WebUI: Stored XSS in Mermaid Markdown Preview
View CVE report →
CVE-2026-42079 · CVSS 8.6
PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope
View CVE report →
CVE-2026-42352 · CVSS 8.6
pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber
View CVE report →
CVE-2026-44023 · CVSS 8.6
Docling Core: Unsafe remote filename resolution
View CVE report →
CVE-2026-44339 · CVSS 8.6
PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute
View CVE report →
CVE-2026-53755 · CVSS 8.6
Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check
View CVE report →
CVE-2026-44797 · CVSS 8.5
Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)
View CVE report →
CVE-2026-45400 · CVSS 8.5
Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`
View CVE report →
CVE-2026-45401 · CVSS 8.5
Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)
View CVE report →
CVE-2026-54008 · CVSS 8.5
Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)
View CVE report →
CVE-2026-44334 · CVSS 8.4
PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)
View CVE report →
CVE-2026-46345 · CVSS 8.4
compliance-trestle - jinja has an Arbitrary File Write via Path Traversal
View CVE report →
CVE-2026-54447 · CVSS 8.4
garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store
View CVE report →
CVE-2026-55786 · CVSS 8.4
flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`
View CVE report →
CVE-2026-42313 · CVSS 8.3
pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy via unrestricted `proxy.*` config (incomplete fix for CVE-2026-33509 / -35463 / -35464 / -35586)
View CVE report →
CVE-2026-47415 · CVSS 8.3
praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR
View CVE report →
CVE-2026-47419 · CVSS 8.3
praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR
View CVE report →
CVE-2026-49471 · CVSS 8.3
Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE
View CVE report →
CVE-2026-50574 · CVSS 8.3
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
View CVE report →
CVE-2026-54010 · CVSS 8.3
Open WebUI: Forged chat-file link allows cross-user file read and deletion
View CVE report →
CVE-2026-44016 · CVSS 8.2
Docling: Unsafe Playwright-based HTML Rendering
View CVE report →
CVE-2026-44843 · CVSS 8.2
LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists
View CVE report →
CVE-2026-49825 · CVSS 8.2
`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes
View CVE report →
CVE-2026-59197 · CVSS 8.2
Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`
View CVE report →
CVE-2026-42315 · CVSS 8.1
PyLoad vulnerable to Path Traversal via Package Folder Name in set_package_data
View CVE report →
CVE-2026-44019 · CVSS 8.1
Docling Core: Insufficient validation of image reference URIs
View CVE report →
CVE-2026-44304 · CVSS 8.1
Lemur: LDAP Filter Injection enables post-authentication privilege escalation
View CVE report →
CVE-2026-44553 · CVSS 8.1
Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access
View CVE report →
CVE-2026-44554 · CVSS 8.1
Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite
View CVE report →
CVE-2026-44565 · CVSS 8.1
Open WebUI Arbitrary File Write, Delete via Path Traversal
View CVE report →
CVE-2026-45402 · CVSS 8.1
Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints
View CVE report →
CVE-2026-45675 · CVSS 8.1
Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts
View CVE report →
CVE-2026-47398 · CVSS 8.1
PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334
View CVE report →
CVE-2026-47406 · CVSS 8.1
praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks
View CVE report →
CVE-2026-47409 · CVSS 8.1
praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role
View CVE report →
CVE-2026-47412 · CVSS 8.1
praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}
View CVE report →
CVE-2026-47417 · CVSS 8.1
praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR
View CVE report →
CVE-2026-47418 · CVSS 8.1
praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR
View CVE report →
CVE-2026-48060 · CVSS 8.1
Litestar has HTML Injection Through its CSRF Token
View CVE report →
CVE-2026-49291 · CVSS 8.1
mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call
View CVE report →
CVE-2026-54446 · CVSS 8.1
NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode
View CVE report →
CVE-2026-54771 · CVSS 8.1
Langroid: handle_message() executes user-supplied tool JSON without sender verification
View CVE report →
CVE-2026-61668 · CVSS 8.1
DIRAC: Pilot code downloaded over unverified HTTPS connection
View CVE report →
CVE-2026-45671 · CVSS 8
Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion
View CVE report →
CVE-2026-54552 · CVSS 7.9
sh _uid does not drop supplementary groups (incomplete privilege drop)
View CVE report →
CVE-2022-44451 · CVSS 7.8
Open Babel has uninitialized pointer dereference in MSI atom parser
View CVE report →
CVE-2022-46280 · CVSS 7.8
Open Babel has uninitialized pointer dereference in PQS pFormat
View CVE report →
CVE-2022-46289 · CVSS 7.8
Open Babel has out-of-bounds write in ORCA nAtoms parser
View CVE report →
CVE-2022-46290 · CVSS 7.8
Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)
View CVE report →
CVE-2022-46291 · CVSS 7.8
Open Babel has out-of-bounds write in Gaussian translationVectors[]
View CVE report →
CVE-2022-46292 · CVSS 7.8
Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)
View CVE report →
CVE-2022-46293 · CVSS 7.8
Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)
View CVE report →
CVE-2022-46294 · CVSS 7.8
Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)
View CVE report →
CVE-2022-46295 · CVSS 7.8
Open Babel has out-of-bounds write in MSI translationVectors[]
View CVE report →
CVE-2025-10996 · CVSS 7.8
Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles
View CVE report →
CVE-2026-42301 · CVSS 7.8
pyp2spec is Vulnerable to Code Injection
View CVE report →
CVE-2026-44244 · CVSS 7.8
GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
View CVE report →
CVE-2026-46432 · CVSS 7.8
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
View CVE report →
CVE-2026-46439 · CVSS 7.8
compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)
View CVE report →
CVE-2026-46517 · CVSS 7.8
lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
View CVE report →
CVE-2026-46606 · CVSS 7.8
Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py
View CVE report →
CVE-2026-46607 · CVSS 7.8
Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution
View CVE report →
CVE-2026-53925 · CVSS 7.8
Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration
View CVE report →
CVE-2026-54071 · CVSS 7.8
BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py
View CVE report →
CVE-2026-55426 · CVSS 7.8
Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command
View CVE report →
CVE-2026-21887 · CVSS 7.7
OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature
View CVE report →
CVE-2026-33079 · CVSS 7.5
Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input
View CVE report →
CVE-2026-33441 · CVSS 7.5
Mistune has a Denial-of-Service (DoS) vulnerability
View CVE report →
CVE-2026-40110 · CVSS 7.5
Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` (from huntr)
View CVE report →
CVE-2026-41523 · CVSS 7.5
vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution
View CVE report →
CVE-2026-41895 · CVSS 7.5
changedetection.io project has an XXE vulnerability
View CVE report →
CVE-2026-42031 · CVSS 7.5
CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`
View CVE report →
CVE-2026-42311 · CVSS 7.5
Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)
View CVE report →
CVE-2026-42351 · CVSS 7.5
pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider
View CVE report →
CVE-2026-43891 · CVSS 7.5
changedetection.io has an Arbitrary Local File Read via a crafted backup restore
View CVE report →
CVE-2026-44017 · CVSS 7.5
Docling: Unsafe Zip Extraction in EasyOCR Model Download
View CVE report →
CVE-2026-44209 · CVSS 7.5
banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI
View CVE report →
CVE-2026-44335 · CVSS 7.5
PraisonAI has an SSRF bypass
View CVE report →
CVE-2026-45725 · CVSS 7.5
compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal
View CVE report →
CVE-2026-45727 · CVSS 7.5
CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion
View CVE report →
CVE-2026-45804 · CVSS 7.5
Diffusers: TOCTOU Trust Remote Code Bypass
View CVE report →
CVE-2026-47397 · CVSS 7.5
PraisonAI has an Arbitrary File Write in Python API
View CVE report →
CVE-2026-47764 · CVSS 7.5
PDM wheel installation leads to Path Traversal via overridden write_to_fs
View CVE report →
CVE-2026-48818 · CVSS 7.5
Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows
View CVE report →
CVE-2026-49852 · CVSS 7.5
joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)
View CVE report →
CVE-2026-50180 · CVSS 7.5
Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read
View CVE report →
CVE-2026-52817 · CVSS 7.5
Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get arguments
View CVE report →
CVE-2026-54134 · CVSS 7.5
OctoPrint has possible file exfiltration via query parameters on upload endpoints
View CVE report →
CVE-2026-54499 · CVSS 7.5
Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
View CVE report →
CVE-2026-55446 · CVSS 7.5
Langflow: Unauthenticated DoS through multipart form boundary file upload
View CVE report →
CVE-2026-59205 · CVSS 7.5
Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch
View CVE report →
CVE-2026-45539 · CVSS 7.4
Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents into the project tree
View CVE report →
CVE-2026-12530 · CVSS 7.3
Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()
View CVE report →
CVE-2026-26192 · CVSS 7.3
Open WebUI vulnerable to Stored XSS via iFrame in citations model
View CVE report →
CVE-2026-26193 · CVSS 7.3
Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages
View CVE report →
CVE-2026-44549 · CVSS 7.3
Open WebUI has stored XSS in Excel file preview
View CVE report →
CVE-2026-8596 · CVSS 7.2
Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path
View CVE report →
CVE-2026-35397 · CVSS 7.1
Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories
View CVE report →
CVE-2026-44556 · CVSS 7.1
Open WebUI's responses passthrough endpoint lacks access control authorization
View CVE report →
CVE-2026-44641 · CVSS 7.1
Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install
View CVE report →
CVE-2026-50181 · CVSS 7.1
Langroid: Path traversal in the file tools allows read/write outside configured current directory
View CVE report →
CVE-2026-55787 · CVSS 7.1
flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf
View CVE report →
CVE-2026-9291 · CVSS 7.1
amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads()
View CVE report →