Vendor Intelligence

pip

114 tracked CVEs · 0 in CISA KEV · 0 confirmed exploited in the wild.

CVE-2026-33760 · CVSS 8.8

Langflow: IDOR/BOLA in Monitor API — Missing Ownership Enforcement on 7 Endpoints

View CVE report →
CVE-2026-40217 · CVSS 8.8

LiteLLM has a sandbox escape in custom-code guardrail

View CVE report →
CVE-2026-42305 · CVSS 8.8

Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows

View CVE report →
CVE-2026-44513 · CVSS 8.8

Diffusers has a `trust_remote_code` bypass via `custom_pipeline` and local custom components

View CVE report →
CVE-2026-45672 · CVSS 8.8

Open WebUI: Jupyter code execution works despite `ENABLE_CODE_EXECUTION=false` — feature gate bypassed

View CVE report →
CVE-2026-47399 · CVSS 8.8

PraisonAI Platform workspace-scoped routes allow cross-workspace object access by global object ID

View CVE report →
CVE-2026-47405 · CVSS 8.8

PraisonAI Platform: Missing role checks let any workspace member become owner and control workspace membership

View CVE report →
CVE-2026-48169 · CVSS 8.8

PraisonAI has Cross-Workspace IDOR and Privilege Escalation via Platform API

View CVE report →
CVE-2026-48508 · CVSS 8.8

Lemur has an authorization bypass in StrictRolePermission / AuthorityCreatorPermission

View CVE report →
CVE-2026-54449 · CVSS 8.8

LangBot: Authenticated RCE Via MCP Configuration

View CVE report →
CVE-2026-44552 · CVSS 8.7

Open WebUI: Redis Cache Keys tool_servers and terminal_servers Missing Instance Prefix Enable Cross-Instance Cache Poisoning

View CVE report →
CVE-2026-54011 · CVSS 8.7

Open WebUI: Stored XSS in Mermaid Markdown Preview

View CVE report →
CVE-2026-42079 · CVSS 8.6

PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins in Scope

View CVE report →
CVE-2026-42352 · CVSS 8.6

pygeoapi 0.23.x: Unauthenticated SSRF via OGC API - Processes Subscriber

View CVE report →
CVE-2026-44023 · CVSS 8.6

Docling Core: Unsafe remote filename resolution

View CVE report →
CVE-2026-44339 · CVSS 8.6

PraisonAI has unsafe tool resolution in `ToolExecutionMixin.execute_tool`: undeclared `__main__` callables execute

View CVE report →
CVE-2026-53755 · CVSS 8.6

Crawl4AI: SSRF via proxy settings in the Docker server bypasses the crawl-URL SSRF check

View CVE report →
CVE-2026-44797 · CVSS 8.5

Nautobot: Webhook definitions could be used for server-side request forgery (SSRF)

View CVE report →
CVE-2026-45400 · CVSS 8.5

Open WebUI has a Server-Side Request Forgery (SSRF) bypass in `validate_url`

View CVE report →
CVE-2026-45401 · CVSS 8.5

Open WebUI has a SSRF Bypass via HTTP Redirect Following in Web-Fetch and Image-Load Endpoints (not addressed by CVE-2025-65958)

View CVE report →
CVE-2026-54008 · CVSS 8.5

Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)

View CVE report →
CVE-2026-44334 · CVSS 8.4

PraisonAI has unauthenticated RCE via `tool_override.py` (CVE-2026-40287 patch bypass)

View CVE report →
CVE-2026-46345 · CVSS 8.4

compliance-trestle - jinja has an Arbitrary File Write via Path Traversal

View CVE report →
CVE-2026-54447 · CVSS 8.4

garminconnect Has Insecure Permission Assignment for Garmin OAuth Token Store

View CVE report →
CVE-2026-55786 · CVSS 8.4

flyto-core has Unauthenticated Command Execution via HTTP MCP `execute_module`

View CVE report →
CVE-2026-42313 · CVSS 8.3

pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker-controlled proxy via unrestricted `proxy.*` config (incomplete fix for CVE-2026-33509 / -35463 / -35464 / -35586)

View CVE report →
CVE-2026-47415 · CVSS 8.3

praisonai-platform: Issue endpoints accept any issue_id without workspace ownership check, cross-workspace read/update/delete IDOR

View CVE report →
CVE-2026-47419 · CVSS 8.3

praisonai-platform: Agent endpoints accept any agent_id without workspace ownership check, cross-workspace read/update/delete IDOR

View CVE report →
CVE-2026-49471 · CVSS 8.3

Serena: Unauthenticated Flask dashboard on fixed port enables DNS rebinding → memory poisoning → RCE

View CVE report →
CVE-2026-50574 · CVSS 8.3

yt-dlp: Arbitrary code execution via manifest downloads with aria2c

View CVE report →
CVE-2026-54010 · CVSS 8.3

Open WebUI: Forged chat-file link allows cross-user file read and deletion

View CVE report →
CVE-2026-44016 · CVSS 8.2

Docling: Unsafe Playwright-based HTML Rendering

View CVE report →
CVE-2026-44843 · CVSS 8.2

LangChain vulnerable to unsafe deserialization of attacker-controlled objects through overly broad `load()` allowlists

View CVE report →
CVE-2026-49825 · CVSS 8.2

`lxml_html_clean.Cleaner` does not strip `javascript:` URLs from namespaced URL attributes

View CVE report →
CVE-2026-59197 · CVSS 8.2

Pillow: Heap out-of-bounds write in `ImageFilter.RankFilter` via integer overflow in `ImagingExpand`

View CVE report →
CVE-2026-42315 · CVSS 8.1

PyLoad vulnerable to Path Traversal via Package Folder Name in set_package_data

View CVE report →
CVE-2026-44019 · CVSS 8.1

Docling Core: Insufficient validation of image reference URIs

View CVE report →
CVE-2026-44304 · CVSS 8.1

Lemur: LDAP Filter Injection enables post-authentication privilege escalation

View CVE report →
CVE-2026-44553 · CVSS 8.1

Open WebUI: Stale Admin Role in Socket.IO Session Pool Enables Post-Demotion Cross-User Note Access

View CVE report →
CVE-2026-44554 · CVSS 8.1

Open WebUI has Knowledge Base Destruction and RAG Poisoning via Unauthorized Collection Overwrite

View CVE report →
CVE-2026-44565 · CVSS 8.1

Open WebUI Arbitrary File Write, Delete via Path Traversal

View CVE report →
CVE-2026-45402 · CVSS 8.1

Open WebUI: Cross-User File Access via Unchecked file_id in Folder Knowledge and Knowledge-Base Attach Endpoints

View CVE report →
CVE-2026-45675 · CVSS 8.1

Open WebUI: LDAP and OAuth First-User Race Condition Allows Multiple Admin Accounts

View CVE report →
CVE-2026-47398 · CVSS 8.1

PraisonAI: Arbitrary code execution via unguarded `spec.loader.exec_module` in `agents_generator.py` - sibling of CVE-2026-44334

View CVE report →
CVE-2026-47406 · CVSS 8.1

praisonai-platform: IDOR in dependency endpoints allows cross-workspace issue linking, reading, and deletion due to missing ownership checks

View CVE report →
CVE-2026-47409 · CVSS 8.1

praisonai-platform: Missing authorization on member removal enables full workspace takeover by any user regardless of role

View CVE report →
CVE-2026-47412 · CVSS 8.1

praisonai-platform: Any workspace member can delete the entire workspace via DELETE /workspaces/{id}

View CVE report →
CVE-2026-47417 · CVSS 8.1

praisonai-platform: Comment endpoints accept any issue_id without workspace ownership check, cross-workspace comment read and post IDOR

View CVE report →
CVE-2026-47418 · CVSS 8.1

praisonai-platform: Project endpoints accept any project_id without workspace ownership check, cross-workspace read/update/delete IDOR

View CVE report →
CVE-2026-48060 · CVSS 8.1

Litestar has HTML Injection Through its CSRF Token

View CVE report →
CVE-2026-49291 · CVSS 8.1

mcp-memory-service: OAuth read-only clients can write and delete memories through MCP tools/call

View CVE report →
CVE-2026-54446 · CVSS 8.1

NetLicensing-MCP: Unauthenticated Use of Server-Side NetLicensing API Key in HTTP Mode

View CVE report →
CVE-2026-54771 · CVSS 8.1

Langroid: handle_message() executes user-supplied tool JSON without sender verification

View CVE report →
CVE-2026-61668 · CVSS 8.1

DIRAC: Pilot code downloaded over unverified HTTPS connection

View CVE report →
CVE-2026-45671 · CVSS 8

Open WebUI: shared-chat branch ignores access_type, allowing unauthorized file deletion

View CVE report →
CVE-2026-54552 · CVSS 7.9

sh _uid does not drop supplementary groups (incomplete privilege drop)

View CVE report →
CVE-2022-44451 · CVSS 7.8

Open Babel has uninitialized pointer dereference in MSI atom parser

View CVE report →
CVE-2022-46280 · CVSS 7.8

Open Babel has uninitialized pointer dereference in PQS pFormat

View CVE report →
CVE-2022-46289 · CVSS 7.8

Open Babel has out-of-bounds write in ORCA nAtoms parser

View CVE report →
CVE-2022-46290 · CVSS 7.8

Open Babel has out-of-bounds write in ORCA nAtoms parser (second variant)

View CVE report →
CVE-2022-46291 · CVSS 7.8

Open Babel has out-of-bounds write in Gaussian translationVectors[]

View CVE report →
CVE-2022-46292 · CVSS 7.8

Open Babel has out-of-bounds write in MOPAC translationVectors[] (UNIT CELL TRANSLATION)

View CVE report →
CVE-2022-46293 · CVSS 7.8

Open Babel has out-of-bounds write in MOPAC translationVectors[] (FINAL POINT)

View CVE report →
CVE-2022-46294 · CVSS 7.8

Open Babel has out-of-bounds write in MOPAC IN translationVectors[] (Tv atom)

View CVE report →
CVE-2022-46295 · CVSS 7.8

Open Babel has out-of-bounds write in MSI translationVectors[]

View CVE report →
CVE-2025-10996 · CVSS 7.8

Open Babel has heap buffer overflow in SMILES OBSmilesParser::ParseSmiles

View CVE report →
CVE-2026-42301 · CVSS 7.8

pyp2spec is Vulnerable to Code Injection

View CVE report →
CVE-2026-44244 · CVSS 7.8

GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath

View CVE report →
CVE-2026-46432 · CVSS 7.8

LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization

View CVE report →
CVE-2026-46439 · CVSS 7.8

compliance-trestle Vulnerable to Remote Code Execution via Recursive Server-Side Template Injection (SSTI)

View CVE report →
CVE-2026-46517 · CVSS 7.8

lmdeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out

View CVE report →
CVE-2026-46606 · CVSS 7.8

Glances is Vulnerable to Command Injection via KVM/QEMU VM Domain Names in glances/plugins/vms/engines/virsh.py

View CVE report →
CVE-2026-46607 · CVSS 7.8

Glances has Insecure Pickle Deserialization in its Version Cache that Leads to Arbitrary Code Execution

View CVE report →
CVE-2026-53925 · CVSS 7.8

Glances has arbitrary file write and command execution via `secure_popen` redirection and chaining operators in AMP command configuration

View CVE report →
CVE-2026-54071 · CVSS 7.8

BabelDOC: Arbitrary Code Execution via CMap Pickle Deserialization in babeldoc/pdfminer/cmapdb.py

View CVE report →
CVE-2026-55426 · CVSS 7.8

Linuxfabrik Monitoring Plugins have local privilege escalation using embedded command

View CVE report →
CVE-2026-21887 · CVSS 7.7

OpenCTI has Semi-Blind SSRF via Unvalidated External URL in Data Ingestion Feature

View CVE report →
CVE-2026-33079 · CVSS 7.5

Mistune has a ReDoS in LINK_TITLE_RE that allows denial of service via crafted Markdown input

View CVE report →
CVE-2026-33441 · CVSS 7.5

Mistune has a Denial-of-Service (DoS) vulnerability

View CVE report →
CVE-2026-40110 · CVSS 7.5

Jupyter Server has a CORS Origin Validation Bypass via `re.match()` in `allow_origin_pat` (from huntr)

View CVE report →
CVE-2026-41523 · CVSS 7.5

vLLM: Security Check Bypass via assert Statement in Activation Function Loading Allows Arbitrary Code Execution

View CVE report →
CVE-2026-41895 · CVSS 7.5

changedetection.io project has an XXE vulnerability

View CVE report →
CVE-2026-42031 · CVSS 7.5

CKAN has Unauthenticated SQL Injection and Authorization Bypass in `datastore_search_sql`

View CVE report →
CVE-2026-42311 · CVSS 7.5

Pillow has an OOB Write with Invalid PSD Tile Extents (Integer Overflow)

View CVE report →
CVE-2026-42351 · CVSS 7.5

pygeoapi 0.23.x: Path Traversal in STAC FileSystemProvider

View CVE report →
CVE-2026-43891 · CVSS 7.5

changedetection.io has an Arbitrary Local File Read via a crafted backup restore

View CVE report →
CVE-2026-44017 · CVSS 7.5

Docling: Unsafe Zip Extraction in EasyOCR Model Download

View CVE report →
CVE-2026-44209 · CVSS 7.5

banks has Critical Remote Code Execution (RCE) via Jinja2 SSTI

View CVE report →
CVE-2026-44335 · CVSS 7.5

PraisonAI has an SSRF bypass

View CVE report →
CVE-2026-45725 · CVSS 7.5

compliance-trestle Remote Fetching Mechanism has an Arbitrary File Write via Cache Path Traversal

View CVE report →
CVE-2026-45727 · CVSS 7.5

CloakBrowser: Unauthenticated path traversal via fingerprint parameter in cloakserve leads to arbitrary directory deletion

View CVE report →
CVE-2026-45804 · CVSS 7.5

Diffusers: TOCTOU Trust Remote Code Bypass

View CVE report →
CVE-2026-47397 · CVSS 7.5

PraisonAI has an Arbitrary File Write in Python API

View CVE report →
CVE-2026-47764 · CVSS 7.5

PDM wheel installation leads to Path Traversal via overridden write_to_fs

View CVE report →
CVE-2026-48818 · CVSS 7.5

Starlette: SSRF and NTLM credential theft via UNC paths in StaticFiles on Windows

View CVE report →
CVE-2026-49852 · CVSS 7.5

joserfc: HS256/HS384/HS512 verify accepts empty/nil HMAC key (cross-language sibling of CVE-2026-45363)

View CVE report →
CVE-2026-50180 · CVSS 7.5

Langroid: SQLChatAgent _validate_query blocklist misses pg_read_file family enabling arbitrary file read

View CVE report →
CVE-2026-52817 · CVSS 7.5

Linuxfabrik Monitoring Plugins: Sudoers may be able to obtain privilege escalation via /usr/bin/apt-get arguments

View CVE report →
CVE-2026-54134 · CVSS 7.5

OctoPrint has possible file exfiltration via query parameters on upload endpoints

View CVE report →
CVE-2026-54499 · CVSS 7.5

Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders

View CVE report →
CVE-2026-55446 · CVSS 7.5

Langflow: Unauthenticated DoS through multipart form boundary file upload

View CVE report →
CVE-2026-59205 · CVSS 7.5

Pillow: Controlled heap out-of-bounds write in Pillow `ImageCmsTransform.apply()` via output mode mismatch

View CVE report →
CVE-2026-45539 · CVSS 7.4

Microsoft APM: Symlinks under `.apm/prompts/` and `.apm/agents/` are dereferenced during `apm install`, copying host-local file contents into the project tree

View CVE report →
CVE-2026-12530 · CVSS 7.3

Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_packages()

View CVE report →
CVE-2026-26192 · CVSS 7.3

Open WebUI vulnerable to Stored XSS via iFrame in citations model

View CVE report →
CVE-2026-26193 · CVSS 7.3

Open WebUI vulnerable to Stored XSS via iFrame embeds in response messages

View CVE report →
CVE-2026-44549 · CVSS 7.3

Open WebUI has stored XSS in Excel file preview

View CVE report →
CVE-2026-8596 · CVSS 7.2

Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK ModelBuilder/Serve path

View CVE report →
CVE-2026-35397 · CVSS 7.1

Jupyter Server: Path Traversal via incorrect startswith() root directory check allows access to sibling directories

View CVE report →
CVE-2026-44556 · CVSS 7.1

Open WebUI's responses passthrough endpoint lacks access control authorization

View CVE report →
CVE-2026-44641 · CVSS 7.1

Microsoft APM CLI's plugin.json component paths escape plugin root and copy arbitrary host files during install

View CVE report →
CVE-2026-50181 · CVSS 7.1

Langroid: Path traversal in the file tools allows read/write outside configured current directory

View CVE report →
CVE-2026-55787 · CVSS 7.1

flyto-core has SSRF guard bypass via IPv6 transition addresses (IPv4-mapped / 6to4 / NAT64) in validate_url_ssrf

View CVE report →
CVE-2026-9291 · CVSS 7.1

amazon-braket-sdk vulnerable to Insecure Deserialization via pickle.loads()

View CVE report →