MEDIUM5.4Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
MEDIUM6.1marimo contains a reflected cross-site scripting vulnerability in the notebook page
MEDIUM6.0OpenStack Horizon RC file generation does not escape special characters in project names
CRITICAL9.3Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
CRITICAL9.1Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory
MEDIUM6.5Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
MEDIUM6.5Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
MEDIUM4.9Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
CRITICAL9.1Apache DolphinScheduler: The `/v2` experimental interface lacks permission checks
CRITICAL9.8Apache DolphinScheduler: DataSource API Missing Authorization Check Leads to Arbitrary Data Source Metadata Disclosure
MEDIUM5.3Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
MEDIUM6.3Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
MEDIUM6.5Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
MEDIUM4.3Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
MEDIUM6.4Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
MEDIUM4.3Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}
MEDIUM6.5Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
MEDIUM4.3Open WebUI IDOR: Calendar event re-parenting allows writing events into another user's calendar
MEDIUM6.5vLLM: OOM Denial of Service via Audio Decompression Bomb