MEDIUM5.3CVE-2026-12565BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
MEDIUM5.4Strimzi: Unrestricted access to all Secrets within namespace watched by the Topic operator
MEDIUM6.1marimo contains a reflected cross-site scripting vulnerability in the notebook page
MEDIUM5.3joserfc is a Python library that provides an implementation of several JSON Object Signing and Encryption (JOSE) standards.
MEDIUM5.9undici vulnerable to HTTP header injection via Set-Cookie percent-decoding
MEDIUM5.9undici vulnerable to cross-user information disclosure via shared cache whitespace bypass
LOW3.7undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse
LOW3.7undici vulnerable to Set-Cookie SameSite attribute downgrade via permissive substring matching
MEDIUM5.5Hermes Agent creates response_store.db and webhook_subscriptions.json with world-readable permissions (mode 0o644)
MEDIUM5.8Shaarli is a personal bookmarking service.
MEDIUM5.9libssh2 through 1.11.1, fixed in commit 1762685, contains a pre-authentication denial of service vulnerability in the SSH_MSG_EXT_INFO hand…
MEDIUM4.8Shaarli is a personal bookmarking service.
MEDIUM5.8Shaarli is a personal bookmarking service.
MEDIUM6.0OpenStack Horizon RC file generation does not escape special characters in project names
MEDIUM6.5Apache DolphinScheduler: An incorrect authorization vulnerability allows authenticated users to access alert instances associated with alert groups they do not have permission to access.
MEDIUM6.5Apache DolphinScheduler: Incorrect Authorization vulnerability allows users to access workflow instance information belonging to projects they do not have permission to access.
MEDIUM4.9Apache DolphinScheduler: Incorrect Authorization vulnerability allows users with system login privileges to delete task definitions in unauthorized projects
MEDIUM5.3Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
MEDIUM6.3Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
MEDIUM6.5Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
MEDIUM5.4A flaw was found in 389 Directory Server in the __aclp__normalize_acltxt() function of aclparse.c.
MEDIUM4.3Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
MEDIUM6.4Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
MEDIUM4.3Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}
MEDIUM6.5Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field