VulnScope — 以套件為主體的 CVE 查詢工具- HIGH7.5CVE-2026-54695Pipecat: Telephony WebSocket `/ws` Unauthenticated Call-Control Abuse via Attacker-Supplied Call SID
- LOW2.2BBOT: Symlink-Following Arbitrary Write via github_workflows Module
- MEDIUM6.5BBOT: Arbitrary File Write in postman_download Module
- LOW3.1BBOT: Server-Side Request Forgery (SSRF) in docker_pull module via WWW-Authenticate realm parsing
- MEDIUM5.3BBOT: Path traversal (Zip-Slip) in unarchive module - incomplete fix for CVE-2025-10284
- CRITICAL9.8python-statemachine SCXML <data expr> Eval Injection
- MEDIUM6.1marimo contains a reflected cross-site scripting vulnerability in the notebook page
- MEDIUM6.0OpenStack Horizon RC file generation does not escape special characters in project names
- CRITICAL9.3Langflow: Unauthenticated file upload leads to DoS (space exhaustion) and information leak
- HIGH8.4pdfkit: Path traversal in from_string
- CRITICAL9.1Apache Airflow SFTP provider: Path traversal in SFTPHook.retrieve_directory
- MEDIUM5.3Open WebUI: Any authenticated user can read other users' private notes via Socket.IO
- MEDIUM6.3Open WebUI: Authenticated users can target arbitrary configured Ollama backends via unguarded url_idx path parameter
- MEDIUM6.5Open WebUI: RAG ACL Bypass in Milvus Multitenancy Mode
- HIGH7.7Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects
- HIGH7.7Open WebUI: Path traversal / SSRF in terminal server proxy via encoded path traversal
- MEDIUM4.3Open WebUI BOLA: `search_knowledge_files` Allows Unauthorized Knowledge Base File Enumeration
- MEDIUM6.4Open WebUI Prompt history IDOR: unbound history_id allows cross-prompt read and deletion
- MEDIUM4.3Open WebUI: Sibling-Prefix Path Traversal via /cache/{path}
- HIGH7.6Open WebUI: Stored XSS to Account Takeover via Model Profile Images
- HIGH7.1Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion
- HIGH8.7Open WebUI: Stored XSS in Mermaid Markdown Preview
- HIGH8.3Open WebUI: Forged chat-file link allows cross-user file read and deletion
- MEDIUM6.5Open WebUI: Cross-user file disclosure via /api/chat/completions image_url field
- HIGH8.5Open WebUI: Redirect-Bypass SSRF in OAuth `_process_picture_url` (incomplete-fix sibling of CVE-2026-45401)