Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 8.5 CVE-2026-12958

Arbitrary file write in Language Servers for AWS_CVE-2026-12958

Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur wh...

Amazon Web Services Language Servers for AWS CVE
HIGH 8.5 CVE-2026-12957

Arbitrary Code Execution in Language Servers for AWS_CVE-2026-12957

Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for arbitrary code exe...

Amazon Web Services Language Servers for AWS CVE
HIGH 7.8 CVE-2026-11940

tarfile extraction filter bypass allows escaping the destination directory_CVE-2026-11940

tarfile.extractall() with the 'data' or 'tar' filter could be bypassed by a crafted archive where a hardlink references a symlink stored at a dee...

Python Software Foundation CPython CVE
HIGH 7.5 CVE-2025-61025

CVE-2025-61025_CVE-2025-61025

An issue in the sslr_qst_get component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL ...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-61022

CVE-2025-61022_CVE-2025-61022

An issue in the sqlo_tb_col_preds component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-61020

CVE-2025-61020_CVE-2025-61020

An issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafte...

n/a n/a n/a CVE
HIGH 7.5 CVE-2025-61018

CVE-2025-61018_CVE-2025-61018

An issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted...

n/a n/a n/a CVE
HIGH 7.7 CVE-2026-54018

Open WebUI: SSRF Protection Bypass in Playwright Web Loader via HTTP Redirects_CVE-2026-54018

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, the SafePlaywrightURLLoader impl...

open-webui open-webui < 0.9.6 CVE
HIGH 7.6 CVE-2026-54013

Open WebUI: Stored XSS to Account Takeover via Model Profile Images in Open WebUI_CVE-2026-54013

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI patched SVG XSS in us...

open-webui open-webui < 0.9.6 CVE
HIGH 7.1 CVE-2026-54012

Open WebUI: Forged model meta.knowledge allows cross-user file read and deletion_CVE-2026-54012

Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI lets a user who can c...

open-webui open-webui < 0.9.6 CVE