Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.86%—Openwebui Open Webui20/3/202517/6/2026
In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload can cause the server to spend excessive time converting it, leading to a denial of service. The server becomes unresponsive to other requests until the conversion is…
AnalizadaAlta (8.9)0.52%—Openwebui Open Webui20/3/202517/6/2026
A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui version 0.3.8. An attacker can inject malicious content into a file, which, when accessed by a victim through a URL or shared chat, executes JavaScript in the victim's browser. This can lead to user…
ModificadaAlta (8.8)0.60%—Openwebui Open Webui20/3/202517/6/2026
An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the GET /api/v1/files/ interface to retrieve information on all files uploaded by…
AnalizadaMedia (6.9)8.5%—Openwebui Open Webui20/3/202517/6/2026
In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform Cross-Site Request Forgery (CSRF) attacks, where an unaware user can unintentionally perform sensitive actions by simply visiting a malicious…
RechazadaSin puntuar——Openwebui Open Webui10/10/202411/9/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
ModificadaMedia (5.4)0.37%—Openwebui Open Webui10/10/202417/6/2026
In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a higher-privileged admin. By exploiting this vulnerability, an…
ModificadaMedia (6.5)0.37%—Openwebui Open Webui9/10/202417/6/2026
An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is flawed, allowing attackers to edit other users' memories without proper…
ModificadaAlta (8.8)1.0%—Openwebui Open Webui7/8/202417/6/2026
Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability.
ModificadaMedia (6.1)0.66%—Openwebui Open Webui7/8/202417/6/2026
Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page.
AnalizadaMedia (6.4)0.41%—Openwebui Open Webui16/4/202417/6/2026
Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forgery. This vulnerability is fixed in 0.1.117.
Orbitaley — Vulnerabilidades