Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.86% | — | Openwebui Open Webui | 20/3/2025 | 17/6/2026 | In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload can cause the server to spend excessive time converting it, leading to a denial of service. The server becomes unresponsive to other requests until the conversion is… | |
| Analizada | Alta (8.9) | 0.52% | — | Openwebui Open Webui | 20/3/2025 | 17/6/2026 | A Stored Cross-Site Scripting (XSS) vulnerability exists in the chat file upload functionality of open-webui/open-webui version 0.3.8. An attacker can inject malicious content into a file, which, when accessed by a victim through a URL or shared chat, executes JavaScript in the victim's browser. This can lead to user… | |
| Modificada | Alta (8.8) | 0.60% | — | Openwebui Open Webui | 20/3/2025 | 17/6/2026 | An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the GET /api/v1/files/ interface to retrieve information on all files uploaded by… | |
| Analizada | Media (6.9) | 8.5% | — | Openwebui Open Webui | 20/3/2025 | 17/6/2026 | In version v0.3.8 of open-webui/open-webui, sensitive actions such as deleting and resetting are performed using the GET method. This vulnerability allows an attacker to perform Cross-Site Request Forgery (CSRF) attacks, where an unaware user can unintentionally perform sensitive actions by simply visiting a malicious… | |
| Rechazada | Sin puntuar | — | — | Openwebui Open Webui | 10/10/2024 | 11/9/2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| Modificada | Media (5.4) | 0.37% | — | Openwebui Open Webui | 10/10/2024 | 17/6/2026 | In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a higher-privileged admin. By exploiting this vulnerability, an… | |
| Modificada | Media (6.5) | 0.37% | — | Openwebui Open Webui | 9/10/2024 | 17/6/2026 | An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is flawed, allowing attackers to edit other users' memories without proper… | |
| Modificada | Alta (8.8) | 1.0% | — | Openwebui Open Webui | 7/8/2024 | 17/6/2026 | Attacker controlled files can be uploaded to arbitrary locations on the web server's filesystem by abusing a path traversal vulnerability. | |
| Modificada | Media (6.1) | 0.66% | — | Openwebui Open Webui | 7/8/2024 | 17/6/2026 | Attackers can craft a malicious prompt that coerces the language model into executing arbitrary JavaScript in the context of the web page. | |
| Analizada | Media (6.4) | 0.41% | — | Openwebui Open Webui | 16/4/2024 | 17/6/2026 | Open WebUI is a user-friendly WebUI for LLMs. Open-webui is vulnerable to authenticated blind server-side request forgery. This vulnerability is fixed in 0.1.117. |