vciy

CVEs we hold for Open

Records whose assigning authority named Open as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-9560no title heldOpenVPN Connect
CVE-2026-93854no title heldOpenStack Blazar
CVE-2026-93852no title heldOpenStack Blazar
CVE-2026-92794OpenSign through 2.41.3 Information Disclosure via getDocumentOpenSignLabs OpenSign
CVE-2026-92792OpenNHP through 1.0.2 Authentication Bypass via Fallback Verifieropennhp
CVE-2026-92764OpenCVE before 3.1.0 Organization API Ignores Token Scopeopencve
CVE-2026-92569Hippo4j through 1.5.0 SSRF via clientAddress Parameteropengoofy hippo4j
CVE-2026-92417Open5GS PFCP types.c ogs_pfcp_parse_volume_measurement null pointer dereferencen/a Open5GS
CVE-2026-92416Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request assertionn/a Open5GS
CVE-2026-91855Open5GS PFCP Message handler.c denial of servicen/a Open5GS
CVE-2026-91842OpenBankProject OBP-API Kryo Redis.scala KryoInjection.invert deserializationOpenBankProject OBP-API
CVE-2026-91836OpenClaw ClawScan Static Scanner static_scanner.go incomplete comparison with missing factorsOpenClaw ClawScan
CVE-2026-91835OpenClaw ClawScan File Classifier static_scanner.go IsBinaryFile interpretation conflictOpenClaw ClawScan
CVE-2026-90770Spug through 3.4.0 Remote Code Execution via ping_checkopenspug spug
CVE-2026-9076Out-of-Bounds Read in CMS Password-Based DecryptionOpenSSL
CVE-2026-90707Open5GS Old AMF Discovery Fallback nnrf-handler.c amf_nnrf_try_old_amf_discovery_fallback use after freen/a Open5GS
CVE-2026-90486openstatusHQ openstatus resolve-custom-domain-rewrite.ts server-side request forgeryopenstatusHQ openstatus
CVE-2026-90461no title heldOpenStack Ironic
CVE-2026-90460no title heldOpenStack Keystone
CVE-2026-88893OpenPanel Unauthenticated Share Lookup Information DisclosureOpenpanel-dev openpanel
CVE-2026-88892OpenPanel SSRF via Unguarded Importer File URL FetchOpenpanel-dev openpanel
CVE-2026-88891OpenPanel Read-Only Access Level Enforcement Bypass via MutationsOpenpanel-dev openpanel
CVE-2026-88890OpenPanel SQL Injection via unvalidated profile filter column identifierOpenpanel-dev openpanel
CVE-2026-8803opensourcepos Open Source Point of Sale Employee Login Employee.php login weak hashopensourcepos Open Source Point of Sale
CVE-2026-8802opensourcepos Open Source Point of Sale Items.php getPicThumb path traversalopensourcepos Open Source Point of Sale
CVE-2026-88006Open WebUI: Users denied by the OAuth role policy can still sign in via token exchangeopen-webui
CVE-2026-88005Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchangeopen-webui
CVE-2026-88002Open WebUI: Any authenticated user can hang the server via a cyclic chat message historyopen-webui
CVE-2026-88001Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targetsopen-webui
CVE-2026-88000Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat treeopen-webui
CVE-2026-87999Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetchopen-webui
CVE-2026-87998Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletionopen-webui
CVE-2026-87997Open WebUI: Any authenticated user can inject chats into another user's folder via chat completionsopen-webui
CVE-2026-87996Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loaderopen-webui
CVE-2026-87995Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-originopen-webui
CVE-2026-87994Open WebUI: Channel members can overwrite another member's message via the chat completions endpointopen-webui
CVE-2026-8746Open5GS NRF nghttp2-server.c discover_handler use after freen/a Open5GS
CVE-2026-8745Open5GS AUSF nausf-handler.c ogs_timer_add denial of servicen/a Open5GS
CVE-2026-8744Open5GS NRF context.c ogs_sbi_nf_service_add denial of servicen/a Open5GS
CVE-2026-8743Open5GS AMF/MME context.c ran_ue_find_by_amf_ue_ngap_id improper authorizationn/a Open5GS
CVE-2026-8731Open5GS NRF client.c ogs_sbi_client_add denial of servicen/a Open5GS
CVE-2026-8730Open5GS NRF context.c ogs_sbi_nf_instance_set_id denial of servicen/a Open5GS
CVE-2026-8729Open5GS NRF message.c denial of servicen/a Open5GS
CVE-2026-8728Open5GS NRF conv.c ogs_sbi_discovery_option_parse_plmn_list denial of servicen/a Open5GS
CVE-2026-87017Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backendsopen-webui
CVE-2026-87016Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLiteopen-webui
CVE-2026-87015Open WebUI: A user's session cookies are sent to tool servers configured for bearer authenticationopen-webui
CVE-2026-87014Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notesopen-webui
CVE-2026-87013Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycleopen-webui
CVE-2026-87012Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert valueopen-webui
CVE-2026-87011Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logoutopen-webui
CVE-2026-86810Open-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authenticationn/a Open-Web-Analytics
CVE-2026-86806opengeos GeoLibre _is_within_roots server-side request forgeryopengeos GeoLibre
CVE-2026-8634Crabbox < v0.12.0 Environment Variable Information Disclosureopenclaw crabbox
CVE-2026-8629Crabbox < v0.12.0 Privilege Escalation via Agent Ticket Endpointsopenclaw crabbox
CVE-2026-86237openagents-org openagents http.py test_default_model server-side request forgeryopenagents-org openagents
CVE-2026-86212Open5GS AMF/MME improper authorizationn/a Open5GS
CVE-2026-8621Crabbox < v0.12.0 Authentication Bypass via Header Spoofingopenclaw crabbox
CVE-2026-85696SadTalker OS Command Injection via Audio FilenameOpenTalker SadTalker
CVE-2026-85615Openpanel before 2.3.0 Cross-Tenant IDOR via report.getLayoutsOpenpanel-dev openpanel
CVE-2026-85614OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checkerOpenpanel-dev openpanel
CVE-2026-85613OpenPanel Unauthenticated XSS via SVG Favicon ProxyOpenpanel-dev openpanel
CVE-2026-85612OpenPanel before 2.3.0 SSRF via favicon and og endpointsOpenpanel-dev openpanel
CVE-2026-85611OpenPanel before 2.3.0 Cross-Tenant BOLA via report proceduresOpenpanel-dev openpanel
CVE-2026-85610OpenPanel before 2.3.0 Remote Code Execution via chart formulasOpenpanel-dev openpanel
CVE-2026-85609Openpanel before 2.3.0 SSRF via Site Checker EndpointOpenpanel-dev openpanel
CVE-2026-85272Open edX Platform: Path traversal via prefix-bypass in safe_extractall Path Validationopenedx-platform
CVE-2026-85271Open edX Platform: Stored CSS Injection in Email Digest Notifications via Unsanitized Thread Title (incomplete patch of…openedx-platform
CVE-2026-84732no title heldOpenVPN
CVE-2026-84700Pika Unauthenticated Replication Access via Internal Protobuf PortOpenAtomFoundation pikiwidb
CVE-2026-8462OpenMeter SQL Injection in ClickHouse-backed Meter Definitionsopenmeter
CVE-2026-84438OpenCart Autocomplete Workflow edit.php cross site scriptingn/a OpenCart
CVE-2026-84437OpenCart Autocomplete Workflow address.php cross site scriptingn/a OpenCart
CVE-2026-84256no title heldOpenVPN
CVE-2026-84226no title heldOpenVPN
CVE-2026-84165Lack of authorisation in OpenNebula by OpenNebula SystemsOpenNebula
CVE-2026-83497Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor PaginationOpenSearch; Amazon OpenSearch Service
CVE-2026-8305OpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authenticationn/a OpenClaw
CVE-2026-8292Open5GS NRF conv.c yuarel_parse denial of servicen/a Open5GS
CVE-2026-8291Open5GS NRF nnrf-handler.c ogs_nnrf_nfm_handle_nf_profile denial of servicen/a Open5GS
CVE-2026-8290Open5GS SMF nsmf-handler.c smf_nsmf_handle_update_data_in_vsmf denial of servicen/a Open5GS
CVE-2026-8289Open5GS SMF nsmf-handler.c smf_nsmf_handle_update_data_in_vsmf denial of servicen/a Open5GS
CVE-2026-8288Open5GS SMF gsm-handler.c denial of servicen/a Open5GS
CVE-2026-8270Open5GS SMF ogs_nas_parse_qos_rules denial of servicen/a Open5GS
CVE-2026-8269Open5GS SMF smf_nsmf_handle_create_sm_context denial of servicen/a Open5GS
CVE-2026-8268Open5GS SMF OpenAPI_list_create denial of servicen/a Open5GS
CVE-2026-8267Open5GS SMF smf_nsmf_handle_created_data_in_vsmf denial of servicen/a Open5GS
CVE-2026-8266Open5GS SMF gsm-build.c gsm_build_pdu_session_establishment_accept denial of servicen/a Open5GS
CVE-2026-82623open62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange use after freen/a open62541
CVE-2026-82591Open Asset Import Library Assimp MD5Loader.cpp MakeDataUnique heap-based overflowOpen Asset Import Library Assimp
CVE-2026-82590Open5GS SMF nudm-handler.c smf_nudm_sdm_handle_get assertionn/a Open5GS
CVE-2026-82589Open5GS N1-N2 Message namf-handler.c amf_namf_comm_handle_n1_n2_message_transfer denial of servicen/a Open5GS
CVE-2026-82588Open5GS Transfer Endpoint namf-handler.c null pointer dereferencen/a Open5GS
CVE-2026-82587Open5GS AMF namf-handler.c amf_namf_comm_decode_ue_mm_context_list memory corruptionn/a Open5GS
CVE-2026-8252Open5GS SMF smf_nsmf_handle_create_data_in_hsmf null pointer dereferencen/a Open5GS
CVE-2026-8251Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of servicen/a Open5GS
CVE-2026-8250Open5GS SMF n4-build.c smf_n4_build_qos_flow_to_modify_list denial of servicen/a Open5GS
CVE-2026-8249Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of servicen/a Open5GS
CVE-2026-8248Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of servicen/a Open5GS
CVE-2026-82325no title heldOpenVPN ovpn-dco-win
CVE-2026-82312no title heldOpenVPN
CVE-2026-82265Zipkin Unauthenticated Spring Boot Actuator Endpoints Exposureopenzipkin zipkin
CVE-2026-8226Open5GS types.c ogs_pcc_rule_install_flow_from_media denial of servicen/a Open5GS
CVE-2026-8225Open5GS delete Endpoint sm-sm.c pcf_npcf_smpolicycontrol_handle_delete denial of servicen/a Open5GS
CVE-2026-8224Open5GS PCF context.c pcf_sess_set_ipv6prefix denial of servicen/a Open5GS
CVE-2026-8223Open5GS sm-policies Endpoint pcf_sess_sbi_discover_and_send denial of servicen/a Open5GS
CVE-2026-8222Open5GS sm-policies Endpoint nbsf-handler.c pcf_nbsf_management_handle_register denial of servicen/a Open5GS
CVE-2026-81872OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is fullopen-telemetry opentelemetry-go
CVE-2026-81871OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinningopen-telemetry opentelemetry-go
CVE-2026-81870OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logsopen-telemetry opentelemetry-go
CVE-2026-8187Open5GS UPF gtp-path.c _gtpv1_u_recv_cb resource consumptionn/a Open5GS
CVE-2026-81869OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncationopen-telemetry opentelemetry-go
CVE-2026-8186Open5GS NF client.c ogs_sbi_client_send_via_scp_or_sepp out-of-boundsn/a Open5GS
CVE-2026-81830no title heldOpenVPN
CVE-2026-81738no title heldOpenVPN
CVE-2026-81679OpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification APIopenremote
CVE-2026-81664OpenFaaS Gateway 0.27.11 through 0.27.13 Missing Authentication on the /system/telemetry Routeopenfaas faas
CVE-2026-8123Open5GS NSSF message.c ogs_sbi_discovery_option_add_snssais denial of servicen/a Open5GS
CVE-2026-8122Open5GS NSSF message.c ogs_sbi_discovery_option_add_service_names denial of servicen/a Open5GS
CVE-2026-8121Open5GS NSSF conv.c ogs_sbi_parse_plmn_list denial of servicen/a Open5GS
CVE-2026-8120Open5GS NSSF nnssf-handler.c denial of servicen/a Open5GS
CVE-2026-81192OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOSopen-telemetry opentelemetry-dotnet-contrib
CVE-2026-8119Open5GS NSSF nghttp2-server.c ogs_sbi_stream_find_by_id denial of servicen/a Open5GS
CVE-2026-81029OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redirect URIopen-metadata OpenMetadata
CVE-2026-80184no title heldOpenStack Keystone
CVE-2026-80183no title heldOpenStack Keystone
CVE-2026-80182no title heldOpenStack Keystone
CVE-2026-79619OpenZFS: user-namespace capability check allows unprivileged local authorization bypassOpenZFS
CVE-2026-78221no title heldOpenVPN
CVE-2026-78186Open5GS HSS hss-cx-path.c assertionn/a Open5GS
CVE-2026-78158Open5GS AMF UEContextReleaseRequest Path improper authorizationn/a Open5GS
CVE-2026-78157Open5GS Rx AA-Request pcrf-rx-path.c pcrf_rx_aar_cb out-of-boundsn/a Open5GS
CVE-2026-78156Open5GS S6a Authentication-Information-Request hss-s6a-path.c hss_ogs_diam_s6a_air_cb heap-based overflown/a Open5GS
CVE-2026-78043no title heldOpenVPN
CVE-2026-7781Open5GS amf-3gpp-access Endpoint nudm-handler.c udm_nudm_uecm_handle_amf_registration_update denial of servicen/a Open5GS
CVE-2026-7780Open5GS smf-registrations Endpoint udm-sm.c udm_state_operational denial of servicen/a Open5GS
CVE-2026-7779Open5GS authentication-subscription Endpoint nudr-handler.c udm_nudr_dr_handle_subscription_authentication denial of…n/a Open5GS
CVE-2026-77769OpenPanel report.list Queries Reports by an Unverified dashboardId, Crossing Organization BoundariesOpenpanel-dev openpanel
CVE-2026-77768OpenPanel report.get Returns Any Report by Identifier Without Checking Project AccessOpenpanel-dev openpanel
CVE-2026-77648no title heldOpenStack Glance
CVE-2026-77615Paella Player: Stored XSS via caption cue textopencast; polimediaupv paella-player
CVE-2026-77614Opencast: Session fixation in login enables account takeover via crafted linkopencast
CVE-2026-7708Open5GS UDR subscription.c ogs_dbi_subscription_data denial of servicen/a Open5GS
CVE-2026-7707Open5GS UDR nudr-handler.c udr_nudr_dr_handle_subscription_context denial of servicen/a Open5GS
CVE-2026-7706Open5GS AMF gmm-handler.c gmm_handle_service_request denial of servicen/a Open5GS
CVE-2026-76878no title heldOpenStack Aodh
CVE-2026-76821OpenCTI: User-Controlled ReDoS in JSON Ingestion MapperOpenCTI-Platform opencti
CVE-2026-76820OpenCTI: Synchronizer SSRF: stream fetch has no URL validationOpenCTI-Platform opencti
CVE-2026-76614OpenEMR < 8.3.0 Path Traversal Information Disclosure via EDI Archive Restoreopenemr
CVE-2026-7601Open5GS AMF gmm-handler.c denial of servicen/a Open5GS
CVE-2026-75897Uncontrolled Resource Consumption in Capabilities Route in OpenSearch DashboardsOpenSearch Service
CVE-2026-7587Open5GS AMF nsmf-handler.c amf_nsmf_pdusession_handle_update_sm_context denial of servicen/a Open5GS
CVE-2026-7586Open5GS AMF nudm-handler.c ogs_id_get_value denial of servicen/a Open5GS
CVE-2026-7585Open5GS AMF nudm-handler.c amf_nudm_sdm_handle_provisioned denial of servicen/a Open5GS
CVE-2026-7583Open5GS BSF context.c bsf_sess_find_by_ipv6prefix denial of servicen/a Open5GS
CVE-2026-75803AEAD Forgeries with Empty Ciphertext When Using EVP_Cipher()OpenSSL
CVE-2026-75602OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolOpenListTeam OpenList
CVE-2026-7536Open5GS BSF pcfBindings bsf_sess_add_by_ip_address denial of servicen/a Open5GS
CVE-2026-7535Open5GS transfer-update denial of servicen/a Open5GS
CVE-2026-7518Open5GS AMF SBI Endpoint sdmsubscription-notify amf_namf_callback_handle_sdm_data_change_notify denial of servicen/a Open5GS
CVE-2026-74797OpenTofu before 1.11.4 Denial of Service via malicious zipopentofu
CVE-2026-74796OpenTofu before 1.11.7 Symlink Following Path Traversalopentofu
CVE-2026-74250no title heldOpenStack Ironic
CVE-2026-74248no title heldOpenStack Octavia
CVE-2026-73843OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIsopenchoreo
CVE-2026-73842OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret…openchoreo
CVE-2026-73841OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs…openchoreo
CVE-2026-73840OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)openchoreo
CVE-2026-7383Possible Heap Buffer Overflow in ASN.1 Multibyte String ConversionOpenSSL
CVE-2026-73667OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in…openchoreo
CVE-2026-73666OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows…openchoreo backstage-plugins
CVE-2026-73645OpenZeppelin Confidential Contracts ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not…openzeppelin-confidential-contracts
CVE-2026-73644OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user…OpenIdentityPlatform OpenDJ
CVE-2026-73616OpenRemote Notification Delete Cross-Realm Insecure Direct Object Referenceopenremote
CVE-2026-73509OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversalOpenListTeam OpenList
CVE-2026-73283no title heldOpenBSD OpenSSH
CVE-2026-73282no title heldOpenBSD OpenSSH
CVE-2026-73281no title heldOpenBSD OpenSSH
CVE-2026-73209no title heldOpen-Xchange GmbH OX Dovecot CE
CVE-2026-73208no title heldOpen-Xchange GmbH OX Dovecot CE
CVE-2026-72842OpenWrt luci-app-lxc ACL Inconsistency Authentication Bypassopenwrt luci
CVE-2026-72841luci-app-openvpn Path Traversal RCE via instance_name2openwrt luci
CVE-2026-72840OpenWrt LuCI luci-mod-system-mounts ACL Root RCE via Crontab Writeopenwrt luci
CVE-2026-72713XAgent Path Traversal Arbitrary File Read via /workspace/fileOpenBMB XAgent
CVE-2026-72692OpenSignLabs opensignserver - Missing AuthorizationOpenSignLabs opensignserver
CVE-2026-72691OpenSignLabs opensignserver - Authentication BypassOpenSignLabs opensignserver
CVE-2026-72689OpenSignLabs opensignserver - Broken Object Level AuthorizationOpenSignLabs opensignserver
CVE-2026-72688OpenSignLabs opensignserver - Missing Authentication for Critical FunctionOpenSignLabs opensignserver
CVE-2026-72549OpenSignLabs OpenSign - Information DisclosureOpenSignLabs OpenSign
CVE-2026-72548OpenSignLabs OpenSign - Information DisclosureOpenSignLabs OpenSign
CVE-2026-72545OpenSignLabs OpenSign - Insecure Direct Object ReferenceOpenSignLabs OpenSign
CVE-2026-72544OpenSignLabs OpenSign - Insufficient Verification of Data AuthenticityOpenSignLabs OpenSign
CVE-2026-72543OpenSignLabs OpenSign - Insecure Direct Object ReferenceOpenSignLabs OpenSign
CVE-2026-71568BMCtest exposes Ironic without authentication and TLS during the testopenshift-metal3 bmctest
CVE-2026-71567User-controlled variables inserted unescaped into shell scripts and Kubernetes manifestsopenshift-metal3 fakefish
CVE-2026-71566KubeVirt backend is not authenticatedopenshift-metal3 fakefish
CVE-2026-71275OpenBK7231T - Reflected XSS via OTA host Parameteropenshwprojects OpenBK7231T_App
CVE-2026-71274OpenBK7231T Stored XSS via Unsanitized MQTT-Set Channel Labelsopenshwprojects OpenBK7231T_App
CVE-2026-71273OpenBK7231T CSRF in /cfg_wifi_set Leading to Implicit Web Password Disable and WiFi Hijackopenshwprojects OpenBK7231T_App
CVE-2026-71201no title heldOpenStack Ironic

200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.