CVEs we hold for Open
Records whose assigning authority named Open as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-92417Open5GS PFCP types.c ogs_pfcp_parse_volume_measurement null pointer dereferencen/a Open5GS
CVE-2026-92416Open5GS PFCP Session Report Request n4-handler.c smf_n4_handle_session_report_request assertionn/a Open5GS
CVE-2026-91842OpenBankProject OBP-API Kryo Redis.scala KryoInjection.invert deserializationOpenBankProject OBP-API
CVE-2026-91836OpenClaw ClawScan Static Scanner static_scanner.go incomplete comparison with missing factorsOpenClaw ClawScan
CVE-2026-91835OpenClaw ClawScan File Classifier static_scanner.go IsBinaryFile interpretation conflictOpenClaw ClawScan
CVE-2026-90707Open5GS Old AMF Discovery Fallback nnrf-handler.c amf_nnrf_try_old_amf_discovery_fallback use after freen/a Open5GS
CVE-2026-90486openstatusHQ openstatus resolve-custom-domain-rewrite.ts server-side request forgeryopenstatusHQ openstatus
CVE-2026-88891OpenPanel Read-Only Access Level Enforcement Bypass via MutationsOpenpanel-dev openpanel
CVE-2026-88890OpenPanel SQL Injection via unvalidated profile filter column identifierOpenpanel-dev openpanel
CVE-2026-8803opensourcepos Open Source Point of Sale Employee Login Employee.php login weak hashopensourcepos Open Source Point of Sale
CVE-2026-8802opensourcepos Open Source Point of Sale Items.php getPicThumb path traversalopensourcepos Open Source Point of Sale
CVE-2026-88006Open WebUI: Users denied by the OAuth role policy can still sign in via token exchangeopen-webui
CVE-2026-88005Open WebUI: Users denied by the OAuth domain allowlist or role policy can still sign in via token exchangeopen-webui
CVE-2026-88002Open WebUI: Any authenticated user can hang the server via a cyclic chat message historyopen-webui
CVE-2026-88001Open WebUI: Server-side fetches reach blocked and internal hosts via unvalidated HTTP redirect targetsopen-webui
CVE-2026-88000Open WebUI: Any authenticated user can hang the server via message deletion in a cyclic chat treeopen-webui
CVE-2026-87999Open WebUI: Any authenticated user can reach the Azure platform channel via server-side web fetchopen-webui
CVE-2026-87998Open WebUI: Non-admin users can delete admin-owned external knowledge connections via knowledge base deletionopen-webui
CVE-2026-87997Open WebUI: Any authenticated user can inject chats into another user's folder via chat completionsopen-webui
CVE-2026-87996Open WebUI: SSRF into internal services via DNS rebinding in the Playwright web loaderopen-webui
CVE-2026-87995Open WebUI: Same-origin XSS to account takeover via terminal port-preview iframe hardcoding allow-same-originopen-webui
CVE-2026-87994Open WebUI: Channel members can overwrite another member's message via the chat completions endpointopen-webui
CVE-2026-8743Open5GS AMF/MME context.c ran_ue_find_by_amf_ue_ngap_id improper authorizationn/a Open5GS
CVE-2026-8728Open5GS NRF conv.c ogs_sbi_discovery_option_parse_plmn_list denial of servicen/a Open5GS
CVE-2026-87017Open WebUI: Inaccessible knowledge bases are exposed through the built-in knowledge tool on most vector backendsopen-webui
CVE-2026-87016Open WebUI: Sign-in as another user via wildcard characters in the OAuth subject claim on SQLiteopen-webui
CVE-2026-87015Open WebUI: A user's session cookies are sent to tool servers configured for bearer authenticationopen-webui
CVE-2026-87014Open WebUI: Admin demoted through SSO role sync keeps read and write access to all users' notesopen-webui
CVE-2026-87013Open WebUI: Any authenticated user can start a non-terminating request via a folder parent cycleopen-webui
CVE-2026-87012Open WebUI: Any authenticated user can suppress calendar alerts instance-wide via a non-numeric alert valueopen-webui
CVE-2026-87011Open WebUI: Unauthenticated requests can stall the server via uncached OIDC fetches in back-channel logoutopen-webui
CVE-2026-86810Open-Web-Analytics Controller Controller.php checkCapabilityAndAuthenticateUser improper authenticationn/a Open-Web-Analytics
CVE-2026-86237openagents-org openagents http.py test_default_model server-side request forgeryopenagents-org openagents
CVE-2026-85614OpenPanel API before 2.3.0 Unauthenticated SSRF via site-checkerOpenpanel-dev openpanel
CVE-2026-85610OpenPanel before 2.3.0 Remote Code Execution via chart formulasOpenpanel-dev openpanel
CVE-2026-85272Open edX Platform: Path traversal via prefix-bypass in safe_extractall Path Validationopenedx-platform
CVE-2026-85271Open edX Platform: Stored CSS Injection in Email Digest Notifications via Unsanitized Thread Title (incomplete patch of…openedx-platform
CVE-2026-84700Pika Unauthenticated Replication Access via Internal Protobuf PortOpenAtomFoundation pikiwidb
CVE-2026-83497Unrestricted Java Deserialization in OpenSearch SQL Plugin Cursor PaginationOpenSearch; Amazon OpenSearch Service
CVE-2026-8305OpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authenticationn/a OpenClaw
CVE-2026-8290Open5GS SMF nsmf-handler.c smf_nsmf_handle_update_data_in_vsmf denial of servicen/a Open5GS
CVE-2026-8289Open5GS SMF nsmf-handler.c smf_nsmf_handle_update_data_in_vsmf denial of servicen/a Open5GS
CVE-2026-8266Open5GS SMF gsm-build.c gsm_build_pdu_session_establishment_accept denial of servicen/a Open5GS
CVE-2026-82623open62541 History Backend ua_history_data_backend_memory.c UA_DataValue_backend_copyRange use after freen/a open62541
CVE-2026-82591Open Asset Import Library Assimp MD5Loader.cpp MakeDataUnique heap-based overflowOpen Asset Import Library Assimp
CVE-2026-82589Open5GS N1-N2 Message namf-handler.c amf_namf_comm_handle_n1_n2_message_transfer denial of servicen/a Open5GS
CVE-2026-82587Open5GS AMF namf-handler.c amf_namf_comm_decode_ue_mm_context_list memory corruptionn/a Open5GS
CVE-2026-8251Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of servicen/a Open5GS
CVE-2026-8250Open5GS SMF n4-build.c smf_n4_build_qos_flow_to_modify_list denial of servicen/a Open5GS
CVE-2026-8249Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of servicen/a Open5GS
CVE-2026-8248Open5GS SMF npcf-handler.c update_authorized_pcc_rule_and_qos denial of servicen/a Open5GS
CVE-2026-8225Open5GS delete Endpoint sm-sm.c pcf_npcf_smpolicycontrol_handle_delete denial of servicen/a Open5GS
CVE-2026-8223Open5GS sm-policies Endpoint pcf_sess_sbi_discover_and_send denial of servicen/a Open5GS
CVE-2026-8222Open5GS sm-policies Endpoint nbsf-handler.c pcf_nbsf_management_handle_register denial of servicen/a Open5GS
CVE-2026-81872OpenTelemetry-Go: BatchProcessor can busy-spin when export buffer is fullopen-telemetry opentelemetry-go
CVE-2026-81871OpenTelemetry-Go: Log gRPC exporter ignores env TLS certs, bypassing mTLS/pinningopen-telemetry opentelemetry-go
CVE-2026-81870OpenTelemetry-Go: Exporter config logging may leak endpoint URLs in info logsopen-telemetry opentelemetry-go
CVE-2026-81869OpenTelemetry-Go: UTF-8 replacement rune bypasses attribute length truncationopen-telemetry opentelemetry-go
CVE-2026-81679OpenRemote before 1.28.0 Cross-Realm Information Disclosure via Notification APIopenremote
CVE-2026-81664OpenFaaS Gateway 0.27.11 through 0.27.13 Missing Authentication on the /system/telemetry Routeopenfaas faas
CVE-2026-8123Open5GS NSSF message.c ogs_sbi_discovery_option_add_snssais denial of servicen/a Open5GS
CVE-2026-8122Open5GS NSSF message.c ogs_sbi_discovery_option_add_service_names denial of servicen/a Open5GS
CVE-2026-81192OpenTelemetry.Resources.Host vulnerable to arbitrary code execution via local PATH hijacking on macOSopen-telemetry opentelemetry-dotnet-contrib
CVE-2026-81029OpenMetadata before 2.0.0 JWT Disclosure via Unvalidated SAML and OIDC Redirect URIopen-metadata OpenMetadata
CVE-2026-79619OpenZFS: user-namespace capability check allows unprivileged local authorization bypassOpenZFS
CVE-2026-78156Open5GS S6a Authentication-Information-Request hss-s6a-path.c hss_ogs_diam_s6a_air_cb heap-based overflown/a Open5GS
CVE-2026-7781Open5GS amf-3gpp-access Endpoint nudm-handler.c udm_nudm_uecm_handle_amf_registration_update denial of servicen/a Open5GS
CVE-2026-7780Open5GS smf-registrations Endpoint udm-sm.c udm_state_operational denial of servicen/a Open5GS
CVE-2026-7779Open5GS authentication-subscription Endpoint nudr-handler.c udm_nudr_dr_handle_subscription_authentication denial of…n/a Open5GS
CVE-2026-77769OpenPanel report.list Queries Reports by an Unverified dashboardId, Crossing Organization BoundariesOpenpanel-dev openpanel
CVE-2026-77768OpenPanel report.get Returns Any Report by Identifier Without Checking Project AccessOpenpanel-dev openpanel
CVE-2026-7707Open5GS UDR nudr-handler.c udr_nudr_dr_handle_subscription_context denial of servicen/a Open5GS
CVE-2026-76820OpenCTI: Synchronizer SSRF: stream fetch has no URL validationOpenCTI-Platform opencti
CVE-2026-75897Uncontrolled Resource Consumption in Capabilities Route in OpenSearch DashboardsOpenSearch Service
CVE-2026-7587Open5GS AMF nsmf-handler.c amf_nsmf_pdusession_handle_update_sm_context denial of servicen/a Open5GS
CVE-2026-7585Open5GS AMF nudm-handler.c amf_nudm_sdm_handle_provisioned denial of servicen/a Open5GS
CVE-2026-75602OpenList: Authenticated arbitrary file write via Content-Disposition path traversal in SimpleHttp offline-download toolOpenListTeam OpenList
CVE-2026-7518Open5GS AMF SBI Endpoint sdmsubscription-notify amf_namf_callback_handle_sdm_data_change_notify denial of servicen/a Open5GS
CVE-2026-73843OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIsopenchoreo
CVE-2026-73842OpenChoreo: cluster-gateway internal proxy performs no caller authentication and is not read-only — data-plane Secret…openchoreo
CVE-2026-73841OpenChoreo: Cross-project command execution and wirelog view access via OpenChoreo openchoreo-api exec and wirelogs…openchoreo
CVE-2026-73840OpenChoreo: Unauthenticated build/workflow trigger via git-provider confusion (webhook signature bypass)openchoreo
CVE-2026-73667OpenChoreo: Authenticated OS command injection via OpenChoreo Workflow Plane templates enables code execution in…openchoreo
CVE-2026-73666OpenChoreo: Unauthenticated Backstage developer-portal API exposes OpenChoreo catalog data, scaffolder logs, and allows…openchoreo backstage-plugins
CVE-2026-73645OpenZeppelin Confidential Contracts ERC7984ERC20Wrapper: once a wrapper is filled, subsequent wrap requests do not…openzeppelin-confidential-contracts
CVE-2026-73644OpenDJ: Authorization bypass in SASL PLAIN allowing a `proxied-auth` holder to impersonate any resolvable non-root user…OpenIdentityPlatform OpenDJ
CVE-2026-73509OpenList: Authenticated users can rename files outside their base path via batch rename `src_name` traversalOpenListTeam OpenList
CVE-2026-72689OpenSignLabs opensignserver - Broken Object Level AuthorizationOpenSignLabs opensignserver
CVE-2026-72688OpenSignLabs opensignserver - Missing Authentication for Critical FunctionOpenSignLabs opensignserver
CVE-2026-72544OpenSignLabs OpenSign - Insufficient Verification of Data AuthenticityOpenSignLabs OpenSign
CVE-2026-71568BMCtest exposes Ironic without authentication and TLS during the testopenshift-metal3 bmctest
CVE-2026-71567User-controlled variables inserted unescaped into shell scripts and Kubernetes manifestsopenshift-metal3 fakefish
CVE-2026-71274OpenBK7231T Stored XSS via Unsanitized MQTT-Set Channel Labelsopenshwprojects OpenBK7231T_App
CVE-2026-71273OpenBK7231T CSRF in /cfg_wifi_set Leading to Implicit Web Password Disable and WiFi Hijackopenshwprojects OpenBK7231T_App
200 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.