Total CVEs detected worldwide to date.
CVE Threat Dashboard - Common Vulnerabilities and Exposures Database
CVE Database Dashboard – Real-time tracking of cybersecurity threats. Monitor the latest Common Vulnerabilities and Exposures (CVEs), analyze trends, and stay informed with real-time security intelligence, updated every 30 minutes. Be the first to spot emerging vulnerabilities and strengthen your defense. Explore the latest CVEs affecting software, systems, and networks worldwide.
Tracking all new vulnerabilities.
Ongoing analysis for enhanced threat understanding.
Top 10 CVE Newest Entries - Real-Time Updates
Stay ahead of cybersecurity threats with real-time updates on the latest vulnerabilities. This section highlights the top 10 most recently disclosed Common Vulnerabilities and Exposures (CVEs). Explore details, impact assessments, and mitigation strategies to safeguard your systems.
-
CVE-2026-45675 Immediate Threat Report
Detected on 15 May 2026, 20:16 UTC (only 47 minutes ago)
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, he LDAP and OAuth authentication flows use a TOCTOU (Time-of-Check-Time-of-Use) pa...
-
CVE-2026-45671 Exploitable Vulnerability Warning
Detected on 15 May 2026, 20:16 UTC (only 47 minutes ago)
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user can permanently delete files owned by other users via DELET...
-
CVE-2026-45399 Exploitable Vulnerability Warning
Detected on 15 May 2026, 20:16 UTC (only 47 minutes ago)
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, any authenticated user with low privileges can enumerate active background tasks a...
-
CVE-2026-45349 Exploitable Vulnerability Warning
Detected on 15 May 2026, 20:16 UTC (only 47 minutes ago)
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, a user just needs to use the API endpoint: /api/chat/completions with their own AP...
-
CVE-2026-45339 Critical Risk Assessment
Detected on 15 May 2026, 20:16 UTC (only 47 minutes ago)
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, Open WebUI allows admins to restrict which API endpoints an API key can access. Wh...
-
CVE-2026-45331 Severe Vulnerability Alert
Detected on 15 May 2026, 20:16 UTC (only 47 minutes ago)
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, validate_url() in backend/open_webui/retrieval/web/utils.py calls validators.ipv6(...
-
CVE-2026-44568 Cybersecurity Threat Advisory
Detected on 15 May 2026, 20:16 UTC (only 47 minutes ago)
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the AccountPending.svelte component renders the admin-configured "Pending User Ove...
-
CVE-2026-44564 Active Threat Alert
Detected on 15 May 2026, 20:16 UTC (only 47 minutes ago)
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the ydoc:document:update Socket.IO event handler checks whether the sender is a me...
-
CVE-2026-44563 Significant Vulnerability Warning
Detected on 15 May 2026, 20:16 UTC (only 47 minutes ago)
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the /api/generate, /api/embed, /api/embeddings, and /api/show endpoints accept any...
-
CVE-2026-44562 Critical Risk Assessment
Detected on 15 May 2026, 20:16 UTC (only 47 minutes ago)
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the POST /api/v1/models/import endpoint allows users with the workspace.models_imp...
Anticipate and Assess Emerging Threats
With the constant rise of new vulnerabilities, anticipating potential threats is critical to safeguarding your systems. Beyond simply consulting the CVE database, it is essential to understand the potential impact of each vulnerability and maintain a continuous vulnerability management strategy. By quickly identifying the exploits that can affect your resources, you enhance your organization’s security posture in the face of targeted attacks.
- Proactive Monitoring: regularly review bulletins and CVE updates.
- Risk Analysis: prioritize vulnerabilities based on their severity and the affected environment.
- Collaboration: coordinate with business teams to implement timely fixes and mitigate risks.
Recently Updated Vulnerabilities
Keep track of recent changes to existing vulnerabilities. This section highlights the latest modifications to CVE records, ensuring you have the most current information for effective vulnerability management.
Discover the most recent updates to CVEs, including critical vulnerabilities and their revised scores. Stay ahead of threats by accessing updated security details.
-
CVE-2026-22586 Critical Vulnerability Alert
Hard-coded Cryptographic Key vulnerability in Salesforce Marketing Cloud Engagement (CloudPages, Forward to a Friend, Profile Center, Subscription Center, Unsub Center, View As ... -
CVE-2026-44695 Active Threat Alert
Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independen... -
CVE-2026-43912 Urgent Exploit Warning
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the sam... -
CVE-2026-46408 Exploitable Vulnerability Warning
Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. Prior to 1.0.8.3, the checkout endpoint accepts a user-controlled cart_id... -
CVE-2026-46333 Vulnerability Insight
In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory...
Top Critical CVEs - Highest Severity Risks
Monitor vulnerabilities that are pending detailed examination. This section lists the ten most recent CVEs that are awaiting comprehensive analysis, allowing you to anticipate potential risks.
Discover the Top Critical CVEs
Explore the most critical CVEs with the highest severity scores. Prioritize these vulnerabilities to safeguard your systems against the most dangerous threats.
- CVE-2026-44523 Emergency Security Advisory Note Mark is an open-source note-taking application. Prior to 0.19.4, no minimum length or entropy is enforced on the JWT_SECRET configuration value. The application accepts any...
- CVE-2026-44005 Emergency Security Advisory vm2 is an open source vm/sandbox for Node.js. From 3.9.6 to 3.10.5, vm2's bridge exposes mutable proxies for real host-realm intrinsic prototypes and then forwards sandbox write...
- CVE-2026-42288 Emergency Security Advisory ChurchCRM is an open-source church management system. Prior to 7.3.2, The fix for CVE-2026-39337 is incomplete. The pre-authentication remote code execution vulnerability in Chu...
- CVE-2026-42869 High-Severity Security Breach SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret...
- CVE-2026-42298 Critical Vulnerability Alert Postiz is an AI social media scheduling tool. Prior to commit da44801, a "Pwn Request" vulnerability in the Build and Publish PR Docker Image workflow (.github/workflows/pr-dock...
Understanding the CVE Landscape
Keeping track of the most recent Common Vulnerabilities and Exposures (CVEs) is essential for businesses aiming to strengthen their cybersecurity posture. By monitoring newly disclosed vulnerabilities, security teams can proactively patch critical flaws, mitigate the risk of exploits, and safeguard critical infrastructures. Our curated list of the Top 10 Latest CVEs reflects real-time updates, ensuring you stay informed about newly released advisories across multiple vendors.
Average CVSS Score Over the Last 30 Days
6.25
Assess the severity of recent vulnerabilities. This section displays the average Common Vulnerability Scoring System (CVSS) score for CVEs reported in the past 30 days, indicating the criticality level of recent threats.
Number of Critical CVSS Scores (Above 9)
17608
Identify the count of highly severe vulnerabilities. This section enumerates the number of CVEs with a CVSS score above 9, signifying critical security issues that require immediate attention.
Assessing Risk Through CVSS Scores
CVSS (Common Vulnerability Scoring System) provides a standardized way to gauge the severity of vulnerabilities. High-severity or critical CVEs often require immediate attention, especially if they affect widely used software components. Failing to address them promptly can lead to unauthorized access, data breaches, and operational disruptions. Our platform not only highlights top-scoring vulnerabilities but also provides direct links to remediation steps and references.
Monthly CVE Growth
-5.2 %
Understand the trend of vulnerabilities over the past month. This section presents statistical data on the growth of CVEs in the last 30 days, helping you gauge the current security landscape.
Quarterly CVE Growth
32.9 %
Analyze the increase in vulnerabilities over the past quarter. This section provides insights into the quarterly growth of CVEs, assisting in long-term security planning.
Annual CVE Growth
23.8 %
Review the yearly escalation of reported vulnerabilities. This section offers an overview of the annual growth in CVEs, highlighting the evolving nature of security threats.
Strengthen Remediation and Patch Management
Once critical flaws are identified, deploying fixes swiftly and methodically is essential to minimize the impact of vulnerabilities on your infrastructure. Remediation efforts should be part of an overall patch management program and regular security audits. By optimizing your update process and performing routine tests, you reduce residual risks that attackers could otherwise exploit.
For more information on best practices for vulnerability fixes and improving response time, please visit our dedicated page: How to Fix CVEs .