Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| open-webui | open-webui/open-webui | unspecified ~ latest | - |
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-7046 | Improper Access Control in open-webui/open-webui | |
| CVE-2024-8053 | Improper Authentication in open-webui/open-webui | |
| CVE-2024-8017 | Cross-site Scripting (XSS) in open-webui/open-webui | |
| CVE-2024-8060 | Remote Code Execution in OpenWebUI via Arbitrary File Upload | |
| CVE-2024-7990 | Stored Cross-Site Scripting in open-webui/open-webui | |
| CVE-2024-7043 | Improper Access Control in open-webui/open-webui | |
| CVE-2024-7983 | Denial of Service in open-webui/open-webui | |
| CVE-2024-7035 | Cross-Site Request Forgery (CSRF) in open-webui/open-webui | |
| CVE-2024-7053 | Session Fixation in open-webui/open-webui | |
| CVE-2024-7806 | Remote Code Execution by Non-Admin Users via CSRF in open-webui/open-webui | |
| CVE-2024-12534 | Denial of Service (DoS) in open-webui/open-webui | |
| CVE-2024-7033 | Arbitrary File Write in open-webui/open-webui | |
| CVE-2024-7036 | Denial of Service in open-webui/open-webui | |
| CVE-2024-7044 | Stored XSS in open-webui/open-webui | |
| CVE-2024-7040 | Improper Access Control in open-webui/open-webui | |
| CVE-2024-7045 | Improper Access Control in open-webui/open-webui | |
| CVE-2024-7959 | SSRF in open-webui/open-webui | |
| CVE-2024-7034 | Remote Code Execution due to Arbitrary File Write in open-webui/open-webui | |
| CVE-2024-12537 | Unauthenticated Denial of Service in open-webui/open-webui |
No comments yet