7.5

CVSS3.1

CVE-2026-35485 - text-generation-webui has a Path Traversal in load_grammar() — arbitrary file read without authenti…

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_grammar() allows reading any file on the server filesystem with no extension restriction. Gradio does not server-side validate dropdown valu…

📅 Published: April 7, 2026, 2:47 p.m. 🔄 Last Modified: April 7, 2026, 3:17 p.m.

5.3

CVSS3.1

CVE-2026-35484 - text-generation-webui has a Path Traversal in load_preset() — .yaml file read without authentication

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_preset() allows reading any .yaml file on the server filesystem. The parsed YAML key-value pairs (including passwords, API keys, connection …

📅 Published: April 7, 2026, 2:46 p.m. 🔄 Last Modified: April 7, 2026, 3:17 p.m.

5.3

CVSS3.1

CVE-2026-35483 - text-generation-webui has a Path Traversal in load_template() — .jinja/.yaml/.yml file read without…

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_template() allows reading files with .jinja, .jinja2, .yaml, or .yml extensions from anywhere on the server filesystem. For .jinja files the…

📅 Published: April 7, 2026, 2:45 p.m. 🔄 Last Modified: April 7, 2026, 3:17 p.m.

6.2

CVSS3.1

CVE-2026-35480 - go-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headers

go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on IPLD objects. Prior to 0.22.0, the DAG-CBOR decoder uses collection sizes declared in CBOR headers a…

📅 Published: April 7, 2026, 2:43 p.m. 🔄 Last Modified: April 7, 2026, 3:17 p.m.

7.5

CVSS3.1

CVE-2026-35464 - pyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbitrary file …

pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifying security-critical config options. The storage_folder option is not in this set and passes the existing path restriction because the…

📅 Published: April 7, 2026, 2:38 p.m. 🔄 Last Modified: April 7, 2026, 3:17 p.m.
Load More Vulnerability
avatar

Mehmet Ince

@mdisec

CVE stats coming here

avatar

Nuri Çilengir

@ncilengir

CVE stats coming here

avatar

@aydinnyunus

CVE stats coming here

avatar

Onurcan Genç

@onurcangnc

CVE stats coming here

avatar

Seyit Sigirci

@h3xecute

CVE stats coming here

avatar

Ali İltizar

@iltosec

CVE stats coming here

avatar

@b3rsec

CVE stats coming here

avatar

@furkank

CVE stats coming here

avatar

kutaysec

@kutaysec

CVE stats coming here