Vulnerabilities
Vulnerable Software
Security Vulnerabilities
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, he superbooga and superboogav2 RAG extensions fetch user-supplied URLs via requests.get() with zero validation — no scheme check, no IP filtering, no hostname allowlist. An attacker can access cloud metadata endpoints, steal IAM credentials, and probe internal services. The fetched content is exfiltrated through the RAG pipeline. This vulnerability is fixed in 4.3.
CVSS Score
7.5
EPSS Score
0.0
Published
2026-04-07
text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_prompt() allows reading any .txt file on the server filesystem. The file content is returned verbatim in the API response. This vulnerability is fixed in 4.3.
CVSS Score
5.3
EPSS Score
0.001
Published
2026-04-07
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVSS Score
9.8
EPSS Score
0.001
Published
2026-04-07
Memory-safety vulnerability in github.com/jackc/pgx/v5.
CVSS Score
9.8
EPSS Score
0.001
Published
2026-04-07
An issue was discovered in the Wi-Fi driver in Samsung Mobile Processor and Wearable Processor Exynos 980, 850, 1280, 1330, 1380, 1480, 1580, W920, W930, and W1000. Incorrect Handling of the NL80211 vendor command leads to a buffer overflow via a certain ioctl message, issue 1 of 2.
CVSS Score
9.8
EPSS Score
0.0
Published
2026-04-07
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.
CVSS Score
8.8
EPSS Score
0.001
Published
2026-04-07
Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Symptom Collector application.
CVSS Score
8.0
EPSS Score
0.001
Published
2026-04-07
Nokia MantaRay NM is vulnerable to an OS command injection vulnerability due to improper neutralization of special elements used in an OS command in Log Search application.
CVSS Score
8.0
EPSS Score
0.001
Published
2026-04-07
Nokia MantaRay NM is vulnerable to a Relative Path Traversal vulnerability due to improper validation of input parameter on the file system in Software Manager application.
CVSS Score
5.7
EPSS Score
0.0
Published
2026-04-07
An issue that could allow an authorized user to view the clear-text secrets for a subset of credential types and fields has been resolved. This is an instance of CWE-522: Insufficiently Protected Credentials, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N (5.3 Medium). This issue was fixed in version 4.0.260204.2 of the runZero Platform.
CVSS Score
5.3
EPSS Score
0.0
Published
2026-04-07


Contact Us

Shodan ® - All rights reserved