Wingetlywingetly

Security

Vulnerabilities in the winget catalog.

Known CVEs for Windows applications shipped via the Microsoft Windows Package Manager community repository. Mapping is best-effort and limited to packages with a confirmed NVD CPE identity. Source: NVD (updated 4h ago).

Critical, last 90 days

Highest severity

Recent

New advisories this month

  • critical10.0CVE-2026-85706Sep 12, 2026

    GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.7 before 19.1.8, 19.2 before 19.2.6, and 19.3 before 19.3.2 that, under certain conditions, an unauthenticated user could have read arbitrary files from the GitL...

    AffectsGLab
  • critical9.8CVE-2026-88018Sep 10, 2026

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, rclone serve s3 configured with --auth-proxy but without --auth-key allows authPairMiddleware to register any cl...

    AffectsRcloneView
  • high7.3CVE-2026-88017Sep 10, 2026

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. From 1.64.0 until 1.75.1, the FTP auth-proxy driver in cmd/serve/ftp/ftp.go stores one obscured password per username in the serv...

    AffectsRcloneView
  • high7.1CVE-2026-88016Sep 10, 2026

    rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.75.1, when backend/local runs with --links, a source .rclonelink object can plant a symlink in the destination and lat...

    AffectsRcloneView
  • medium6.5CVE-2026-88002Sep 9, 2026

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.5.0 until 0.11.1, the message-chain reconstruction helper in backend/open_webui/utils/misc.py advanced through a chat history by map key but track...

  • medium5.0CVE-2026-88001Sep 9, 2026

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.9.5 until 0.11.1, server-side web fetches did not reapply WEB_FETCH_FILTER_LIST or private-address controls to HTTP redirect destinations when AIO...

  • medium6.5CVE-2026-88000Sep 9, 2026

    Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. From 0.10.0 until 0.11.1, DELETE /api/v1/chats/{id}/messages/{message_id} used the chat-history deletion helper in backend/open_webui/models/chats.py to...

  • high8.1CVE-2026-73334Sep 9, 2026

    Potential problem for users of the org.apache.parquet.crypto.keytools package in Apache Parquet, versions 1.12 to 1.18. This package enables users to encrypt Parquet files via an envelope encryption mechanism that wraps (encrypts) data ke...

  • medium4.3CVE-2026-87658Sep 9, 2026

    Information leak in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote attacker leveraging social engineering to obtain cross-origin data via a crafted Chrome extension. (Chromium security severity: Medium)

  • low3.1CVE-2026-87657Sep 9, 2026

    Use after free in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer process to read memory inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)