Vulnerabilities
Last updated 48 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 11 hours ago |
|
|
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 11 hours ago |
|
|
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests | Medium Risk 5.4 | 2 months ago | 11 hours ago |
|
|
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 11 hours ago |
|
|
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root | High Risk 7.1 | 1 month ago | 1 month ago |
|
|
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server | Medium Risk 6.5 | 2 months ago | 1 month ago |
|
|
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings | Medium Risk 4.3 | 2 months ago | 1 month ago |
|
|
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails | Medium Risk 4.3 | 2 months ago | 1 month ago |
|
|
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account | Medium Risk 4.3 | 2 months ago | 1 month ago |
|
|
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials | High Risk 7.1 | 2 months ago | 1 month ago |
|
|
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored | Medium Risk 6.3 | 2 months ago | 1 month ago |
|
|
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses | Medium Risk 6.5 | 2 months ago | 2 months ago |
|
|
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim in github.com/cloudreve/Cloudreve | Unknown | 2 months ago | 2 months ago |
|
|
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses in github.com/cloudreve/Cloudreve | Unknown | 2 months ago | 2 months ago |
|
|
Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding) in github.com/cloudreve/Cloudreve | Unknown | 3 months ago | 3 months ago |
|
|
Cross site scripting in Cloudreve | Medium Risk 5.4 | 4 years ago | 2 years ago |
Page 1