Vulnerabilities
Last updated 46 minutes ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Cloudreve's remote download file paths can escape the selected destination directory | Medium Risk 6.0 | 1 month ago | 16 hours ago |
|
|
Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 16 hours ago |
|
|
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint | Medium Risk 5.3 | 1 month ago | 16 hours ago |
|
|
Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 16 hours ago |
|
|
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests | Medium Risk 5.4 | 2 months ago | 16 hours ago |
|
|
Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 16 hours ago |
|
|
Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service | High Risk 7.1 | 5 days ago | 5 days ago |
|
|
Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses | Medium Risk 6.5 | 5 days ago | 5 days ago |
|
|
Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope | Low Risk 3.8 | 5 days ago | 5 days ago |
|
|
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root | High Risk 7.1 | 1 month ago | 1 month ago |
|
|
Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server | Medium Risk 6.5 | 2 months ago | 1 month ago |
|
|
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings | Medium Risk 4.3 | 2 months ago | 1 month ago |
|
|
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails | Medium Risk 4.3 | 2 months ago | 1 month ago |
|
|
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account | Medium Risk 4.3 | 2 months ago | 1 month ago |
|
|
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials | High Risk 7.1 | 2 months ago | 1 month ago |
|
|
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored | Medium Risk 6.3 | 2 months ago | 1 month ago |
|
|
Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve | Unknown | 1 month ago | 1 month ago |
|
|
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim | High Risk 7.6 | 2 months ago | 2 months ago |
|
|
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses | Medium Risk 6.5 | 2 months ago | 2 months ago |
|
|
Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim in github.com/cloudreve/Cloudreve | Unknown | 2 months ago | 2 months ago |
|
|
Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses in github.com/cloudreve/Cloudreve | Unknown | 2 months ago | 2 months ago |
|
|
Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding) | High Risk 8.1 | 6 months ago | 3 months ago |
|
|
Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding) in github.com/cloudreve/Cloudreve | Unknown | 3 months ago | 3 months ago |
Page 1