Vulnerabilities
Last updated 1 hour ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
AzuraCast Vulnerable to Liquidsoap Code Injection via Incomplete cleanUpString-to-toRawString Migration in Remote Relay Password Field | High Risk 8.8 | 4 months ago | 1 day ago |
|
|
AzuraCast has Missing Permissions Check on Media File Download, Allowing Cross-Station Data Exfiltration | Medium Risk 6.5 | 4 months ago | 1 day ago |
|
|
AzuraCast's Missing RequireInternalConnection on Liquidsoap API Allows Low-Privilege Metadata Injection and Broadcast Disruption | Medium Risk 6.3 | 4 months ago | 1 day ago |
|
|
AzuraCast: RCE via Liquidsoap string interpolation injection in station metadata and playlist URLs | High Risk 8.7 | 6 months ago | 1 day ago |
|
|
AzuraCast has Password Reset Poisoning via Untrusted X-Forwarded-Host Header that Leads to Account Takeover and 2FA Bypass | High Risk 8.1 | 4 months ago | 4 months ago |
|
|
AzuraCast has Path Traversal in `currentDirectory` Parameter that Enables Remote Code Execution via Media Upload | High Risk 8.8 | 4 months ago | 4 months ago |
|
|
AzuraCast Vulnerable to Pre-Auth File Deletion & Admin RCE | Low Risk 3.1 | 9 months ago | 9 months ago |
|
|
AzuraCast/AzuraCast vulnerable to cross-site scripting | Low Risk 3.5 | 3 years ago | 2 years ago |
|
|
AzuraCast missing brute force prevention | Critical 9.8 | 3 years ago | 2 years ago |
Page 1