Vulnerabilities

Last updated 1 hour ago
Filters
Severity
Critical Severity
CVSS Score Range: 9.0–10.0
Critical severity vulnerabilities (CVSS 9.0–10.0). These represent the highest impact issues.
High Severity
CVSS Score Range: 7.0–8.9
High severity vulnerabilities (CVSS 7.0–8.9). Serious vulnerabilities that should be prioritized soon after critical fixes.
Medium Severity
CVSS Score Range: 4.0–6.9
Medium severity vulnerabilities (CVSS 4.0–6.9). Important issues that meaningfully reduce security confidence.
Low Severity
CVSS Score Range: < 4.0
Low severity vulnerabilities (CVSS < 4.0). Hygiene issues that can accumulate but pose lower immediate risk.
Unknown Severity
CVSS Score Range: No score
Vulnerabilities without an assigned CVSS score. Severity is not determinable from available data.
Package Summary Severity Published Modified
github.com/cloudreve/Cloudreve/v4 Cloudreve's remote download file paths can escape the selected destination directory Medium Risk 6.0 1 month ago 15 hours ago
github.com/cloudreve/Cloudreve/v4 Cloudreve's remote download file paths can escape the selected destination directory in github.com/cloudreve/Cloudreve Unknown 1 month ago 15 hours ago
github.com/cloudreve/Cloudreve/v4 Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint Medium Risk 5.3 1 month ago 15 hours ago
github.com/cloudreve/Cloudreve/v4 Cloudreve has Broken Access Control - Revoked Share Access Still Allows Signed File URL Generation via Cached context_hint in github.com/cloudreve/Cloudreve Unknown 1 month ago 15 hours ago
github.com/cloudreve/Cloudreve/v4 Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests Medium Risk 5.4 2 months ago 15 hours ago
github.com/cloudreve/Cloudreve/v4 Cloudreve Admin.Read OAuth tokens can trigger server-side node test requests in github.com/cloudreve/Cloudreve Unknown 1 month ago 15 hours ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: Storage-quota TOCTOU race allows quota bypass and storage-based denial of service High Risk 7.1 5 days ago 5 days ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: SSRF guard bypass: checkIP does not decode IPv6-transition wrappers (NAT64, IPv4-compatible, 6to4) reaching internal and cloud-metadata addresses Medium Risk 6.5 5 days ago 5 days ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: Privilege Scope Bypass: State-Mutating Admin Operations Accessible via Read-Only OAuth Scope Low Risk 3.8 5 days ago 5 days ago
github.com/cloudreve/Cloudreve/v4 Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root High Risk 7.1 1 month ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve WebDAV (`/dav`) has Path Traversal / Broken Access Control — scoped DAV credential escapes its configured account root in github.com/cloudreve/Cloudreve Unknown 1 month ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server Medium Risk 6.5 2 months ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings Medium Risk 4.3 2 months ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails Medium Risk 4.3 2 months ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account Medium Risk 4.3 2 months ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials High Risk 7.1 2 months ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored Medium Risk 6.3 2 months ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: Path Traversal in WOPI PUT_RELATIVE Allows Arbitrary File Creation in Owner Account in github.com/cloudreve/Cloudreve Unknown 1 month ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve OAuth Admin.Read scope can update OneDrive storage policy credentials in github.com/cloudreve/Cloudreve Unknown 1 month ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: Information Exposure in `GET /api/v4/user/search`: `SearchActive` omits the active-status predicate, leaking inactive/banned account emails in github.com/cloudreve/Cloudreve Unknown 1 month ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: Broken Access Control in file event stream: a single-file share recipient is subscribed to the owner's parent folder and receives activity events for unshared siblings in github.com/cloudreve/Cloudreve Unknown 1 month ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: Denial of Service - Image decompression / pixel bomb in thumbnail & avatar decoding crashes the server in github.com/cloudreve/Cloudreve Unknown 1 month ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve WOPI view sessions can write files and WOPI access token secret is ignored in github.com/cloudreve/Cloudreve Unknown 1 month ago 1 month ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim High Risk 7.6 2 months ago 2 months ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses Medium Risk 6.5 2 months ago 2 months ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: OAuth access tokens bypass scope enforcement due to missing client_id claim in github.com/cloudreve/Cloudreve Unknown 2 months ago 2 months ago
github.com/cloudreve/Cloudreve/v4 Cloudreve: Non-admin remote download users can SSRF loopback/internal services and read imported responses in github.com/cloudreve/Cloudreve Unknown 2 months ago 2 months ago
github.com/cloudreve/Cloudreve/v4 Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding) High Risk 8.1 6 months ago 3 months ago
github.com/cloudreve/Cloudreve/v4 Cloudreve is vulnerable to Account Takeover via Weak Cryptographic Token Generation (Insecure PRNG Seeding) in github.com/cloudreve/Cloudreve Unknown 3 months ago 3 months ago