Vulnerabilities
Last updated 2 hours ago
| Package | Summary | Severity | Published | Modified |
|---|---|---|---|---|
|
|
Nezha: OAuth2 redirect_uri Host header injection regression when dashboard_host is empty | Low Risk 3.0 | 3 hours ago | 3 hours ago |
|
|
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check | Critical 9.9 | 2 months ago | 24 days ago |
|
|
Nezha vulnerable to cross-tenant terminal/file-manager session hijack via WebSocket stream UUID without ownership check in github.com/nezhahq/nezha | Unknown | 2 months ago | 24 days ago |
|
|
Nezha's authenticated agents can forge service-monitor results for other users' services | High Risk 7.1 | 3 months ago | 1 month ago |
|
|
Nezha's authenticated agents can forge service-monitor results for other users' services in github.com/nezhahq/nezha | Unknown | 1 month ago | 1 month ago |
|
|
Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API | Medium Risk 6.0 | 2 months ago | 2 months ago |
|
|
Nezha Dashboard: DDNS and Notification credential exposure via unredacted list API in github.com/nezhahq/nezha | Unknown | 2 months ago | 2 months ago |
|
|
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context | Medium Risk 6.4 | 2 months ago | 2 months ago |
|
|
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key | Critical 9.1 | 2 months ago | 2 months ago |
|
|
Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection | Medium Risk 6.8 | 2 months ago | 2 months ago |
|
|
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS | Medium Risk 6.5 | 2 months ago | 2 months ago |
|
|
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing | Medium Risk 6.5 | 2 months ago | 2 months ago |
|
|
Nezha Monitoring: Pre-auth path traversal via /dashboard.. prefix confusion leaks jwt_secret_key in github.com/nezhahq/nezha | Unknown | 2 months ago | 2 months ago |
|
|
Nezha Monitoring: Unbounded WebSocket Streams — Resource Exhaustion DoS in github.com/nezhahq/nezha | Unknown | 2 months ago | 2 months ago |
|
|
Nezha Monitoring: Authenticated users can claim the dashboard Host through NAT and preempt all dashboard routing in github.com/nezhahq/nezha | Unknown | 2 months ago | 2 months ago |
|
|
Nezha Monitoring: OAuth2 Redirect URL — Host Header Injection in github.com/nezhahq/nezha | Unknown | 2 months ago | 2 months ago |
|
|
Nezha Monitoring: Stored future DDNS profile ID allows unauthorized use of another user's DDNS profile context in github.com/nezhahq/nezha | Unknown | 2 months ago | 2 months ago |
|
|
Nezha's authenticated DDNS webhook configuration allows blind SSRF from the dashboard host | Medium Risk 6.4 | 3 months ago | 2 months ago |
|
|
Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents | High Risk 7.1 | 3 months ago | 2 months ago |
|
|
Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron | Critical 9.9 | 3 months ago | 2 months ago |
|
|
Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members | Medium Risk 6.5 | 3 months ago | 2 months ago |
|
|
Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check) | Medium Risk 5.4 | 3 months ago | 2 months ago |
|
|
Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data | Medium Risk 5.3 | 3 months ago | 2 months ago |
|
|
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification | High Risk 8.5 | 3 months ago | 2 months ago |
|
|
Nezha Monitoring: RoleMember-reachable SSRF with full response-body reflection via POST /api/v1/notification in github.com/nezhahq/nezha | Unknown | 2 months ago | 2 months ago |
|
|
Nezha Monitoring: RoleMember can fire other users' cron tasks via AlertRule.FailTriggerTasks (no ownership check) in github.com/nezhahq/nezha | Unknown | 2 months ago | 2 months ago |
|
|
Nezha's private services (`EnableShowInService: false`) are enumerable via per-server endpoints, leaking name and timing data in github.com/nezhahq/nezha | Unknown | 2 months ago | 2 months ago |
|
|
Nezha Monitoring: Nezha WebSocket server stream discloses cross-tenant server telemetry to authenticated members in github.com/nezhahq/nezha | Unknown | 2 months ago | 2 months ago |
|
|
Nezha has cross-site GET request that can trigger stored cron commands on a victim's agents in github.com/nezhahq/nezha | Unknown | 2 months ago | 2 months ago |
|
|
Nezha Monitoring: RoleMember can run shell on every server (cross-tenant RCE) via POST /api/v1/cron in github.com/nezhahq/nezha | Unknown | 2 months ago | 2 months ago |
Page 1