28,676 Entries 2,229 Sources 5 Verticals Last sync 8 minutes Live
Dashboard/Self-hosted apps
Vertical

Self-hosted apps

Aktuelle ÄnderungenSelf-hosted apps
Type Item · Event · Source Value · Time
CVE
Sonarr Self-hosted apps High

A vulnerability in Sonarr software allows attackers to bypass authentication when local addresses are exempted from login requirements and no properly configured reverse proxy is used.

CVE-2026-30975
07.06.2026
CVE
Sonarr Self-hosted apps High

A security vulnerability in Sonarr version 4 on Windows systems allows unauthenticated attackers to read arbitrary files, including configuration files containing API keys and system files.

CVE-2026-30976
07.06.2026
CVE
Jellyseerr Self-hosted apps High

An authentication logic flaw in Jellyseerr allows attackers to register unauthorized accounts by using their own Jellyfin server details, even when the application is configured for Plex instead.

CVE-2026-27707
07.06.2026
CVE
Jellyseerr Self-hosted apps Medium

A vulnerability in Jellyseerr allows any authenticated user to retrieve complete settings of other users, including private API keys for Pushover, Pushbullet and Telegram notifications.

CVE-2026-27793
07.06.2026
CVE
Jellyseerr Self-hosted apps Medium

An authorization flaw in Jellyseerr allows authenticated users to view or delete other users' push notification subscriptions and watch data by manipulating the user ID parameter in the URL.

CVE-2026-27792
07.06.2026
CVE
changedetection.io Self-hosted apps Low

A security vulnerability in changedetection.io allows unauthorized users to access watch history data without providing an API key, though the impact is limited since attackers need to know specific watch identifiers.

CVE-2024-23329
07.06.2026
CVE
changedetection.io Self-hosted apps Critical

A critical vulnerability in the website monitoring software changedetection.io allows attackers to execute arbitrary commands on the server by injecting malicious code into notification templates.

CVE-2024-32651
07.06.2026
CVE
changedetection.io Self-hosted apps Medium

A vulnerability in changedetection.io allows attackers to inject malicious JavaScript code through the notification URLs input field, which then executes in the user's browser.

CVE-2024-34061
07.06.2026
CVE
changedetection.io Self-hosted apps Medium

A vulnerability in changedetection.io allows attackers to read local system files through a special URL syntax when WebDriver is used, as security filters can be bypassed.

CVE-2024-51483
07.06.2026
CVE
changedetection.io Self-hosted apps High

A security vulnerability in changedetection.io allows attackers to read any file from the server when a webdriver is enabled and local files should be prohibited.

CVE-2024-51998
07.06.2026
CVE
changedetection.io Self-hosted apps High

A vulnerability in changedetection.io allows attackers to read local files on the server by exploiting insufficient input validation for file URLs.

CVE-2024-56509
07.06.2026
CVE
changedetection.io Self-hosted apps High

A security vulnerability in changedetection.io allows cross-site scripting attacks because error messages from website monitoring filters are not properly sanitized.

CVE-2025-52558
07.06.2026
CVE
changedetection.io Self-hosted apps Low

A vulnerability in changedetection.io allows attackers to store malicious JavaScript URLs through the API, which then execute when users click on these links.

CVE-2025-62780
07.06.2026
CVE
changedetection.io Self-hosted apps Medium

A vulnerability in changedetection.io allows any user without authentication to read application source code through manipulated URLs, exposing internal program logic.

CVE-2026-25527
07.06.2026
CVE
changedetection.io Self-hosted apps High

Changedetection.io has a Server-Side Request Forgery vulnerability where users can monitor internal network URLs, causing the application to fetch sensitive data from internal services and make it accessible through the web interface.

CVE-2026-27696
07.06.2026
CVE
changedetection.io Self-hosted apps Medium

A cross-site scripting vulnerability in changedetection.io allows attackers to inject malicious JavaScript code into error messages that gets executed in users' browsers, potentially stealing session cookies.

CVE-2026-27645
07.06.2026
CVE
changedetection.io Self-hosted apps Medium

A vulnerability in changedetection.io allows cross-site scripting attacks through the RSS tag endpoint, where user input is inserted into HTML responses without proper escaping. Attackers can execute malicious JavaScript code and potentially steal session cookies or take over user accounts.

CVE-2026-29038
07.06.2026
CVE
changedetection.io Self-hosted apps Critical

A vulnerability in the changedetection.io web application allows attackers to read arbitrary files from the server by using malicious XPath expressions in filter fields.

CVE-2026-29039
07.06.2026
CVE
changedetection.io Self-hosted apps Critical

A critical security vulnerability in changedetection.io allows attackers to overwrite arbitrary files on the server by uploading malicious ZIP archives through the backup restore functionality.

CVE-2026-29065
07.06.2026
CVE
changedetection.io Self-hosted apps High

A vulnerability in changedetection.io allows users to read all server environment variables through jq filters, including password hashes and other secrets.

CVE-2026-33981
07.06.2026
CVE
changedetection.io Self-hosted apps Critical

A web monitoring service has a critical authentication flaw where 13 routes are accidentally accessible without login, allowing attackers to download and delete backups containing sensitive data.

CVE-2026-35490
07.06.2026
CVE
changedetection.io Self-hosted apps Medium

An XML processing vulnerability in changedetection.io allows attackers to read local files from the server when they control the content of a monitored XML/RSS URL and XPath filters are used.

CVE-2026-41895
07.06.2026
CVE
changedetection.io Self-hosted apps High

A security vulnerability in changedetection.io allows attackers to read local files on the server by restoring malicious backup files that contain harmful paths in the history file.

CVE-2026-43891
07.06.2026
CVE
Tandoor Recipes Self-hosted apps Critical

A vulnerability in Tandoor Recipes software allows any user to execute arbitrary commands on the server by exploiting unsafe template processing in recipe instructions.

CVE-2025-23211
07.06.2026
Tracked items76
Item Vendor Version As of
AdGuard Home AdGuard v0.107.77 02.06.2026
AdminLTE ColorlibHQ v4.0.0 19.05.2026
AFFiNE toeverything v2026.6.7-canary.1000 07.06.2026
agents wshobson
AndroidUtilCode Blankj 1.31.1 14.10.2022
ant-design-pro ant-design v6.0.2 28.05.2026
Search all 76 items →