Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2026-33470 Source A security vulnerability in Frigate software allows authenticated users with restricted camera permissions to view snapshots from other cameras they shouldn't have access to, bypassing access controls. |
Frigate | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-32136 Source AdGuard Home has a critical vulnerability where attackers can completely bypass authentication by establishing an HTTP/2 connection via the h2c protocol and then access all administrative functions without providing any login credentials. |
AdGuard Home | Self-hosted apps | Critical | 06.06.2026 |
| CVE-2026-47703 Source AdGuard Home and dnsproxy have a vulnerability in DNS forwarding over DoQ where the DNS ID is set to zero, reducing randomness and potentially allowing attackers to manipulate DNS queries. |
AdGuard Home | Self-hosted apps | Low | 06.06.2026 |
| CVE-2023-25811 Source A vulnerability in Uptime Kuma allows attackers to inject malicious JavaScript code into status page names, which then executes in other users' browsers and can compromise their sessions. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2023-25810 Source A vulnerability in Uptime Kuma allows attackers to inject malicious JavaScript code into status page descriptions, which then executes when other users view those pages. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2023-36821 Source A vulnerability in Uptime Kuma monitoring software allows authenticated users to install malicious plugins that can automatically execute code on the server. |
Uptime Kuma | Self-hosted apps | High | 06.06.2026 |
| CVE-2023-36822 Source A path traversal vulnerability in Uptime Kuma allows authenticated users to delete arbitrary files on the server by using manipulated plugin names, potentially causing system failure and data loss. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2023-44400 Source A vulnerability in Uptime Kuma monitoring software causes user sessions to remain valid even after password changes or long periods of inactivity, allowing attackers with device access to gain persistent account access. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2023-49276 Source A vulnerability in Uptime Kuma allows attackers to inject malicious code into web pages by manipulating the Google Analytics ID field in custom status pages, as user inputs are not properly sanitized. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| GHSA-hfxh-rjv7-2369 Source A vulnerability in Uptime Kuma allows authenticated users to execute arbitrary commands on the server by injecting malicious code into the hostname field of the Tailscale Ping monitor. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2023-49805 Source Uptime Kuma fails to verify the origin of WebSocket connections, allowing third-party websites to access the application on behalf of their visitors and bypass firewall or proxy protections. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2023-49804 Source Uptime Kuma has a vulnerability where logged-in users remain authenticated after password changes, allowing continued account access without re-authentication. This enables unauthorized access to user data even after passwords have been changed. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| GHSA-23q2-5gf8-gjpp Source Uptime Kuma fails to automatically invalidate existing user sessions when authentication is enabled, allowing already logged-in users to retain full access until they manually log out or refresh the page. |
Uptime Kuma | Self-hosted apps | Low | 06.06.2026 |
| CVE-2024-56331 Source A vulnerability in Uptime Kuma allows attackers to read local files from the server by using file:// URLs in the "real-browser" feature that takes screenshots, potentially exposing sensitive system files like /etc/passwd. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| GHSA-hx7h-9vf7-5xhg Source A vulnerability in Uptime Kuma allows administrators to trigger a ReDoS attack through specially crafted URL inputs in notification settings, potentially freezing the web service due to excessive CPU usage. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| GHSA-qjxc-h5jf-c7rj Source A vulnerability in Uptime Kuma allows authenticated attackers to extract sensitive data from internal cloud metadata services through SSRF attacks, potentially exposing access tokens and configuration information. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| GHSA-5px6-fx2w-459r Source A vulnerability in Uptime Kuma allows unauthenticated attackers to access files starting with 'index.' through path traversal, potentially exposing sensitive information from the server's file system. |
Uptime Kuma | Self-hosted apps | High | 06.06.2026 |
| GHSA-vffh-c9pq-4crh Source A vulnerability in Uptime Kuma allows authenticated users to read arbitrary files from the server by injecting malicious templates into webhook notifications. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| GHSA-9fg7-wgm7-57fh Source Uptime Kuma sends RSS feeds for public status pages with incorrect content type as HTML instead of XML, causing browsers to misinterpret the feed and potentially execute scripts. |
Uptime Kuma | Self-hosted apps | Low | 06.06.2026 |
| CVE-2026-32230 Source A security flaw in Uptime Kuma allows unauthenticated users to retrieve average response times of private monitoring services because one API endpoint fails to verify proper authorization. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-33130 Source A security vulnerability in Uptime Kuma allows authenticated users to read arbitrary files from the server by using malicious templates in webhook notifications. |
Uptime Kuma | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2024-56335 Source A vulnerability in Vaultwarden allows attackers with admin rights in one organization to modify or delete groups in other organizations if they know the relevant UUIDs. This can lead to denial of service or privilege escalation. |
Vaultwarden | Self-hosted apps | High | 06.06.2026 |
| CVE-2025-24365 Source A vulnerability in Vaultwarden allows attackers to gain administrator privileges in foreign organizations by manipulating URL parameters while exploiting their own organization rights. |
Vaultwarden | Self-hosted apps | High | 06.06.2026 |
| CVE-2025-24364 Source A vulnerability in Vaultwarden allows attackers with admin access to execute arbitrary code on the server by manipulating configuration settings and uploading specially crafted files. |
Vaultwarden | Self-hosted apps | High | 06.06.2026 |
| GHSA-f7r5-w49x-gxm3 Source A vulnerability in Vaultwarden allows attackers to modify administrator settings without authorization through malicious web pages when the DISABLE_ADMIN_TOKEN option is enabled. |
Vaultwarden | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-27801 Source Vaultwarden password manager up to version 1.34.3 has a two-factor authentication flaw that allows attackers with account access to bypass the six-digit one-time code through repeated attempts and perform protected actions like account deletion. |
Vaultwarden | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-26012 Source A vulnerability in Vaultwarden allows organization members to retrieve all encrypted passwords and data from the organization, even when they should not have access to certain collections. |
Vaultwarden | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-27802 Source A vulnerability in Vaultwarden allows Manager accounts to escalate their privileges and gain unauthorized access to collections not originally assigned to them by exploiting a specific API function. |
Vaultwarden | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-27803 Source Vaultwarden password manager allows users with Manager role to edit and delete collections even when their permission to manage them is explicitly disabled, potentially leading to unauthorized access and data loss. |
Vaultwarden | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-27898 Source A vulnerability in Vaultwarden allows authenticated users to retrieve encrypted password data and attachments belonging to other users through a flawed API endpoint, even though they lack proper authorization. |
Vaultwarden | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-47158 Source A vulnerability in Vaultwarden's SSO login allowed attackers to take over other users' accounts by tricking victims into authenticating through an attacker-controlled login process. |
Vaultwarden | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-33420 Source An authorization flaw in Vaultwarden allows managers with restricted permissions to view names and assignments of all collections in their organization, even though they should only access specific collections assigned to them. |
Vaultwarden | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-31835 Source A vulnerability in Vaultwarden allows attackers with password access to permanently corrupt WebAuthn credentials by sending fake authentication data that gets processed before signature verification, potentially causing permanent denial of two-factor authentication service. |
Vaultwarden | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-47159 Source A vulnerability in Vaultwarden allows attackers to discover which organizations use SSO by submitting arbitrary email addresses, then obtain valid authentication tokens without proving identity ownership. |
Vaultwarden | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-43911 Source A security vulnerability in Vaultwarden allows attackers to maintain account access using old refresh tokens even after users perform security-sensitive actions like password changes. |
Vaultwarden | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-47164 Source A vulnerability in Vaultwarden allowed attackers to impersonate other users by registering an identity with the victim's email address at an Identity Provider and exploiting insufficient email verification in the SSO login process. |
Vaultwarden | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-43912 Source Vaultwarden, a password manager, fails to properly verify that groups and users belong to the same organization, allowing administrators of one organization to gain unauthorized access to passwords and data from other organizations. |
Vaultwarden | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-43913 Source A security vulnerability in Vaultwarden allows invited organization owners to delete the entire organization vault before their invitation is confirmed by existing owners, potentially causing immediate data loss. |
Vaultwarden | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-43914 Source Vaultwarden before version 1.35.4 has a vulnerability that allows attackers to bypass brute-force protection when email 2FA is enabled, enabling password guessing without rate limiting. |
Vaultwarden | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-47160 Source Vaultwarden, a password manager, has a vulnerability in its icon fetching feature that allows attackers to send HTTP requests to internal servers by using IP addresses in alternative formats (decimal, hexadecimal) to bypass security filters. |
Vaultwarden | Self-hosted apps | Medium | 06.06.2026 |
| GHSA-3m6q-h5gj-7mrw Source Gitea uses insecure SSH configurations by default with weak encryption algorithms that are considered compromised or use outdated hash functions, compromising the security of SSH connections. |
Gitea | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-25714 Source A vulnerability in Gitea allows public-only scoped API tokens to access private organization data, despite being restricted to public content only. |
Gitea | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-26231 Source A vulnerability in Gitea allows authenticated users with only read access to push arbitrary commits directly to repositories, bypassing all write access controls, which can lead to complete repository compromise. |
Gitea | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-28699 Source Gitea bypasses OAuth2 permission restrictions when tokens are submitted via HTTP Basic Authentication instead of Bearer tokens, allowing apps with limited scopes to gain write access to user profiles and repositories. |
Gitea | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-27771 Source | Gitea | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-28744 Source A security vulnerability in Gitea allows accessing private Git repositories with OAuth2/Bearer tokens that lack required repository permissions, because scope validation only occurs during Basic authentication but not Bearer authentication. |
Gitea | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-20706 Source A security vulnerability in Gitea allows downloading complete private repository archives using access tokens that only have permissions for other areas like issues, not repository content. |
Gitea | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-27783 Source Three API endpoints in Gitea allow users with limited permissions to read issue template and configuration files from private repositories, even though they should not have access to the code section. |
Gitea | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2021-21402 Source A vulnerability in Jellyfin media servers allows attackers to read arbitrary files from the server, especially on Windows systems. Publicly accessible servers are at risk of sensitive data exposure. |
Jellyfin | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2021-29490 Source Jellyfin media server contains a Server-Side Request Forgery vulnerability in multiple API endpoints that allows unauthenticated attackers to access internal network services, steal data, and scan networks. |
Jellyfin | Self-hosted apps | Medium | 06.06.2026 |