Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2025-67733 Source A flaw in Valkey's Lua script error handling allows malicious users to inject arbitrary data into responses, potentially serving tampered data to other users on the same connection. |
Valkey | OS & platform | High | 07.06.2026 |
| CVE-2026-21863 Source A vulnerability in Valkey allows attackers with access to the clusterbus port to trigger a memory error through invalid packets, potentially causing the Valkey process to crash. |
Valkey | OS & platform | Medium | 07.06.2026 |
| CVE-2026-27623 Source A vulnerability in the Valkey database allows attackers with network access to crash the server by sending specially crafted requests, as the software fails to properly reset networking state after processing empty requests. |
Valkey | OS & platform | High | 07.06.2026 |
| CVE-2020-11012 Source MinIO object storage contains a vulnerability that allows attackers to perform admin functions without the required secret password when they already possess an admin access key. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2021-21287 Source MinIO storage software contains a vulnerability in its browser API that allows attackers to access internal server services or read sensitive configuration data by manipulating URLs. |
MinIO | OS & platform | Medium | 07.06.2026 |
| CVE-2021-21362 Source MinIO storage systems with multiple users have a security vulnerability in handling multipart/form-data uploads that affects all multi-user installations and poses medium-level risks. |
MinIO | OS & platform | Medium | 07.06.2026 |
| CVE-2021-21390 Source MinIO object storage fails to properly verify data integrity for certain upload requests when attackers send false chunk sizes. This allows man-in-the-middle attacks to modify data during transmission. |
MinIO | OS & platform | Medium | 07.06.2026 |
| CVE-2021-41137 Source A faulty permission check in MinIO allowed regular users to access data and functions they should not have been authorized to use. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2021-43858 Source A vulnerability in MinIO allows authenticated users to escalate their own privileges by abusing a user creation/update API function to grant themselves higher privileges than originally assigned. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2022-24842 Source A security flaw in MinIO allows regular users to create service accounts for administrator users and assume their elevated access privileges, leading to privilege escalation. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2022-31028 Source MinIO object storage has a vulnerability where malicious HTTP clients can create endless Go routines by keeping connections open, leading to resource exhaustion and denial of service. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2022-35919 Source A vulnerability in MinIO allows administrators with ServerUpdate permissions to read arbitrary files from the server by making a malformed update request that returns the file content in the error response. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2023-25812 Source MinIO object storage incorrectly ignores deny rules for bypassing governance locks when allow rules for all S3 actions exist simultaneously, enabling users to delete protected objects. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2023-27589 Source An administrator with special permissions can create a user in MinIO that matches the root account name, permanently disabling root access to the system. |
MinIO | OS & platform | Medium | 07.06.2026 |
| CVE-2023-28433 Source MinIO on Windows systems fails to properly filter backslash characters, allowing users with limited permissions to place objects in arbitrary buckets and even create admin users. |
MinIO | OS & platform | Critical | 07.06.2026 |
| CVE-2023-28434 Source A security vulnerability in MinIO allows attackers with certain permissions to bypass bucket name validation through crafted requests and write objects to any bucket. |
MinIO | OS & platform | Critical | 07.06.2026 |
| CVE-2023-28432 Source MinIO clusters accidentally expose all environment variables including secret passwords and keys through an internal interface, potentially compromising sensitive authentication credentials. |
MinIO | OS & platform | Critical | 07.06.2026 |
| CVE-2024-24747 Source MinIO storage system allows users with restricted access keys to escalate their own permissions and access all data, because access keys inherit admin rights by default. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2024-36107 Source MinIO object storage checked HTTP conditions before permissions, allowing anonymous users to discover if objects exist and view their metadata like modification dates or cache settings through crafted requests. |
MinIO | OS & platform | Medium | 07.06.2026 |
| CVE-2024-55949 Source A vulnerability in MinIO allows users to escalate their own privileges by manipulating an IAM import file to gain administrator rights. |
MinIO | OS & platform | Critical | 07.06.2026 |
| CVE-2025-27414 Source A bug in MinIO's SFTP authentication allows attackers to bypass login without valid SSH keys when LDAP users have no SSH keys configured, enabling unauthorized access to files. |
MinIO | OS & platform | Medium | 07.06.2026 |
| CVE-2025-31489 Source A vulnerability in MinIO allows attackers to upload arbitrary files to buckets when they already have write permissions and knowledge of the access key, due to faulty signature verification. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2025-62506 Source A vulnerability in MinIO allows restricted service and STS accounts to bypass their permission limitations by creating new service accounts for themselves, thereby gaining elevated access rights to buckets and objects beyond their intended restrictions. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2026-33322 Source A vulnerability in MinIO's OpenID Connect authentication allows attackers who know the OIDC client secret to forge arbitrary user identities and gain complete access to all stored data. |
MinIO | OS & platform | Medium | 07.06.2026 |
| CVE-2026-33419 Source MinIO AIStor's authentication service has two vulnerabilities: attackers can guess valid usernames and then try unlimited passwords without rate limiting. This allows them to gain access to S3 storage buckets. |
MinIO | OS & platform | Medium | 07.06.2026 |
| CVE-2026-34204 Source A vulnerability in MinIO allows authenticated users with upload permissions to inject fake encryption metadata into objects, making them permanently unreadable and enabling targeted denial-of-service attacks. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2026-39414 Source MinIO's S3 Select feature has a vulnerability where specially crafted CSV files without newline characters can crash the server by exhausting all available memory. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2026-40344 Source A vulnerability in MinIO allows attackers to write arbitrary files to any bucket without knowing the secret password - only requiring a valid username. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2026-41145 Source A vulnerability in MinIO allows attackers to upload arbitrary files to buckets without knowing the secret password, requiring only a valid username. |
MinIO | OS & platform | High | 07.06.2026 |
| CVE-2026-42600 Source A path traversal vulnerability in MinIO allows attackers with root credentials to read files outside configured storage directories, potentially exposing sensitive data like TLS keys or system files. |
MinIO | OS & platform | Medium | 07.06.2026 |
| CVE-2026-30975 Source A vulnerability in Sonarr software allows attackers to bypass authentication when local addresses are exempted from login requirements and no properly configured reverse proxy is used. |
Sonarr | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-30976 Source A security vulnerability in Sonarr version 4 on Windows systems allows unauthenticated attackers to read arbitrary files, including configuration files containing API keys and system files. |
Sonarr | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-27707 Source An authentication logic flaw in Jellyseerr allows attackers to register unauthorized accounts by using their own Jellyfin server details, even when the application is configured for Plex instead. |
Jellyseerr | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-27793 Source A vulnerability in Jellyseerr allows any authenticated user to retrieve complete settings of other users, including private API keys for Pushover, Pushbullet and Telegram notifications. |
Jellyseerr | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-27792 Source An authorization flaw in Jellyseerr allows authenticated users to view or delete other users' push notification subscriptions and watch data by manipulating the user ID parameter in the URL. |
Jellyseerr | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2024-23329 Source A security vulnerability in changedetection.io allows unauthorized users to access watch history data without providing an API key, though the impact is limited since attackers need to know specific watch identifiers. |
changedetection.io | Self-hosted apps | Low | 07.06.2026 |
| CVE-2024-32651 Source A critical vulnerability in the website monitoring software changedetection.io allows attackers to execute arbitrary commands on the server by injecting malicious code into notification templates. |
changedetection.io | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2024-34061 Source A vulnerability in changedetection.io allows attackers to inject malicious JavaScript code through the notification URLs input field, which then executes in the user's browser. |
changedetection.io | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2024-51483 Source A vulnerability in changedetection.io allows attackers to read local system files through a special URL syntax when WebDriver is used, as security filters can be bypassed. |
changedetection.io | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2024-51998 Source A security vulnerability in changedetection.io allows attackers to read any file from the server when a webdriver is enabled and local files should be prohibited. |
changedetection.io | Self-hosted apps | High | 07.06.2026 |
| CVE-2024-56509 Source A vulnerability in changedetection.io allows attackers to read local files on the server by exploiting insufficient input validation for file URLs. |
changedetection.io | Self-hosted apps | High | 07.06.2026 |
| CVE-2025-52558 Source A security vulnerability in changedetection.io allows cross-site scripting attacks because error messages from website monitoring filters are not properly sanitized. |
changedetection.io | Self-hosted apps | High | 07.06.2026 |
| CVE-2025-62780 Source A vulnerability in changedetection.io allows attackers to store malicious JavaScript URLs through the API, which then execute when users click on these links. |
changedetection.io | Self-hosted apps | Low | 07.06.2026 |
| CVE-2026-25527 Source A vulnerability in changedetection.io allows any user without authentication to read application source code through manipulated URLs, exposing internal program logic. |
changedetection.io | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-27696 Source Changedetection.io has a Server-Side Request Forgery vulnerability where users can monitor internal network URLs, causing the application to fetch sensitive data from internal services and make it accessible through the web interface. |
changedetection.io | Self-hosted apps | High | 07.06.2026 |
| CVE-2026-27645 Source A cross-site scripting vulnerability in changedetection.io allows attackers to inject malicious JavaScript code into error messages that gets executed in users' browsers, potentially stealing session cookies. |
changedetection.io | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-29038 Source A vulnerability in changedetection.io allows cross-site scripting attacks through the RSS tag endpoint, where user input is inserted into HTML responses without proper escaping. Attackers can execute malicious JavaScript code and potentially steal session cookies or take over user accounts. |
changedetection.io | Self-hosted apps | Medium | 07.06.2026 |
| CVE-2026-29039 Source A vulnerability in the changedetection.io web application allows attackers to read arbitrary files from the server by using malicious XPath expressions in filter fields. |
changedetection.io | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-29065 Source A critical security vulnerability in changedetection.io allows attackers to overwrite arbitrary files on the server by uploading malicious ZIP archives through the backup restore functionality. |
changedetection.io | Self-hosted apps | Critical | 07.06.2026 |
| CVE-2026-33981 Source A vulnerability in changedetection.io allows users to read all server environment variables through jq filters, including password hashes and other secrets. |
changedetection.io | Self-hosted apps | High | 07.06.2026 |