CVE Browser

More filters (active)
CVE-2026-43891 HIGH

changedetection.io: Arbitrary Local File Read via crafted backup restore

CVSS 7.5 EPSS 0.50% May 12, 2026
CVE-2026-41895 HIGH

changedetection.io: XXE vulnerability in the changedetection.io project

CVSS 8.2 EPSS 0.37% May 12, 2026
CVE-2026-6743 MEDIUM

WebSystems WebTOTUM Calendar cross site scripting

CVSS 5.1 EPSS 0.33% Apr 21, 2026
CVE-2026-35490 CRITICAL

changedetection.io has an Authentication Bypass via Decorator Ordering

CVSS 9.8 EPSS 0.64% Apr 7, 2026
CVE-2026-35000 HIGH

ChangeDetection.io < 0.54.7 SafeXPath3Parser Bypass Arbitrary File Read

CVSS 7.1 EPSS 0.47% Apr 1, 2026
CVE-2026-33981 HIGH

Changedetection.io Discloses Environment Variables via jq env Builtin in Include Filters

CVSS 8.3 EPSS 0.48% Mar 27, 2026
CVE-2026-29065 HIGH

changedetection.io: Zip Slip vulnerability in the backup restore functionality

CVSS 8.8 EPSS 0.58% Mar 6, 2026
CVE-2026-29039 HIGH

changedetection.io: XPath - Arbitrary File Read via unparsed-text()

CVSS 8.8 EPSS 0.53% Mar 6, 2026
CVE-2026-29038 MEDIUM

changedetection.io: Reflected XSS in RSS Tag Error Response

CVSS 6.1 EPSS 0.35% Mar 6, 2026
CVE-2026-27696 HIGH

changedetection.io Vulnerable to Server-Side Request Forgery (SSRF) via Watch URLs

CVSS 8.6 EPSS 0.48% Feb 25, 2026
CVE-2026-27645 MEDIUM

changedetection.io Vulnerable to Reflected XSS in RSS Single Watch Error Response

CVSS 6.1 EPSS 0.49% Feb 25, 2026
CVE-2026-25527 MEDIUM

changedetection.io vulnerable to unauthenticated static path traversal

CVSS 5.3 EPSS 0.89% Feb 19, 2026
CVE-2024-23329 LOW

changedetection.io API endpoint is not secured with API token

CVSS 1.7 EPSS 0.59% Jan 19, 2024
CVE-2023-24769 MEDIUM

Changedetection.io before v0.40.1.1 was discovered to contain a stored cross-site scripting (XSS) vulnerability in the main page. This vulnerability allows att…

CVSS 4.8 EPSS 0.64% Feb 17, 2023
CVE-2021-4236 CRITICAL

Panic or authentication bypass in github.com/ecnepsnai/web

CVSS 9.8 EPSS 1.12% Dec 27, 2022
Go
CVE-2006-2358 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in various scripts in Web-Labs CMS allow remote attackers to inject arbitrary web script or HTML via (1) th…

CVSS 4.3 EPSS 1.18% May 15, 2006

Showing 1 to 16 CVEs · page 1