Vulnerability index

Browse CVEs

9 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Alist HIGH 8.8
CVE-2026-25161

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application contains path trav…

Fix: 3.57.0+
Fix from $1,950 2026-02-04
Alist HIGH 7.4
CVE-2026-25160

Alist is a file list program that supports multiple storages, powered by Gin and Solidjs. Prior to version 3.57.0, the application disables TLS certi…

Fix: 3.57.0+
Fix from $1,950 2026-02-04
Alist MEDIUM 6.1
CVE-2024-47067

AList is a file list program that supports multiple storages. AList contains a reflected cross-site scripting vulnerability in helper.go. The endpoin…

Fix: 3.29.0+
Fix from $1,600 2024-09-30
Alist HIGH 8.8
CVE-2023-33498

alist <=3.16.3 is vulnerable to Incorrect Access Control. Low privilege accounts can upload any file.

Fix: 3.16.3+
Fix from $1,950 2023-06-07
Alist HIGH 7.5
CVE-2023-31726

AList 3.15.1 is vulnerable to Incorrect Access Control, which can be exploited by attackers to obtain sensitive information.

No fix yet
Fix from $1,950 2023-05-23
Alist CRITICAL 9.8
CVE-2022-45969

Alist v3.4.0 is vulnerable to Directory Traversal,

Patch available
Fix from $2,300 2022-12-15
Alist HIGH 8.8
CVE-2022-45968

Alist v3.4.0 is vulnerable to File Upload. A user with only file upload permission can upload any file to any folder (even a password protected one).

No fix yet
Fix from $1,950 2022-12-12
Alist MEDIUM 5.4
CVE-2022-45970

Alist v3.5.1 is vulnerable to Cross Site Scripting (XSS) via the bulletin board.

No fix yet
Fix from $1,600 2022-12-12
Alist MEDIUM 6.1
CVE-2022-26533

Alist v2.1.0 and below was discovered to contain a cross-site scripting (XSS) vulnerability via /i/:data/ipa.plist.

Fix: after 2.1.0
Fix from $1,600 2022-03-12