Top technology
Linux 13140
Google 12536
Microsoft 12379
Oracle 6843
Apple 6692
Adobe 6387
Ibm 6336
Cisco 5759
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 5.3
CVE-2025-34171
CasaOS versions up to and including 0.4.15 expose multiple unauthenticated endpoints that allow remote attackers to retrieve sensitive configuration …
Casaos
after 0.4.15
HIGH 7.5
CVE-2024-28232
Go package IceWhaleTech/CasaOS-UserService provides user management functionalities to CasaOS. The Casa OS Login page has disclosed the username enum…
Casaos Userservice
Patch available
HIGH 7.5
CVE-2024-24766
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, the Casa OS Login page…
Casaos Userservice
after 0.4.7
CRITICAL 9.8
CVE-2024-24765
CasaOS-UserService provides user management functionalities to CasaOS. Prior to version 0.4.7, path filtering of the URL for user avatar image files …
Casaos
0.4.7+
CRITICAL 9.8
CVE-2024-24767
CasaOS-UserService provides user management functionalities to CasaOS. Starting in version 0.4.4.3 and prior to version 0.4.7, CasaOS doesn't defend …
Casaos
0.4.7+
HIGH 8.8
CVE-2023-37469
CasaOS is an open-source personal cloud system. Prior to version 0.4.4, if an authenticated user using CasaOS is able to successfully connect to a co…
Casaos
0.4.4+
CRITICAL 9.8
CVE-2023-37265EPSS 7%
CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands …
Casaos
0.4.4+
CRITICAL 9.8
CVE-2023-37266EPSS 7%
CasaOS is an open-source Personal Cloud system. Unauthenticated attackers can craft arbitrary JWTs and access features that usually require authentic…
Casaos
0.4.4+
CRITICAL 9.8
CVE-2022-24193EPSS 6%
CasaOS before v0.2.7 was discovered to contain a command injection vulnerability.
Casaos
0.2.7+