Top technology
Linux 13140
Google 12530
Microsoft 12379
Oracle 6737
Apple 6692
Adobe 6387
Ibm 6330
Cisco 5757
Debian 3919
Mozilla 2895
Apache 2864
Redhat 2592
MEDIUM 6.1
CVE-2021-3988
A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The vulnerability occurs when ed…
Calibre Web
0.6.15+
MEDIUM 5.4
CVE-2024-39123EPSS 23%
In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization per…
Calibre Web
after 0.6.21
CRITICAL 9.8
CVE-2023-2106
Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20.
Calibre Web
0.6.20+
CRITICAL 9.8
CVE-2022-2525
Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20.
Calibre Web
0.6.20+
CRITICAL 9.8
CVE-2022-30765
Calibre-Web before 0.6.18 allows user table SQL Injection.
Calibre Web
Mitigation only
CRITICAL 9.1
CVE-2022-0990
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
Calibre Web
0.6.18+
CRITICAL 9.9
CVE-2022-0939
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18.
Calibre Web
0.6.18+
CRITICAL 9.9
CVE-2022-0767
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
Calibre Web
0.6.17+
CRITICAL 9.8
CVE-2022-0766
Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17.
Calibre Web
0.6.17+
CRITICAL 9.8
CVE-2022-0339
Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.
Calibre Web
0.6.16+
MEDIUM 6.5
CVE-2022-0273
Improper Access Control in Pypi calibreweb prior to 0.6.16.
Calibre Web
0.6.16+
MEDIUM 6.1
CVE-2022-0352
Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16.
Calibre Web
0.6.16+
HIGH 8.8
CVE-2021-4164
calibre-web is vulnerable to Cross-Site Request Forgery (CSRF)
Calibre Web
0.6.15+
CRITICAL 9.8
CVE-2021-4171
calibre-web is vulnerable to Business Logic Errors
Calibre Web
0.6.15+
MEDIUM 5.4
CVE-2021-4170
calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Calibre Web
0.6.15+
HIGH 8.8
CVE-2021-25965
In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an …
Calibre Web
after 0.6.13
MEDIUM 5.4
CVE-2021-25964
In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata informa…
Calibre Web
0.6.12+
CRITICAL 9.8
CVE-2020-12627
Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.
Calibre Web
Patch available