Vulnerability index

Browse CVEs

18 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 6.1 CVE-2021-3988 A Cross-site Scripting (XSS) vulnerability exists in janeczku/calibre-web, specifically in the file `edit_books.js`. The vulnerability occurs when ed… Calibre Web 0.6.15+ Fix from $1,6002024-11-15 MEDIUM 5.4 CVE-2024-39123EPSS 23% In janeczku Calibre-Web 0.6.0 to 0.6.21, the edit_book_comments function is vulnerable to Cross Site Scripting (XSS) due to improper sanitization per… Calibre Web after 0.6.21 Fix from $1,6002024-07-19 CRITICAL 9.8 CVE-2023-2106 Weak Password Requirements in GitHub repository janeczku/calibre-web prior to 0.6.20. Calibre Web 0.6.20+ Fix from $2,3002023-04-15 CRITICAL 9.8 CVE-2022-2525 Improper Restriction of Excessive Authentication Attempts in GitHub repository janeczku/calibre-web prior to 0.6.20. Calibre Web 0.6.20+ Fix from $2,3002023-04-15 CRITICAL 9.8 CVE-2022-30765 Calibre-Web before 0.6.18 allows user table SQL Injection. Calibre Web Mitigation only Fix from $2,3002022-05-16 CRITICAL 9.1 CVE-2022-0990 Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. Calibre Web 0.6.18+ Fix from $2,3002022-04-04 CRITICAL 9.9 CVE-2022-0939 Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.18. Calibre Web 0.6.18+ Fix from $2,3002022-04-04 CRITICAL 9.9 CVE-2022-0767 Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. Calibre Web 0.6.17+ Fix from $2,3002022-03-07 CRITICAL 9.8 CVE-2022-0766 Server-Side Request Forgery (SSRF) in GitHub repository janeczku/calibre-web prior to 0.6.17. Calibre Web 0.6.17+ Fix from $2,3002022-03-07 CRITICAL 9.8 CVE-2022-0339 Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16. Calibre Web 0.6.16+ Fix from $2,3002022-01-30 MEDIUM 6.5 CVE-2022-0273 Improper Access Control in Pypi calibreweb prior to 0.6.16. Calibre Web 0.6.16+ Fix from $1,6002022-01-30 MEDIUM 6.1 CVE-2022-0352 Cross-site Scripting (XSS) - Reflected in Pypi calibreweb prior to 0.6.16. Calibre Web 0.6.16+ Fix from $1,6002022-01-28 HIGH 8.8 CVE-2021-4164 calibre-web is vulnerable to Cross-Site Request Forgery (CSRF) Calibre Web 0.6.15+ Fix from $1,9502022-01-17 CRITICAL 9.8 CVE-2021-4171 calibre-web is vulnerable to Business Logic Errors Calibre Web 0.6.15+ Fix from $2,3002022-01-17 MEDIUM 5.4 CVE-2021-4170 calibre-web is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Calibre Web 0.6.15+ Fix from $1,6002022-01-16 HIGH 8.8 CVE-2021-25965 In Calibre-web, versions 0.6.0 to 0.6.13 are vulnerable to Cross-Site Request Forgery (CSRF). By luring an authenticated user to click on a link, an … Calibre Web after 0.6.13 Fix from $1,9502021-11-16 MEDIUM 5.4 CVE-2021-25964 In “Calibre-web” application, v0.6.0 to v0.6.12, are vulnerable to Stored XSS in “Metadata”. An attacker that has access to edit the metadata informa… Calibre Web 0.6.12+ Fix from $1,6002021-10-04 CRITICAL 9.8 CVE-2020-12627 Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key. Calibre Web Patch available Fix from $2,3002020-05-04