Vulnerability index

Browse CVEs

10 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Navidrome MEDIUM 6.5
CVE-2026-25579

Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, authenticated users can crash the Navidrome serv…

Fix: 0.60.0+
Fix from $1,600 2026-02-04
Navidrome MEDIUM 6.1
CVE-2026-25578

Navidrome is an open source web-based music collection server and streamer. Prior to version 0.60.0, a cross-site scripting vulnerability in the fron…

Fix: 0.60.0+
Fix from $1,600 2026-02-04
Navidrome CRITICAL 9.8
CVE-2025-48949

Navidrome is an open source web-based music collection server and streamer. Versions 0.55.0 through 0.55.2 have a vulnerability due to improper input…

Fix: 0.56.0+
Fix from $2,300 2025-05-30
Navidrome MEDIUM 6.5
CVE-2025-48948

Navidrome is an open source web-based music collection server and streamer. A permission verification flaw in versions prior to 0.56.0 allows any aut…

Fix: 0.56.0+
Fix from $1,600 2025-05-30
Navidrome MEDIUM 6.5
CVE-2025-27112

Navidrome is an open source web-based music collection server and streamer. Starting in version 0.52.0 and prior to version 0.54.5, in certain Subson…

Fix: 0.54.5+
Fix from $1,600 2025-02-24
Navidrome MEDIUM 5.5
CVE-2024-56362

Navidrome is an open source web-based music collection server and streamer. Navidrome stores the JWT secret in plaintext in the navidrome.db database…

Fix: 0.54.1+
Fix from $1,600 2024-12-23
Navidrome HIGH 8.8
CVE-2024-47062

Navidrome is an open source web-based music collection server and streamer. Navidrome automatically adds parameters in the URL to SQL queries. This c…

Fix: 0.53.0+
Fix from $1,950 2024-09-20
Navidrome CRITICAL 9.1
CVE-2024-41259

Use of insecure hashing algorithm in the Gravatar's service in Navidrome v0.52.3 allows attackers to manipulate a user's account information.

Fix: after 0.52.3
Fix from $2,300 2024-08-01
Navidrome HIGH 8.6
CVE-2023-51442

Navidrome is an open source web-based music collection server and streamer. A security vulnerability has been identified in navidrome's subsonic endp…

Fix: 0.50.2+
Fix from $1,950 2023-12-21
Navidrome MEDIUM 6.5
CVE-2022-23857

model/criteria/criteria.go in Navidrome before 0.47.5 is vulnerable to SQL injection attacks when processing crafted Smart Playlists. An authenticate…

Fix: 0.47.5+
Fix from $1,600 2022-01-24