| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2025-34171 | CasaOS <= 0.4.15 Unauthenticated File and Debug Data Exposure | IceWhale Tech | CasaOS | 中危 | - | 2026-01-03 21:18:51 | Deep Dive |
| CVE-2024-28232 | Username Enumeration in CasaOS via bypass of CVE-2024-24766 | IceWhaleTech | CasaOS-UserService | Medium | 6.2 | 2024-04-01 16:42:06 | Deep Dive |
| CVE-2024-24766 | CasaOS Username Enumeration | IceWhaleTech | CasaOS-UserService | Medium | 6.2 | 2024-03-06 18:10:26 | Deep Dive |
| CVE-2024-24767 | CasaOS Improper Restriction of Excessive Authentication Attempts vulnerability | IceWhaleTech | CasaOS-UserService | Critical | 9.1 | 2024-03-06 18:06:26 | Deep Dive |
| CVE-2024-24765 | CasaOS-UserService allows unauthorized access to any file | IceWhaleTech | CasaOS-UserService | High | 7.5 | 2024-03-06 17:31:57 | Deep Dive |
| CVE-2023-37469 | CasaOS Command Injection vulnerability | IceWhaleTech | CasaOS | High | 8.8 | 2023-08-24 22:12:10 | Deep Dive |
| CVE-2023-37265 | Incorrect identification of source IP addresses in CasaOS | IceWhaleTech | CasaOS-Gateway | Critical | 9.8 | 2023-07-17 20:59:25 | Deep Dive |
| CVE-2023-37266 | Weak json web token (JWT) secrets in CasaOS | IceWhaleTech | CasaOS | Critical | 9.8 | 2023-07-17 20:57:43 | Deep Dive |