| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-40611 | Lego: Arbitrary File Write via Path Traversal in Webroot HTTP-01 Provider | go-acme | lego | High | 8.8 | 2026-04-21 17:58:35 | Deep Dive |
| CVE-2025-62487 | Under certain configurations, file artifacts uploaded to the Dossier and Slides apps did not inherit security markings of their parent artifact. This lack of security markings could lead to unintended access to the uploaded files. | Palantir | com.palantir.acme:gotham-default-apps-bundle | Low | 3.5 | 2026-01-09 21:17:37 | Deep Dive |
| CVE-2023-30971 | Gaia unauthenticated endpoints | Palantir | com.palantir.acme.gaia:gaia | Medium | 6.8 | 2025-12-19 16:34:19 | Deep Dive |
| CVE-2025-54799 | Lego does not enforce HTTPS | go-acme | lego | - | - | 2025-08-07 00:04:15 | Deep Dive |
| CVE-2025-32111 | acme.sh 安全漏洞 | acme.sh project | acme.sh | High | 8.7 | 2025-04-04 00:00:00 | Deep Dive |
| CVE-2025-31540 | WordPress ACME Divi Modules plugin <= 1.3.5 - Broken Access Control vulnerability | acmemediakits | ACME Divi Modules | Medium | 4.3 | 2025-03-31 12:55:12 | Deep Dive |
| CVE-2023-47793 | WordPress Acme Fix Images plugin <= 1.0.0 - Broken Access Control vulnerability | Acme Themes | Acme Fix Images | 中危 | - | 2024-12-09 11:30:46 | Deep Dive |
| CVE-2022-30636 | Limited directory traversal vulnerability on Windows in golang.org/x/crypto | golang.org/x/crypto | golang.org/x/crypto/acme/autocert | - | - | 2024-07-02 19:51:47 | Deep Dive |
| CVE-2023-30968 | Stored XSS in gaia | Palantir | com.palantir.acme.gaia:gaia | Medium | 6.8 | 2024-03-12 19:39:24 | Deep Dive |
| CVE-2024-0263 | ACME Ultra Mini HTTPd HTTP GET Request denial of service | ACME | Ultra Mini HTTPd | Medium | 5.3 | 2024-01-07 03:31:04 | Deep Dive |
| CVE-2023-30961 | Palantir Gotham UI bug that could lead to incorrect data classification | Palantir | com.palantir.acme:gotham-fe-bundle | Medium | 6.5 | 2023-09-26 18:01:07 | Deep Dive |
| CVE-2023-30962 | Stored XSS in cerberus attachments | Palantir | com.palantir.acme.cerberus:cerberus | Medium | 6.8 | 2023-09-12 18:29:42 | Deep Dive |