Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Associated Vulnerability
Found 3 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-40304 zrok's broken ownership check in DELETE /api/v2/unaccess allows non-admin to delete global frontend records openzitizrok Medium 5.3 2026-04-17 21:04:24 Deep Dive
CVE-2026-40303 zrok allows unauthenticated DoS via unbounded memory allocation in striped session cookie parsing openzitizrok High 7.5 2026-04-17 21:01:52 Deep Dive
CVE-2026-40302 zrok has reflected XSS in GitHub OAuth callback via unsanitized refreshInterval error rendering openzitizrok Medium 6.1 2026-04-17 20:56:08 Deep Dive