Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Vulnerability List
Found 9 results
CVE IDTitleVendorProductSeverityCVSS ScorePublished AtAI Analysis
CVE-2026-32275 Tautulli: Unsanitized JSONP callback parameter allows cross-origin script injection and API key theft TautulliTautulli 中危 -2026-03-30 19:43:07 Deep Dive
CVE-2026-31799 Tautulli: SQL Injection in get_home_stats API endpoint via unsanitised filter parameters TautulliTautulli Medium 4.9 2026-03-30 19:42:57 Deep Dive
CVE-2026-31831 Tautulli: Unauthenticated Path Traversal in `/newsletter/image/images` endpoint TautulliTautulli 中危 -2026-03-30 19:42:23 Deep Dive
CVE-2026-31804 Tautulli: Unauthenticated pms_image_proxy endpoint proxies arbitrary HTTP requests through the Plex Media Server TautulliTautulli Medium 4.0 2026-03-30 19:42:10 Deep Dive
CVE-2026-28505 Tautulli: RCE via eval() sandbox bypass using lambda nested scope to escape co_names whitelist check TautulliTautulli 中危 -2026-03-30 19:41:55 Deep Dive
CVE-2025-58763 Tautulli vulnerable to Authenticated Remote Code Execution via Command Injection TautulliTautulli High 8.0 2025-09-09 20:13:45 Deep Dive
CVE-2025-58762 Tautulli vulnerable to Authenticated Remote Code Execution via write primitive and `Script` notification agent TautulliTautulli Critical 9.1 2025-09-09 20:08:28 Deep Dive
CVE-2025-58761 Tautulli vulnerable to Unauthenticated Path Traversal in `real_pms_image_proxy` TautulliTautulli High 8.6 2025-09-09 19:59:17 Deep Dive
CVE-2025-58760 Tautulli vulnerable to Unauthenticated Path Traversal in `/image` endpoint TautulliTautulli High 8.6 2025-09-09 19:56:58 Deep Dive