| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-32729 | Runtipi has a TOTP two-factor authentication bypass via unrestricted brute-force on `/api/auth/verify-totp` | runtipi | runtipi | High | 8.1 | 2026-03-13 21:41:12 | Deep Dive |
| CVE-2026-31881 | Runtipi unauthenticated /api/auth/reset-password allows operator account takeover during active reset window | runtipi | runtipi | High | 7.7 | 2026-03-11 18:37:11 | Deep Dive |
| CVE-2026-25116 | Runtipi vulnerable to unauthenticated docker-compose.yml Overwrite via Path Traversal | runtipi | runtipi | High | 7.6 | 2026-01-29 21:49:49 | Deep Dive |
| CVE-2026-24129 | Runtipi is Vulnerable to Authenticated Arbitrary Remote Code Execution | runtipi | runtipi | High | 8.0 | 2026-01-22 22:41:29 | Deep Dive |