Vulnerabilities (CVE)

Filtered by vendor Calibre-web Project Subscribe
Filtered by product Calibre-web
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-30765 1 Calibre-web Project 1 Calibre-web 2022-05-24 7.5 HIGH 9.8 CRITICAL
Calibre-Web before 0.6.18 allows user table SQL Injection.
CVE-2022-0339 1 Calibre-web Project 1 Calibre-web 2022-02-14 7.5 HIGH 9.8 CRITICAL
Server-Side Request Forgery (SSRF) in Pypi calibreweb prior to 0.6.16.
CVE-2021-4171 1 Calibre-web Project 1 Calibre-web 2022-01-24 7.5 HIGH 9.8 CRITICAL
calibre-web is vulnerable to Business Logic Errors
CVE-2020-12627 1 Calibre-web Project 1 Calibre-web 2021-07-21 7.5 HIGH 9.8 CRITICAL
Calibre-Web 0.6.6 allows authentication bypass because of the 'A0Zr98j/3yX R~XHH!jmN]LWX/,?RT' hardcoded secret key.