From Discovery to Disclosure
Explore publicly disclosed CVEs XBOW discovered across widely used products and platforms, with severity ratings and summaries of their technical impact.
CVE-2026-74502
- Product
Linux Kernel
- Severity
High (7.8)
- Description
ALSA: ump: fix double free of out_cvts on rawmidi error
- Notes
CVE-2026-74501
- Product
Linux Kernel
- Severity
High (7.3)
- Description
ALSA: usb-audio: fix use-after-free in ump_to_endpoint()
- Notes
CVE-2026-74500
- Product
Linux Kernel
- Severity
Medium (5.5)
- Description
ALSA: usb-audio: fix stack info leak in RME Digiface status
- Notes
CVE-2026-74499
- Product
Linux Kernel
- Severity
High (7.8)
- Description
ALSA: usb-audio: fix OOB write in snd_usbmidi_akai_output()
- Notes
CVE-2026-72018
- Product
Linux Kernel
- Severity
High (7.8)
- Description
LPE: Out-of-bounds write in the Linux kernel SMC-D subsystem.
- Notes
CVE-2026-59774
- Product
Gitea
- Severity
Critical (9.8)
- Description
Unauthenticated Arbitrary File Read can lead to RCE
- Notes
CVE-2026-19168
- Product
Google Chrome
- Severity
High
- Description
Inappropriate implementation in V8
- Notes
CVE-2026-16421
- Product
Google Chrome
- Severity
High
- Description
Type Confusion in WebAudio.
- Notes
CVE-2026-16420
- Product
Google Chrome
- Severity
High
- Description
Inappropriate implementation in WebAudio.
- Notes
CVE-2026-16353
- Product
Firefox
- Severity
High
- Description
Invalid pointer in the DOM: Bindings (WebIDL) component
- Notes
CVE-2026-45185
- Product
Exim
- Severity
Critical (9.8)
- Description
Use-after-free in Exim's BDAT body parsing path under certain GnuTLS configurations, allowing unauthenticated remote code execution.
- Notes
CVE-2026-32194
- Product
Microsoft Bing Images
- Severity
Critical (9.8)
- Description
Command injection in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.
- Notes
CVE-2026-32191
- Product
Microsoft Bing Images
- Severity
Critical (9.8)
- Description
OS command injection in Microsoft Bing Images allows an unauthorized attacker to execute code over a network.
- Notes
CVE-2026-22589
- Product
Spree Commerce
- Severity
High (7.5)
- Description
Unauthenticated IDOR in Spree API allows access to guest address information without valid credentials or session cookies.
- Notes
CVE-2026-22588
- Product
Spree Commerce
- Severity
Medium (6.5)
- Description
Authenticated IDOR in Spree API order modification allows a user to retrieve other users' address information by manipulating address identifiers.
- Notes
CVE-2026-21536
- Product
Microsoft Devices Pricing Program
- Severity
Critical (9.8)
- Description
Remote code execution vulnerability caused by unrestricted upload of a file with a dangerous type.
- Notes
CVE-2026-8524
- Product
Google Chrome
- Severity
High (8.8)
- Description
Out-of-bounds write in WebAudio allowed a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page.
- Notes
CVE-2025-8868
- Product
Chef Automate
- Severity
Critical (9.8)
- Description
SQL injection in Chef Automate compliance service before 4.13.295 allows access to restricted functionality through improperly neutralized SQL command inputs.
- Notes
CVE-2025-8264
- Product
Z-Push
- Severity
Critical (9.1)
- Description
SQL injection in the Z-Push IMAP backend before 2.7.6 via unparameterized queries using the Basic Authentication username field.
- Notes
Affects IMAP backend deployments with IMAP_FROM_SQL_QUERY configured.
CVE-2025-58360
- Product
GeoServer
- Severity
High (8.2)
- Description
GeoServer is vulnerable to Unauthenticated XML External Entities (XXE) attack via WMS GetMap feature
- Notes
CVE-2025-49493
- Product
Akamai CloudTest
- Severity
Medium (5.8)
- Description
XML External Entity (XXE) injection in Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion.
- Notes
CVE-2025-32013
- Product
LNbits
- Severity
Critical (9.3)
- Description
SSRF in LNbits LNURL authentication callback handling allows attacker-controlled callback URLs to access internal network resources.
- Notes
SSRF; detected using XBOW and credited to xbow-security
CVE-2025-30220
- Product
GeoServer / GeoTools / GeoNetwork
- Severity
Critical (9.9)
- Description
XXE in GeoTools XSD schema handling can affect GeoServer, GeoTools, and GeoNetwork XML processing paths.
- Notes
XXE;
No known CVE (GHSA-j23f-57hr-qqcx)
- Product
FOLIO mod-service-interaction
- Severity
Critical (9.3)
- Description
Arbitrary code execution in number generator sequence handling allows stored code to execute when getNextNumber is called.
- Notes
Arbitrary Code Execution; credited to XBOW
CVE-2025-27888
- Product
Apache Druid
- Severity
Medium (5.8)
- Description
Druid management proxy URL handling can be abused for SSRF, XSS, and open redirect behavior by an authenticated user.
- Notes
SSRF; fixed in Druid 31.0.2 and 32.0.1.
CVE-2025-27136
- Product
LocalS3
- Severity
Medium (5.5)
- Description
XXE in LocalS3 bucket creation endpoint before 1.21 allows SSRF and leakage of internal service responses through CreateBucketConfiguration XML parsing.
- Notes
XXE;
CVE-2025-27092
- Product
GHOSTS
- Severity
High (8.7)
- Description
Path traversal in the GHOSTS photo retrieval endpoint allows arbitrary file reads through crafted NPC photoLink values.
- Notes
File Read;
CVE-2025-25297
- Product
Label Studio
- Severity
High (8.6)
- Description
SSRF in Label Studio's S3 storage endpoint configuration allows requests to arbitrary internal services via a custom S3 endpoint URL.
- Notes
SSRF;
CVE-2025-25296
- Product
Label Studio
- Severity
Medium (6.1)
- Description
XSS in Label Studio's /projects/upload-example endpoint allows arbitrary HTML or JavaScript injection through crafted label_config query data.
- Notes
SSRF in provided list; public advisory describes XSS;
CVE-2025-25295
- Product
Label Studio
- Severity
High (8.7)
- Description
Path traversal in Label Studio SDK export functionality allows authenticated arbitrary file reads through crafted image field values.
- Notes
Path;
CVE-2025-25286
- Product
Crayfish / Homarus
- Severity
Critical (9.8)
- Description
Remote code execution may be possible in web-accessible Homarus installations via the Authorization header and problematic CLI interpolation.
- Notes
RCE;
CVE-2025-25284
- Product
ZOO-Project
- Severity
High (8.7)
- Description
Path traversal and local file read in ZOO-Project Gdal_Translate VRT handling allows unauthenticated remote reads of arbitrary server files.
- Notes
Path;
CVE-2025-25190
- Product
ZOO-Project
- Severity
Medium (5.5)
- Description
XSS in the ZOO-Project WPS EchoProcess service allows attacker-supplied SVG content to execute JavaScript in a victim's browser.
- Notes
RXSS;
CVE-2025-25189
- Product
ZOO-Project
- Severity
Medium (5.5)
- Description
Reflected XSS in the ZOO-Project WPS publish.py CGI script allows JavaScript injection through the jobid parameter.
- Notes
RXSS;
CVE-2025-24961
- Product
S3Proxy
- Severity
Medium (6.0)
- Description
Path traversal in S3Proxy filesystem and filesystem-nio2 storage backends can expose local files to authenticated clients.
- Notes
Path; privately reported by XBOW Team
CVE-2025-24854
- Product
Apache JSPWiki
- Severity
Medium (6.1)
- Description
XSS in Apache JSPWiki Image plugin allows crafted requests to execute JavaScript in a victim's browser.
- Notes
XSS;
CVE-2025-24853
- Product
Apache JSPWiki
- Severity
High (7.5)
- Description
XSS in Apache JSPWiki header link and markdown processing allows crafted wiki markup to execute JavaScript in a victim's browser.
- Notes
XSS;
CVE-2025-0133
- Product
PAN-OS GlobalProtect
- Severity
Medium
- Description
Reflected XSS in PAN-OS GlobalProtect gateway and portal features can execute JavaScript in the browser of an authenticated Captive Portal user.
- Notes
No known CVE (OTRSCE-SA-2024-01)
- Product
OTRS Community Edition
- Severity
High
- Description
Crafted URLs can inject malicious input into HTTP responses, leading to HTTP response splitting and XSS.
- Notes
HTTP Response Splitting / XSS; reported by XBOW Security
No known CVE (GHSA-c2p2-hgjg-9r3f)
- Product
Crayfish / Hypercube
- Severity
Critical (9.5)
- Description
Remote code execution is possible in web-accessible Hypercube installations via the X-Islandora-Args header.
- Notes
RCE; credited to xbow-security
CVE-2024-53982
- Product
ZOO-Project
- Severity
High (8.7)
- Description
Path traversal in the ZOO-Project Echo example allows arbitrary file download through attacker-controlled caching parameters.
- Notes
Arb File Download;
CVE-2024-53930
- Product
WikiDocs
- Severity
Medium (5.4)
- Description
Stored XSS in WikiDocs before 1.0.65 via KaTeX parser mishandling of user-controlled data after $$\\.
- Notes
XSS;
CVE-2024-53844
- Product
EDDI
- Severity
Medium (6.3)
- Description
Path traversal in EDDI backup export functionality allows access to sensitive container files through the botFilename parameter.
- Notes
Path;
CVE-2024-52598
- Product
2FAuth
- Severity
High (7.5)
- Description
SSRF and URI validation bypass in 2FAuth account preview allows the application to fetch attacker-supplied URLs.
- Notes
SSRF;
CVE-2024-52597
- Product
2FAuth
- Severity
Medium (6.1)
- Description
Stored XSS in 2FAuth allows JavaScript execution through uploaded SVG images rendered with improper headers.
- Notes
XSS;
CVE-2024-50334
- Product
Scoold
- Severity
High (8.7)
- Description
Semicolon path injection bypasses authentication on /api;/config, and HOCON file inclusion can expose local files.
- Notes
Auth Bypass;
CVE-2023-39631
- Product
TiTiler / numexpr
- Severity
Critical (9.8)
- Description
Remote code execution through unsafe expression evaluation in numexpr, exploited by XBOW through TiTiler's expression parser.
- Notes
Public CVE references;