From Discovery to Disclosure
Explore publicly disclosed CVEs XBOW discovered across widely used products and platforms, with severity ratings and summaries of their technical impact.
CVE ID | Product | Severity | Description | Notes |
CVE-2026-16421 | Google Chrome | High | Type Confusion in WebAudio. | |
CVE-2026-16420 | Google Chrome | High | Inappropriate implementation in WebAudio. | |
CVE-2026-16353 | Firefox | High | Invalid pointer in the DOM: Bindings (WebIDL) component | |
CVE-2026-45185 | Exim | Critical (9.8) | Use-after-free in Exim's BDAT body parsing path under certain GnuTLS configurations, allowing unauthenticated remote code execution. | |
CVE-2026-32194 | Microsoft Bing Images | Critical (9.8) | Command injection in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. | |
CVE-2026-32191 | Microsoft Bing Images | Critical (9.8) | OS command injection in Microsoft Bing Images allows an unauthorized attacker to execute code over a network. | |
CVE-2026-22589 | Spree Commerce | High (7.5) | Unauthenticated IDOR in Spree API allows access to guest address information without valid credentials or session cookies. | |
CVE-2026-22588 | Spree Commerce | Medium (6.5) | Authenticated IDOR in Spree API order modification allows a user to retrieve other users' address information by manipulating address identifiers. | |
CVE-2026-21536 | Microsoft Devices Pricing Program | Critical (9.8) | Remote code execution vulnerability caused by unrestricted upload of a file with a dangerous type. | |
CVE-2026-8524 | Google Chrome | High (8.8) | Out-of-bounds write in WebAudio allowed a remote attacker to execute arbitrary code inside the Chrome sandbox via a crafted HTML page. | |
CVE-2025-8868 | Chef Automate | Critical (9.8) | SQL injection in Chef Automate compliance service before 4.13.295 allows access to restricted functionality through improperly neutralized SQL command inputs. | |
CVE-2025-8264 | Z-Push | Critical (9.1) | SQL injection in the Z-Push IMAP backend before 2.7.6 via unparameterized queries using the Basic Authentication username field. | Affects IMAP backend deployments with IMAP_FROM_SQL_QUERY configured. |
CVE-2025-49493 | Akamai CloudTest | Medium (5.8) | XML External Entity (XXE) injection in Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion. | |
CVE-2025-32013 | LNbits | Critical (9.3) | SSRF in LNbits LNURL authentication callback handling allows attacker-controlled callback URLs to access internal network resources. | SSRF; detected using XBOW and credited to xbow-security |
CVE-2025-30220 | GeoServer / GeoTools / GeoNetwork | Critical (9.9) | XXE in GeoTools XSD schema handling can affect GeoServer, GeoTools, and GeoNetwork XML processing paths. | XXE; |
No known CVE (GHSA-j23f-57hr-qqcx) | FOLIO mod-service-interaction | Critical (9.3) | Arbitrary code execution in number generator sequence handling allows stored code to execute when getNextNumber is called. | Arbitrary Code Execution; credited to XBOW |
CVE-2025-27888 | Apache Druid | Medium (5.8) | Druid management proxy URL handling can be abused for SSRF, XSS, and open redirect behavior by an authenticated user. | SSRF; fixed in Druid 31.0.2 and 32.0.1. |
CVE-2025-27136 | LocalS3 | Medium (5.5) | XXE in LocalS3 bucket creation endpoint before 1.21 allows SSRF and leakage of internal service responses through CreateBucketConfiguration XML parsing. | XXE; |
CVE-2025-27092 | GHOSTS | High (8.7) | Path traversal in the GHOSTS photo retrieval endpoint allows arbitrary file reads through crafted NPC photoLink values. | File Read; |
CVE-2025-25297 | Label Studio | High (8.6) | SSRF in Label Studio's S3 storage endpoint configuration allows requests to arbitrary internal services via a custom S3 endpoint URL. | SSRF; |
CVE-2025-25296 | Label Studio | Medium (6.1) | XSS in Label Studio's /projects/upload-example endpoint allows arbitrary HTML or JavaScript injection through crafted label_config query data. | SSRF in provided list; public advisory describes XSS; |
CVE-2025-25295 | Label Studio | High (8.7) | Path traversal in Label Studio SDK export functionality allows authenticated arbitrary file reads through crafted image field values. | Path; |
CVE-2025-25286 | Crayfish / Homarus | Critical (9.8) | Remote code execution may be possible in web-accessible Homarus installations via the Authorization header and problematic CLI interpolation. | RCE; |
CVE-2025-25284 | ZOO-Project | High (8.7) | Path traversal and local file read in ZOO-Project Gdal_Translate VRT handling allows unauthenticated remote reads of arbitrary server files. | Path; |
CVE-2025-25190 | ZOO-Project | Medium (5.5) | XSS in the ZOO-Project WPS EchoProcess service allows attacker-supplied SVG content to execute JavaScript in a victim's browser. | RXSS; |
CVE-2025-25189 | ZOO-Project | Medium (5.5) | Reflected XSS in the ZOO-Project WPS publish.py CGI script allows JavaScript injection through the jobid parameter. | RXSS; |
CVE-2025-24961 | S3Proxy | Medium (6.0) | Path traversal in S3Proxy filesystem and filesystem-nio2 storage backends can expose local files to authenticated clients. | Path; privately reported by XBOW Team |
CVE-2025-24854 | Apache JSPWiki | Medium (6.1) | XSS in Apache JSPWiki Image plugin allows crafted requests to execute JavaScript in a victim's browser. | XSS; |
CVE-2025-24853 | Apache JSPWiki | High (7.5) | XSS in Apache JSPWiki header link and markdown processing allows crafted wiki markup to execute JavaScript in a victim's browser. | XSS; |
CVE-2025-0133 | PAN-OS GlobalProtect | Medium | Reflected XSS in PAN-OS GlobalProtect gateway and portal features can execute JavaScript in the browser of an authenticated Captive Portal user. | |
No known CVE (OTRSCE-SA-2024-01) | OTRS Community Edition | High | Crafted URLs can inject malicious input into HTTP responses, leading to HTTP response splitting and XSS. | HTTP Response Splitting / XSS; reported by XBOW Security |
No known CVE (GHSA-c2p2-hgjg-9r3f) | Crayfish / Hypercube | Critical (9.5) | Remote code execution is possible in web-accessible Hypercube installations via the X-Islandora-Args header. | RCE; credited to xbow-security |
CVE-2024-53982 | ZOO-Project | High (8.7) | Path traversal in the ZOO-Project Echo example allows arbitrary file download through attacker-controlled caching parameters. | Arb File Download; |
CVE-2024-53930 | WikiDocs | Medium (5.4) | Stored XSS in WikiDocs before 1.0.65 via KaTeX parser mishandling of user-controlled data after $$\\. | XSS; |
CVE-2024-53844 | EDDI | Medium (6.3) | Path traversal in EDDI backup export functionality allows access to sensitive container files through the botFilename parameter. | Path; |
CVE-2024-52598 | 2FAuth | High (7.5) | SSRF and URI validation bypass in 2FAuth account preview allows the application to fetch attacker-supplied URLs. | SSRF; |
CVE-2024-52597 | 2FAuth | Medium (6.1) | Stored XSS in 2FAuth allows JavaScript execution through uploaded SVG images rendered with improper headers. | XSS; |
CVE-2024-50334 | Scoold | High (8.7) | Semicolon path injection bypasses authentication on /api;/config, and HOCON file inclusion can expose local files. | Auth Bypass; |
CVE-2023-39631 | TiTiler / numexpr | Critical (9.8) | Remote code execution through unsafe expression evaluation in numexpr, exploited by XBOW through TiTiler's expression parser. | Public CVE references; |