Known Vulnerabilities for Cron by Cron Project
Listed below are 3 of the newest known vulnerabilities associated with "Cron" by "Cron Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-73034 json | DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability that allows remote attackers to write arbitrary files ... | Not Provided | 2026-08-11 | 2026-08-13 |
| CVE-2026-72840 json | OpenWrt LuCI contains an overly permissive ACL definition in luci-mod-system-mounts that grants write access to /etc/crontabs... | Not Provided | 2026-08-13 | 2026-08-14 |
| CVE-2026-72607 json | A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff wi... | Not Provided | 2026-08-11 | 2026-08-11 |
| CVE-2026-72590 json | An OS command injection vulnerability in alseambusher/crontab-ui through 0.4.2 allows an unauthenticated remote attacker to i... | Not Provided | 2026-08-10 | 2026-08-10 |
| CVE-2026-71364 json | A path traversal vulnerability was found in AWX's project archive extraction. The project_archive action plugin extracts zip ... | Not Provided | 2026-08-24 | 2026-08-27 |
| CVE-2026-62202 json | OpenClaw versions 2026.6.1 before 2026.6.9 contain a privilege escalation vulnerability in isolated cron jobs that allows low... | Not Provided | 2026-07-17 | 2026-07-18 |
| CVE-2026-56258 json | Crawl4AI before 0.8.8 contains an arbitrary file write vulnerability in the screenshot and PDF endpoints that allows unauthen... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-55557 json | browse-mcp is a Playwright-based headless-browser MCP server for MCP-capable agents. Prior to 0.8.2, browser_download writes ... | Not Provided | 2026-08-25 | 2026-08-25 |
| CVE-2026-54732 json | libreoffice-convert is a Node.js module for converting office documents to different formats. Prior to 1.8.2, index.js uses t... | Not Provided | 2026-08-27 | 2026-08-28 |
| CVE-2026-54636 json | Dokku is a docker-powered PaaS. Prior to 0.38.7, the cron plugin utilizes commands in the app.json file to manage system cron... | Not Provided | 2026-06-26 | 2026-06-29 |