Known Vulnerabilities for Lookup-server by Nextcloud
Listed below are 1 of the newest known vulnerabilities associated with "Lookup-server" by "Nextcloud".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-77070 json | n8n before 1.123.69, 2.33.4, and 2.34.1 contains a NoSQL injection vulnerability in the MongoDB node's Find, Delete, and Aggr... | Not Provided | 2026-08-20 | 2026-08-21 |
| CVE-2026-73432 json | Vulnerability-Lookup contains a server-side request forgery (SSRF) vulnerability in the remote-instance synchronization funct... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-73405 json | An authorization bypass vulnerability in Vulnerability-Lookup allowed inactive or unconfirmed accounts to subscribe to Server... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-70616 json | boringproxy through 0.10.0 contains a resource exhaustion vulnerability that allows any authenticated user to permanently exh... | Not Provided | 2026-08-05 | 2026-08-06 |
| CVE-2026-69246 json | Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Guzzle gives a transport the request URI as text and supp... | Not Provided | 2026-08-03 | 2026-08-04 |
| CVE-2026-68558 json | Wekan is open source kanban built with Meteor. From 8.36 until 9.74, the outgoing webhook Integration URL validator in models... | Not Provided | 2026-08-19 | 2026-08-19 |
| CVE-2026-68076 json | Apache Airflow's environment-variable secrets backend resolved a team-scoped Connection or Variable from the wrong team's sco... | Not Provided | 2026-08-12 | 2026-08-12 |
| CVE-2026-64142 json | In the Linux kernel, the following vulnerability has been resolved: ksmbd: close durable scavenger races against m_fp_list l... | Not Provided | 2026-07-19 | 2026-08-05 |
| CVE-2026-58371 json | SeaweedFS before 4.30 reflects the callback query parameter verbatim into responses served with Content-Type application/java... | Not Provided | 2026-06-30 | 2026-07-14 |
| CVE-2026-58369 json | Woodpecker before 3.15.0 registers the /api/orgs/lookup/*org_full_name endpoint without authentication middleware, and the Lo... | Not Provided | 2026-06-30 | 2026-07-14 |