Known Vulnerabilities for Private Files by Private Files Project
Listed below are 1 of the newest known vulnerabilities associated with "Private Files" by "Private Files Project".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-59948 json | Composer is a dependency Manager for the PHP language. Prior to 2.2.29 and 2.10.2, a maliciously crafted package from an untr... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59807 json | Composio SDK before 0.2.32-beta.283 contains a path validation bypass vulnerability that allows attackers to read and exfiltr... | Not Provided | 2026-07-08 | 2026-07-09 |
| CVE-2026-59733 json | Rclone is a command-line program to sync files and directories to and from different cloud storage providers. Prior to 1.74.4... | Not Provided | 2026-07-14 | 2026-07-16 |
| CVE-2026-59153 json | Anki is a program for creating and reviewing flashcards. Prior to 25.09.3, Anki launches a local HTTP server to serve media f... | Not Provided | 2026-07-07 | 2026-07-08 |
| CVE-2026-58460 json | react-native-receive-sharing-intent contains a path traversal vulnerability that allows a co-resident malicious application t... | Not Provided | 2026-07-02 | 2026-07-14 |
| CVE-2026-55474 json | Snipe-IT is an IT asset/license management system. Prior to 8.5.0, ActionlogController::displaySig concatenates the route fil... | Not Provided | 2026-07-10 | 2026-07-10 |
| CVE-2026-54016 json | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI... | Not Provided | 2026-06-23 | 2026-06-23 |
| CVE-2026-54012 json | Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI... | Not Provided | 2026-06-23 | 2026-06-24 |
| CVE-2026-53607 json | ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, when `prettyUrls: ... | Not Provided | 2026-06-12 | 2026-06-15 |
| CVE-2026-47182 json | Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private files b... | Not Provided | 2026-06-12 | 2026-06-12 |