Products: 1
    Vulnerabilities: 27
    Known Exploited: 0
    1
    Critical Level Threats
    8
    High Level Threats
    12
    Medium Level Threats
    1
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-77353

    Wallos: iCalendar Injection via CRLF in Subscription Name/Notes Export

    Last Modified: Sep 03, 2026
    Published: Aug 31, 2026

    CVE-2026-77352

    Wallos: Authenticated SSRF via per-user SMTP notification host (low-privilege user)

    Last Modified: Sep 01, 2026
    Published: Aug 31, 2026

    CVE-2026-77348

    Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`

    Last Modified: Sep 03, 2026
    Published: Aug 31, 2026

    CVE-2026-77351

    Wallos: SSRF via Unvalidated User-Level SMTP Host in Email Notification Settings

    Last Modified: Sep 01, 2026
    Published: Aug 31, 2026

    CVE-2026-61641

    Wallos: OIDC account takeover via email-based account linking without `email_verified` check

    Last Modified: Sep 01, 2026
    Published: Aug 31, 2026
    Items Per Page
    Ellite Vulnerabilities & Security CVEs | CVE-DB