Products: 1
Vulnerabilities: 8
Known Exploited: 0
3
Critical Level Threats
3
High Level Threats
2
Medium Level Threats
0
Low Level Threats
Vulnerabilities
100806040200
JanFebMarAprMayJunJulAugSepOctNovDec
Critical Level Threats
High Level Threats
Medium Level Threats
Low Level Threats
Products Security index
Actions
Items Per Page
Vulnerabilities
CVE-2026-40350
Movary User Management (/settings/users) has Authorization Bypass that Allows Low-Privileged Users to Enumerate All Users and Create Administrator Accounts
Last Modified: Apr 27, 2026
Published: Apr 18, 2026
CVE-2026-40349
Authenticated Movary User Can Self-Escalate to Administrator via PUT /settings/users/{userId} by Setting isAdmin=true
Last Modified: Apr 27, 2026
Published: Apr 18, 2026
CVE-2026-40348
Movary has Authenticated SSRF via Jellyfin Server URL Verification that Allows Internal Network Probing
Last Modified: Apr 27, 2026
Published: Apr 18, 2026
CVE-2026-23841
Movary vulnerable to Cross-site Scripting with `?categoryCreated=` param
Last Modified: Apr 18, 2026
Published: Jan 19, 2026
CVE-2026-23840
Movary vulnerable to Cross-site Scripting with `?categoryDeleted=` param
Last Modified: Apr 18, 2026
Published: Jan 19, 2026
Items Per Page
