Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    1
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-86118

    gonic before 0.22.0 Missing Administrator Check on the Subsonic startScan Endpoint

    Last Modified: Sep 08, 2026
    Published: Sep 05, 2026

    CVE-2026-49340

    gonic has arbitrary file write in createPlaylist: any authenticated user can write playlist M3U content to attacker-controlled path on the host

    Last Modified: Jun 22, 2026
    Published: Jun 19, 2026

    CVE-2026-49338

    Subsonic API: any authenticated user can delete or read any other user's playlist (IDOR)

    Last Modified: Jun 23, 2026
    Published: Jun 19, 2026

    CVE-2026-49339

    Path traversal in getPlaylist/deletePlaylist bypasses ownership check: any authenticated user can read or delete any other user's playlist

    Last Modified: Jun 22, 2026
    Published: Jun 19, 2026
    Items Per Page
    Sentriz Vulnerabilities & Security CVEs | CVE-DB