May 7, 2026
CVE-2026-43888
Outline Stored XSS
Public advisory metadata records a stored cross-site scripting issue in Outline.
BugBunny.ai CVEs across open source software, developer tooling, infrastructure, and modern AI stacks. Public records show details; reserved entries stay as placeholders.
66
CVEs discovered
52
Public records
9.9
Peak CVSS
14
Reserved placeholders
Severity Timeline
Hover a point to inspect public advisory metadata or a reserved placeholder. The x-axis tracks disclosure time, while the y-axis uses the numeric CVSS score.

May 7, 2026
CVE-2026-43889
CVSS score
6.5/10
Version 3.1
Public CVEs include readable metadata or advisories. Reserved CVEs show only the assigned number and score.
High / critical: 32
May 7, 2026
CVE-2026-43888
Public advisory metadata records a stored cross-site scripting issue in Outline.
May 7, 2026
CVE-2026-43889
Public advisory metadata records an access-control issue in Outline.
May 5, 2026
CVE-2026-43999
Public advisory metadata records a critical vm2 sandbox escape discovered through BugBunny research.
May 5, 2026
CVE-2026-43998
Public advisory metadata records a high-impact vm2 sandbox boundary bypass discovered through BugBunny research.
May 4, 2026
CVE-2026-42883
Public advisory metadata records an Audiobookshelf access-control issue discovered through BugBunny research.
May 4, 2026
CVE-2026-42884
Public advisory metadata records an Audiobookshelf authorization issue discovered through BugBunny research.
May 4, 2026
CVE-2026-42885
Public advisory metadata records an Audiobookshelf authorization issue discovered through BugBunny research.
May 4, 2026
CVE-2026-42886
Public advisory metadata records an Audiobookshelf authorization issue discovered through BugBunny research.
April 22, 2026
CVE-2026-41590
Disclosure details are withheld until the CVE or advisory is public.
April 20, 2026
CVE-2026-41131
Public advisory metadata records an OpenFGA authorization issue discovered through BugBunny research.
April 20, 2026
CVE-2026-40914
Disclosure details are withheld until the CVE or advisory is public.
April 18, 2026
CVE-2026-40454
Disclosure details are withheld until the CVE or advisory is public.
April 16, 2026
CVE-2026-40304
Public advisory metadata records a broken ownership check in zrok that affected frontend record deletion.
April 16, 2026
CVE-2026-40302
Public advisory metadata records a reflected XSS issue in zrok OAuth callback error rendering.
April 10, 2026
CVE-2026-40293
Public advisory metadata records an OpenFGA authorization issue discovered through BugBunny research.
April 10, 2026
CVE-2026-40165
Disclosure details are withheld until the CVE or advisory is public.
April 7, 2026
CVE-2026-35441
Public advisory metadata records a high-impact Directus security boundary issue discovered through BugBunny research.
April 6, 2026
CVE-2026-34972
Public advisory metadata records an OpenFGA authorization-model disclosure issue discovered through BugBunny research.
April 4, 2026
CVE-2026-35214
Public advisory metadata records path traversal in Budibase plugin upload handling, enabling arbitrary directory deletion and file write.
April 2, 2026
CVE-2026-35413
Public advisory metadata records a Directus security boundary issue discovered through BugBunny research.
April 2, 2026
CVE-2026-35412
Public advisory metadata records a high-impact Directus security boundary issue discovered through BugBunny research.
April 1, 2026
CVE-2026-4800
Public advisory metadata records code injection through lodash template imports key handling.
April 1, 2026
CVE-2026-34750
Public advisory metadata records insufficient filename validation in Payload client-upload signed URL endpoints.
April 1, 2026
CVE-2026-34749
Public advisory metadata records a CSRF protection bypass in Payload authentication flow.
April 1, 2026
CVE-2026-34748
Public advisory metadata records stored cross-site scripting in Payload admin panel handling.
April 1, 2026
CVE-2026-34746
Public advisory metadata records authenticated server-side request forgery in Payload upload functionality.
March 28, 2026
CVE-2026-34595
Public CVE metadata records a Parse Server authorization issue discovered through BugBunny research.
March 28, 2026
CVE-2026-34574
Public CVE metadata records a Parse Server authorization issue discovered through BugBunny research.
March 28, 2026
CVE-2026-34573
Public CVE metadata records a high-impact Parse Server security boundary issue discovered through BugBunny research.
March 28, 2026
CVE-2026-34532
Public CVE metadata records a critical Parse Server authorization issue discovered through BugBunny research.
March 26, 2026
CVE-2026-34198
Disclosure details are withheld until the CVE or advisory is public.
March 26, 2026
CVE-2026-34171
Disclosure details are withheld until the CVE or advisory is public.
March 26, 2026
CVE-2026-34170
Disclosure details are withheld until the CVE or advisory is public.
March 26, 2026
CVE-2026-34167
Disclosure details are withheld until the CVE or advisory is public.
March 26, 2026
CVE-2026-34158
Disclosure details are withheld until the CVE or advisory is public.
March 24, 2026
CVE-2026-34037
Disclosure details are withheld until the CVE or advisory is public.
March 2026
CVE-2026-33016
Disclosure details are withheld until the CVE or advisory is public.
March 2026
CVE-2026-33037
Official AVideo Docker deployment defaults seeded the admin account with the predictable password `password` when operators left environment defaults unchanged.
March 2026
CVE-2026-33038
AVideo exposed an unauthenticated web installer that let remote attackers initialize fresh deployments with attacker-controlled admin credentials and database settings.
March 2026
CVE-2026-33039
AVideo validated the initial LiveLinks URL but trusted redirect targets, enabling unauthenticated SSRF into internal services and cloud metadata endpoints.
March 11, 2026
CVE-2026-31888
Shopware exposed whether an email address belonged to a valid customer by returning distinct error codes on Store API login requests.
March 9, 2026
CVE-2026-30973
A missing throw in Appium’s ZIP extraction path traversal check made Zip Slip protection non-functional and allowed arbitrary file write.
March 2026
CVE-2026-29093
AVideo’s default docker-compose stack published an unauthenticated memcached instance holding all PHP session data directly to the host network.
March 2026
CVE-2026-28398
NocoDB rendered attacker-controlled comments and rich text with v-html and no sanitization, enabling stored XSS for viewers of affected records.
March 2026
CVE-2026-28396
NocoDB invalidated JWT versions on password reset but failed to delete existing refresh tokens, allowing stolen refresh tokens to survive the reset.
March 2026
CVE-2026-28361
NocoDB’s MCP token service skipped ownership validation, allowing users with sufficient base permissions to manipulate another user’s token if they knew its ID.
March 2026
CVE-2026-3351
LXD’s non-recursive certificate listing bypassed per-object authorization and leaked certificate fingerprints to restricted authenticated users.
February 2026
CVE-2026-28445
Disclosure details are withheld until the CVE or advisory is public.
February 2026
CVE-2026-28351
Crafted RunLengthDecode streams in PDFs could trigger large memory consumption inside pypdf and exhaust process RAM.
February 2026
CVE-2026-28217
Hoppscotch’s userCollection GraphQL query returned other users’ private collection data without verifying ownership, exposing secrets and request definitions.
February 24, 2026
CVE-2026-28215
Public CVE metadata records unauthenticated infrastructure configuration overwrite in Hoppscotch onboarding configuration handling.
February 2026
CVE-2026-28444
Disclosure details are withheld until the CVE or advisory is public.
February 2026
CVE-2026-28384
Multiple LXD API endpoints passed user-controlled compression_algorithm strings into shell-parsed host commands, enabling authenticated host RCE.
February 2026
CVE-2026-27955
Disclosure details are withheld until the CVE or advisory is public.
February 2026
CVE-2026-27806
Fleet Orbit interpolated a local password into a Tcl/expect script without safe escaping, allowing local users to inject commands and escalate to root.
February 2026
CVE-2026-27471
Missing validation on sensitive ERPNext endpoints allowed unauthorized access to employee, invoice, and financial documents.
January 2026
CVE-2026-23630
Unsanitized Mermaid SVG rendering enabled stored XSS against any user viewing a poisoned Docmost page.
January 12, 2026
CVE-2026-22807
vLLM loaded Hugging Face auto_map dynamic modules without honoring trust_remote_code, enabling arbitrary Python execution from untrusted models.
January 12, 2026
CVE-2026-21884
Inline ScrollRestoration scripts failed to escape </script> sequences during SSR, allowing attacker-controlled XSS.
November 2025
CVE-2025-64756
The glob CLI passed attacker-controlled filenames into shell execution paths, making malicious repositories executable.
October 2025
CVE-2025-61686
Crafted session identifiers escaped React Router file session storage directories and enabled arbitrary file overwrite.
September 2025
CVE-2025-61622
Unsupported objects in pyfory/pyfury fell back to pickle.loads, enabling arbitrary code execution from crafted serialized data.
August 2025
CVE-2025-59792
Kvrocks MONITOR output leaked plaintext AUTH credentials, exposing passwords to low-privilege observers.
August 2025
CVE-2025-59790
Namespace token validation flaws in Kvrocks allowed lower-privilege users to cross privilege boundaries.
July 2025
CVE-2025-59057
A stored XSS condition in React Router allowed attacker-supplied markup to persist and execute in downstream applications.
June 2025
CVE-2025-58434
Flowise leaked password reset material in a way that enabled full account takeover across local and cloud deployments.
BugBunny runs coordinated AI agents to surface exploitable issues before attackers do, then packages the results into audit-ready findings and CVE-quality disclosures.