Search
Search Results (2 CVEs found)
| CVE | Vendors | Products | Updated | CVSS v3.1 |
|---|---|---|---|---|
| CVE-2026-72569 | 1 Cube-root | 1 Directory-serve | 2026-08-11 | 9.1 Critical |
| A path traversal vulnerability in cube-root/directory-serve through 1.3.7 allows an unauthenticated remote attacker to delete arbitrary files outside the intended served directory when the application is run with the --delete option. | ||||
| CVE-2026-72570 | 1 Cube-root | 1 Directory-serve | 2026-08-11 | 5.4 Medium |
| A stored cross-site scripting (XSS) vulnerability in cube-root/directory-serve through 1.3.7 allows an attacker to inject arbitrary JavaScript into the web interface by uploading a file with a crafted filename containing HTML attribute-breaking characters. | ||||
Page 1 of 1.