Vulnerabilities
Summary — last 7 days
New vulnerabilities2,731▼ 88 vs. last week
Critical / high1,419▲ 189 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)83▼ 429 vs. last week
17 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Low (2) | 0.42% | — | Dgtlmoon Changedetection.ioAI | 9/22/2026 | 9/25/2026 | A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSelectedText of the file changedetectionio/static/js/visual-selector.js of the component Visual Selector. Executing a manipulation of the argument s can lead to cross site scripting. The attack can be… | |
| Deferred | Medium (5.5) | 0.51% | — | Dgtlmoon Changedetection.ioAI | 9/22/2026 | 9/22/2026 | A vulnerability was found in dgtlmoon changedetection.io up to 50389b07. This vulnerability affects the function add_watch_ui_snapshot of the file changedetectionio/blueprint/add_watch_ui/__init__.py of the component Preview Endpoint. Performing a manipulation of the argument url results in server-side request… | |
| Deferred | Low (2.1) | 0.52% | — | Dgtlmoon Changedetection.ioAI | 9/22/2026 | 9/22/2026 | A vulnerability was determined in dgtlmoon changedetection.io up to 0.60.7. This impacts the function static_content of the file changedetectionio/flask_app.py of the component visual_selector_data. Executing a manipulation of the argument filename can lead to path traversal. It is possible to launch the attack… | |
| Deferred | Low (2.9) | 0.67% | — | Dgtlmoon Changedetection.ioAI | 9/22/2026 | 9/22/2026 | A vulnerability was found in dgtlmoon changedetection.io up to 0.60.7. This affects the function static_content of the file changedetectionio/flask_app.py of the component Screenshot Handler. Performing a manipulation of the argument filename results in path traversal. It is possible to initiate the attack remotely.… | |
| Deferred | Medium (5.5) | 0.65% | — | Dgtlmoon Changedetection.ioAI | 9/22/2026 | 9/22/2026 | A vulnerability has been found in dgtlmoon changedetection.io up to 0.60.7. The impacted element is the function check_authentication of the file changedetectionio/flask_app.py of the component Authentication Hook. Such manipulation leads to improper authentication. The attack may be performed from remote. The exploit… | |
| Deferred | Low (2.9) | 0.44% | — | Dgtlmoon Changedetection.ioAI | 9/22/2026 | 9/22/2026 | A flaw has been found in dgtlmoon changedetection.io up to 0.60.7. The affected element is the function check_password of the file changedetectionio/flask_app.py of the component Hash Comparison. This manipulation of the argument Password causes observable timing discrepancy. The attack is possible to be carried out… | |
| Deferred | High (8.7) | 0.54% | — | Changedetection.ioAI | 9/16/2026 | 9/22/2026 | changedetection.io through 0.60.6 fails to validate the Goto URL action in browser steps, allowing unauthenticated attackers to access internal addresses. Attackers can supply arbitrary internal URLs in the optional_value parameter to retrieve responses from restricted network locations. | |
| Deferred | Low (2.3) | 0.30% | — | Changedetection.ioAI | 9/16/2026 | 9/22/2026 | changedetection.io through 0.60.6 fails to escape the scraped page title in HTML notifications, allowing arbitrary markup injection. Attackers can place malicious markup in monitored page titles that reaches notification channels like email and Telegram as live content when the watch_title token is used in templates. | |
| Deferred | Medium (6.5) | 0.27% | — | Changedetection.ioAI | 8/5/2026 | 8/26/2026 | changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements.txt). | |
| Deferred | Medium (6.2) | 0.32% | — | Changedetection.ioAI | 8/5/2026 | 8/28/2026 | changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update. | |
| Deferred | Medium (5.3) | 0.31% | — | Changedetection.ioAI | 8/5/2026 | 8/28/2026 | changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method carries neither @auth.check_token nor @validate_openapi_request. | |
| Deferred | High (7) | 0.59% | — | Changedetection.ioAI | 6/23/2025 | 6/17/2026 | changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Prior to version 0.50.4, errors in filters from website page change detection watches were not being filtered resulting in a cross-site scripting (XSS) vulnerability. This issue has been… | |
| Deferred | High (8.6) | 0.70% | — | Changedetection.ioAI | 12/27/2024 | 6/17/2026 | changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. Improper input validation in the application can allow attackers to perform local file read (LFR) or path traversal attacks. These vulnerabilities occur when user input is used to construct… | |
| Deferred | High (8.6) | 0.69% | — | Changedetection.ioAI | 11/8/2024 | 6/17/2026 | changedetection.io is a free open source web page change detection tool. The validation for the file URI scheme falls short, and results in an attacker being able to read any file on the system. This issue only affects instances with a webdriver enabled, and `ALLOW_FILE_URI` false or not defined. The check used for… | |
| Deferred | Medium (6.9) | 2.3% | — | Changedetection.ioAI | 11/1/2024 | 6/17/2026 | changedetection.io is free, open source web page change detection software. Prior to version 0.47.5, when a WebDriver is used to fetch files, `source:file:///etc/passwd` can be used to retrieve local system files, where the more traditional `file:///etc/passwd` gets blocked. Version 0.47.5 fixes the issue. | |
| Deferred | Medium (4.3) | 1.3% | — | Changedetection.ioAI | 5/2/2024 | 6/17/2026 | changedetection.io is a free open source web page change detection, website watcher, restock monitor and notification service. In affected versions Input in parameter notification_urls is not processed resulting in javascript execution in the application. A reflected XSS vulnerability happens when the user input from… | |
| Deferred | Critical (10) | 84% | — | Changedetection.ioAIPocoo Jinja2AI | 4/26/2024 | 6/17/2026 | changedetection.io is an open source web page change detection, website watcher, restock monitor and notification service. There is a Server Side Template Injection (SSTI) in Jinja2 that allows Remote Command Execution on the server host. Attackers can run any system command without any restriction and they could use… |