Skip to content
Noroxi

LinuxServer records

5 published records for vendor linuxserver.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
1
With a fix record
20%
Median publish → KEV
No record has entered KEV

All records

5 records
  • LinuxServer.io heimdall 2.6.3-ls307 contains a vulnerability in how it handles user-supplied HTTP headers, specifically `X-Forwarded-Host` a

    CriticalCVSS 9.8Proof of conceptEPSS 3%

    linuxserver · docker-heimdallJul 30, 2025

  • An issue in Linux Server Heimdall v.2.6.1 allows a remote attacker to execute arbitrary code via a crafted script to the Add new application

    CriticalCVSS 9.8Proof of conceptEPSS 1%

    Nov 5, 2024

  • LinuxServer.io Heimdall before 2.5.7 does not prevent use of icons that have non-image data such as the "<?php ?>" substring.

    CriticalCVSS 9.8No exploitEPSS 1%

    Mar 31, 2024

  • LinuxServer.io Heimdall before 2.7.3 allows XSS via the q parameter.

    MediumCVSS 6.1Proof of conceptEPSS 1%

    linuxserver · heimdall application dashboardJul 26, 2025

  • Heimdall Application Dashboard through 2.5.4 allows reflected and stored XSS via "Application name" to the "Add application" page.

    MediumCVSS 5.4No exploitEPSS 0%

    linuxserver · heimdall application dashboardDec 27, 2022