Aggregating NVD, CVE, and multi-source threat feeds, this list provides deep analysis of high-risk threats such as RCE. By integrating CVSS and EPSS models, the system dynamically tracks Exp (Exploit) resources and PoC availability to accurately assess Exploitability. Combined with official Patches and remediation strategies, it helps prioritize Vulnerability Management workflows, significantly shortening response cycles and securing your critical assets.
Assigner (CNA / source):[email protected] Remove this filter
| CVE | Description | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|
| CVE-2026-3237 | In affected versions of Octopus Server it was possible for a low privileged user to manipulate an API request to change the signing key expiration and revocation time frames via an API endpoint that had incorrect permission validation. It was not possible to expose the signing keys using this vulnerability. | 2.3 | 0.15% | 2026-03-17 | 2026-06-17 |
| CVE-2026-3236 | In affected versions of Octopus Server it was possible to create a new API key from an existing access token resulting in the new API key having a lifetime exceeding the original API key used to mint the access token. | 2.3 | 0.15% | 2026-03-05 | 2026-06-17 |
| CVE-2024-6972 | In affected versions of Octopus Server under certain circumstances it is possible for sensitive variables to be printed in the task log in clear-text. | 6.5 | 0.17% | 2024-07-25 | 2026-06-17 |
| CVE-2022-2781 | In affected versions of Octopus Server it was identified that the same encryption process was used for both encrypting session cookies and variables. | 5.3 | 0.18% | 2022-10-06 | 2026-06-17 |
| CVE-2022-4008 | In affected versions of Octopus Deploy it is possible to upload a zipbomb file as a task which results in Denial of Service | 5.5 | 0.18% | 2023-05-10 | 2026-06-17 |
| CVE-2021-31821 | When the Windows Tentacle docker image starts up it logs all the commands that it runs along with the arguments, which writes the Octopus Server API key in plaintext. This does not affect the Linux Docker image | 5.5 | 0.18% | 2022-01-19 | 2026-06-16 |
| CVE-2026-8296 | In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts. | 5.6 | 0.20% | 2026-06-19 | 2026-06-22 |
| CVE-2026-4881 | In affected versions of Octopus Server, permissions were not checked correctly resulting in any authenticated user being able to make server level changes using a certain API endpoint despite receiving an error. | 6.0 | 0.21% | 2026-06-04 | 2026-06-17 |
| CVE-2021-31822 | When Octopus Tentacle is installed on a Linux operating system, the systemd service file permissions are misconfigured. This could lead to a local unprivileged user modifying the contents of the systemd service file to gain privileged access. | 7.8 | 0.21% | 2021-11-24 | 2026-06-16 |
| CVE-2022-2783 | In affected versions of Octopus Server it was identified that a session cookie could be used as the CSRF token | 5.3 | 0.21% | 2022-10-06 | 2026-06-17 |
| CVE-2025-0513 | In affected versions of Octopus Server error messages were handled unsafely on the error page. If an adversary could control any part of the error message they could embed code which may impact the user viewing the error message. | 1.8 | 0.22% | 2025-02-11 | 2026-06-17 |
| CVE-2024-1656 | Affected versions of Octopus Server had a weak content security policy. | 2.6 | 0.23% | 2024-09-11 | 2026-06-17 |
| CVE-2023-4509 | It is possible for an API key to be logged in clear text in the audit log file after an invalid login attempt. | 4.3 | 0.23% | 2024-04-17 | 2026-06-17 |
| CVE-2024-7998 | In affected versions of Octopus Server OIDC cookies were using the wrong expiration time which could result in them using the maximum lifespan. | 2.6 | 0.23% | 2024-08-21 | 2026-06-17 |
| CVE-2024-4811 | In affected versions of Octopus Server under certain conditions, a user with specific role assignments can access restricted project artifacts. | 2.2 | 0.24% | 2024-07-25 | 2026-06-17 |
| CVE-2021-26556 | When Octopus Server is installed using a custom folder location, folder ACLs are not set correctly and could lead to an unprivileged user using DLL side-loading to gain privileged access. | 7.8 | 0.25% | 2021-10-06 | 2026-06-16 |
| CVE-2024-4456 | In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting payload on the audit page. | 4.1 | 0.26% | 2024-05-07 | 2026-06-17 |
| CVE-2022-2416 | In affected versions of Octopus Deploy it is possible for a low privileged guest user to craft a request that allows enumeration/recon of an environment. | 5.5 | 0.26% | 2023-08-02 | 2026-06-17 |
| CVE-2022-2346 | In affected versions of Octopus Deploy it is possible for a low privileged guest user to interact with extension endpoints. | 5.5 | 0.29% | 2023-08-01 | 2026-06-17 |
| CVE-2025-0589 | In affected versions of Octopus Deploy where customers are using Active Directory for authentication it was possible for an unauthenticated user to make an API request against two endpoints which would retrieve some data from the associated Active Directory. The requests when crafted correctly would return specific information from user profiles (Email address/UPN and Display name) from one endpoint and group information ( Group ID and Display name) from the other. This vulnerability does not ex | 6.9 | 0.29% | 2025-02-11 | 2026-06-17 |