avo vulnerabilities

Browse known CVEs and advisories by package and ecosystem. Severity tells you the worst case. What determines real risk is whether the vulnerable code actually runs in your applications.

Get a demo

Browse by ecosystem

npmPyPIMavenGoRubyGemsCargoNuGetComposerpubSwiftGitHub Actions
CVE-IDSeverityPackage summary
CVE-2026-53769Mediumavo: Avo: Direct attachment upload endpoint lacks upload authorization and bypasses field-level upload policyCVE-2026-55518Criticalavo: Avo: Missing Authorization in Avo Association Attach Endpoint Allows Unauthorized Relationship Manipulation and Privilege EscalationCVE-2026-42205Highavo: Avo: Broken Access Control Through Unauthorized Execution of Arbitrary Action Classes Across ResourcesCVE-2026-33209Mediumavo: Avo has a XSS vulnerability on `return_to` paramCVE-2024-22411Mediumavo: Cross-site scripting (XSS) in Action messages on AvoCVE-2024-22191Highavo: avo vulnerable to stored cross-site scripting (XSS) in key_value fieldCVE-2023-34102Highavo: avo possible unsafe reflection / partial DoS vulnerabilityCVE-2023-34103Highavo: avo vulnerable to Stored XSS (Cross Site Scripting) in html content based fields

Stop the waste.
Protect your environment with Kodem.