Qanything
This hub aggregates every CVE we track for Qanything, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
OSS Librariesother
9
CVEs tracked
3
Critical
5
High
0
In CISA KEV
Severity distribution
HIGH5CRITICAL3MEDIUM1
Monthly trend
1
0
0
0
0
6
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
0
1
2024-102026-09
Latest CVEs
The 9 most recently published vulnerabilities affecting Qanything.
- CVE-2026-85671QAnything 2.0.0 Unauthenticated Cross-User File Disclosure7.5
- CVE-2024-12866Local File Inclusion in netease-youdao/qanything7.5
- CVE-2024-8026CSRF due to overly permissive CORS headers in netease-youdao/qanything8.1
- CVE-2024-12864Unauthenticated DoS by Sending Large Filename at File Upload Endpoint in netease-youdao/qanything7.5
- CVE-2024-8027Stored Cross-Site Scripting (XSS) in netease-youdao/QAnything6.1
- CVE-2024-8024CORS Misconfiguration in netease-youdao/qanything7.5
- CVE-2024-10264HTTP Request Smuggling in netease-youdao/qanything9.8
- CVE-2024-7099SQL Injection in netease-youdao/qanything9.8
- CVE-2024-25722qanything_kernel/connector/database/mysql/mysql_client.py in qanything.ai QAnything before 1.2.0 allows SQL Injection.9.8
Product normalization is registry-driven with AI assist and human review. How it works