8.7

CVSS4.0

CVE-2026-5687 - Tenda CX12L NatStaticSetting fromNatStaticSetting stack-based overflow

A weakness has been identified in Tenda CX12L 16.03.53.12. This issue affects the function fromNatStaticSetting of the file /goform/NatStaticSetting. This manipulation of the argument page causes stack-based buffer overflow. The attack may be initiated remotely. The exploit has been made available …

πŸ“… Published: April 6, 2026, 10 p.m. πŸ”„ Last Modified: April 7, 2026, 6:53 a.m.

8.7

CVSS4.0

CVE-2026-35454 - Code Extension Marketplace has a Zip Slip Path Traversal

The Code Extension Marketplace is an open-source alternative to the VS Code Marketplace. Prior to 2.4.2, Zip Slip vulnerability in coder/code-marketplace allowed a malicious VSIX file to write arbitrary files outside the extension directory. ExtractZip passed raw zip entry names to a callback that …

πŸ“… Published: April 6, 2026, 9:51 p.m. πŸ”„ Last Modified: April 7, 2026, 2:35 p.m.

5.3

CVSS3.1

CVE-2026-35452 - WWBN AVideo has Unauthenticated Information Disclosure via Missing Auth on CloneSite client.log.php

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint serves the clone operation log file without any authentication. Every other endpoint in the CloneSite plugin directory enforces User::isAdmin(). The log contains internal filesyste…

πŸ“… Published: April 6, 2026, 9:47 p.m. πŸ”„ Last Modified: April 8, 2026, 2:08 p.m.

5.3

CVSS3.1

CVE-2026-35450 - WWBN AVideo has Unauthenticated FFmpeg Remote Server Status Disclosure via check.ffmpeg.json.php

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status without any authentication. All sibling FFmpeg management endpoints (kill.ffmpeg.json.php, list.ffmpe…

πŸ“… Published: April 6, 2026, 9:46 p.m. πŸ”„ Last Modified: April 7, 2026, 1:20 p.m.

5.3

CVSS3.1

CVE-2026-35449 - WWBN AVideo has Unauthenticated Information Disclosure via Disabled CLI Guard in install/test.php

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabled by commenting out the die() statement. The script remains accessible via HTTP after installation, exposing video viewer statistics including IP add…

πŸ“… Published: April 6, 2026, 9:46 p.m. πŸ”„ Last Modified: April 7, 2026, 2:16 p.m.

8.7

CVSS4.0

CVE-2026-5686 - Tenda CX12L RouteStatic fromRouteStatic stack-based overflow

A security flaw has been discovered in Tenda CX12L 16.03.53.12. This vulnerability affects the function fromRouteStatic of the file /goform/RouteStatic. The manipulation of the argument page results in stack-based buffer overflow. The attack can be launched remotely. The exploit has been released t…

πŸ“… Published: April 6, 2026, 9:45 p.m. πŸ”„ Last Modified: April 7, 2026, 6:53 a.m.

3.7

CVSS3.1

CVE-2026-35448 - WWBN AVideo Provides Unauthenticated Access to Payment Order Data via BlockonomicsYPT check.php

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the BlockonomicsYPT plugin's check.php endpoint returns payment order data for any Bitcoin address without requiring authentication. The endpoint was designed as an AJAX polling helper for the authenticated invoice.php page, …

πŸ“… Published: April 6, 2026, 9:45 p.m. πŸ”„ Last Modified: April 7, 2026, 2:37 p.m.

7.1

CVSS3.1

CVE-2026-35444 - SDL_image has a heap buffer overflow READ via unchecked colormap index in XCF loader

SDL_image is a library to load images of various formats as SDL surfaces. In do_layer_surface() in src/IMG_xcf.c, pixel index values from decoded XCF tile data are used directly as colormap indices without validating them against the colormap size (cm_num). A crafted .xcf file with a small colormap…

πŸ“… Published: April 6, 2026, 9:44 p.m. πŸ”„ Last Modified: April 8, 2026, 2:06 p.m.

9.8

CVSS3.0

CVE-2026-35471 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in goshs

goshs is a SimpleHTTPServer written in Go. Prior to 2.0.0-beta.3, tdeleteFile() missing return after path traversal check. This vulnerability is fixed in 2.0.0-beta.3.

πŸ“… Published: April 6, 2026, 9:38 p.m. πŸ”„ Last Modified: April 9, 2026, 9:20 p.m.

8.1

CVSS3.1

CVE-2026-35442 - Directus: Authenticated Users Can Extract Concealed Fields via Aggregate Queries

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, aggregate functions (min, max) applied to fields with the conceal special type incorrectly return raw database values instead of the masked placeholder. When combined with groupBy, any authenticated u…

πŸ“… Published: April 6, 2026, 9:36 p.m. πŸ”„ Last Modified: April 7, 2026, 1:30 p.m.
Total resulsts: 343919
Page 130 of 34,392
Β« previous page Β» next page
Filters