7.5

CVSS3.0

CVE-2026-26209 - cbor2 has a Denial of Service via Uncontrolled Recursion in cbor2.loads

cbor2 provides encoding and decoding for the Concise Binary Object Representation (CBOR) serialization format. Versions prior to 5.9.0 are vulnerable to a Denial of Service (DoS) attack caused by uncontrolled recursion when decoding deeply nested CBOR structures. This vulnerability affects both the…

📅 Published: March 23, 2026, 6:53 p.m. 🔄 Last Modified: March 23, 2026, 6:53 p.m.

7.1

CVSS3.1

CVE-2026-33723 - AVideo Vulnerable to SQL Injection in Subscribe Endpoint via Unsanitized user_id Parameter in subsc…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `objects/subscribe.php` concatenates the `$this->users_id` property directly into an INSERT SQL query without sanitization or parameterized binding. This property originates from `$…

📅 Published: March 23, 2026, 6:50 p.m. 🔄 Last Modified: March 23, 2026, 6:50 p.m.

8.6

CVSS3.1

CVE-2026-33719 - AVideo Vulnerable to Unauthenticated CDN Configuration Takeover via Empty Default Key Bypass and Ma…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN/status.json.php` and `plugin/CDN/disable.json.php` use key-based authentication with an empty string default key. When the CDN plugin is enabled but the key has not been configur…

📅 Published: March 23, 2026, 6:49 p.m. 🔄 Last Modified: March 23, 2026, 6:49 p.m.

8.8

CVSS3.1

CVE-2026-33717 - AVideo Vulnerable to Remote Code Execution via Persistent PHP Temp File in Encoder downloadURL with…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()` function in `objects/aVideoEncoder.json.php` saves remote content to a web-accessible temporary directory using the original URL's filename and extension (including `.php`). By p…

📅 Published: March 23, 2026, 6:48 p.m. 🔄 Last Modified: March 23, 2026, 6:48 p.m.

9.4

CVSS3.1

CVE-2026-33716 - AVideo Allows Unauthenticated Live Stream Control via Token Verification URL Override in control.js…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplied `streamerURL` parameter that overrides where the server sends token verification requests. An att…

📅 Published: March 23, 2026, 6:46 p.m. 🔄 Last Modified: March 23, 2026, 6:46 p.m.

5.3

CVSS3.1

CVE-2026-33690 - AVideo vulnerable to IP Address Spoofing via Untrusted HTTP Headers in getRealIpAddr()

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `objects/functions.php` trusts user-controlled HTTP headers to determine the client's IP address. An attacker can spoof their IP address by sending forged headers, bypassing any IP-…

📅 Published: March 23, 2026, 6:45 p.m. 🔄 Last Modified: March 23, 2026, 6:45 p.m.

5.3

CVSS3.1

CVE-2026-33688 - AVideo has Pre-Captcha User Enumeration and Account Status Disclosure in Password Recovery Endpoint

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `objects/userRecoverPass.php` performs user existence and account status checks before validating the captcha. This allows an unauthenticated attacker to enumerate valid usernames a…

📅 Published: March 23, 2026, 6:43 p.m. 🔄 Last Modified: March 23, 2026, 6:43 p.m.

5.3

CVSS3.1

CVE-2026-33685 - AVideo Allows Unauthenticated Access to AD_Server reports.json.php that Exposes Ad Campaign Analyti…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.php` endpoint performs no authentication or authorization checks, allowing any unauthenticated attacker to extract ad campaign analytics data including video titles, user channel n…

📅 Published: March 23, 2026, 6:42 p.m. 🔄 Last Modified: March 23, 2026, 6:42 p.m.

9

CVSS4.0

CVE-2026-0898 - An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio dev…

An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25. This vulnerability does not affect Robot Runtime users. A bad actor could create a website that includes m…

📅 Published: March 23, 2026, 6:41 p.m. 🔄 Last Modified: March 23, 2026, 6:41 p.m.

5.4

CVSS3.1

CVE-2026-33683 - AVideo vulnerable to Stored XSS via html_entity_decode() Reversing xss_esc() Sanitization in Channe…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations flaw in the user profile "about" field allows any registered user to inject arbitrary JavaScript that executes when other users visit their channel page. The `xss_esc()` function e…

📅 Published: March 23, 2026, 6:41 p.m. 🔄 Last Modified: March 23, 2026, 6:41 p.m.
Total resulsts: 339488
Page 2 of 33,949
« previous page » next page
Filters