5.3

CVSS4.0

CVE-2026-4963 - huggingface smolagents Incomplete Fix CVE-2025-9959 local_python_executor.py evaluate_with code inj…

A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the file src/smolagents/local_python_executor.py of the component Incomplete Fix CVE-2025-9959. This manipulation causes code injection. It is possible t…

📅 Published: March 27, 2026, 5:05 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

7.3

CVSS4.0

CVE-2026-4962 - UltraVNC Service version.dll uncontrolled search path

A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in the library version.dll of the component Service. The manipulation results in uncontrolled search path. The attack needs to be approached locally. This attack is characterized by h…

📅 Published: March 27, 2026, 5:05 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

5.4

CVSS3.1

CVE-2026-34362 - AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never expire despite being generated with a 12-hour timeout. This al…

📅 Published: March 27, 2026, 4:42 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.

5.4

CVSS3.1

CVE-2026-34247 - AVideo's IDOR in uploadPoster.php Allows Any Authenticated User to Overwrite Scheduled Live Stream …

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` endpoint allows any authenticated user to overwrite the poster image for any scheduled live stream by supplying an arbitrary `live_schedule_id`. The endpoint only checks `User::isL…

📅 Published: March 27, 2026, 4:39 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.

7.1

CVSS4.0

CVE-2025-15616 - Wazuh Agent and Manager OS Command Injection and Untrusted Search Path

Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vulnerabilities that allow attackers to execute arbitrary commands through various components including logcollector configuration, maild SMTP server tags, and Kaspersky AR scr…

📅 Published: March 27, 2026, 4:38 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.

6.3

CVSS3.1

CVE-2026-34245 - AVideo's Missing Authorization in Playlist Schedule Creation Allows Cross-User Broadcast Hijacking

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endpoint allows any authenticated user with streaming permission to create or modify broadcast schedules targeting any playlist on the platform, regardles…

📅 Published: March 27, 2026, 4:32 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.

9.1

CVSS4.0

CVE-2026-33867 - AVideo has Plaintext Video Password Storage

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext — no hashing, salting, or encryption is applied. If an attacker gains read access to the …

📅 Published: March 27, 2026, 4:30 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.

6.9

CVSS4.0

CVE-2026-34411 - Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs

Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoints like /api/v1/consolidated-api/view and /api/v1/tenants/current to retrieve configuration metadata, license information, and unsalted SHA-256 hashe…

📅 Published: March 27, 2026, 4:24 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.

6.9

CVSS4.0

CVE-2025-15615 - Wazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of Service

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack …

📅 Published: March 27, 2026, 4:23 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.

8.1

CVSS3.0

CVE-2025-15381 - Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflow

In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and create assessments fo…

📅 Published: March 27, 2026, 4:17 p.m. 🔄 Last Modified: March 28, 2026, 3:55 a.m.
Total resulsts: 341070
Page 21 of 34,107
« previous page » next page
Filters