7.1

CVSS4.0

CVE-2026-33770 - AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title and id Var…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method in `objects/category.php` constructs a SQL SELECT query by directly interpolating both `$clean_title` and `$id` into the query string without using prepared statements or paramete…

📅 Published: March 27, 2026, 4:13 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.

8.7

CVSS3.1

CVE-2026-28369 - Undertow: undertow: request smuggling via malformed http request headers

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform req…

📅 Published: March 27, 2026, 4:13 p.m. 🔄 Last Modified: March 29, 2026, 1:56 p.m.

8.7

CVSS3.1

CVE-2026-28367 - Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, such as older versions of Apache Traffic Server and Google Cloud Classic Application Load Balancer, pot…

📅 Published: March 27, 2026, 4:13 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.

8.7

CVSS3.1

CVE-2026-28368 - Undertow: undertow: request smuggling via inconsistent header parsing

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. This discrepancy in header interpretation can be exploited to launch request smuggling attacks, poten…

📅 Published: March 27, 2026, 4:13 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.

7.1

CVSS4.0

CVE-2026-33767 - AVideo has SQL Injection via Partial Prepared Statement — videos_id Concatenated Directly into Query

WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike()` method constructs a SQL query using a prepared statement placeholder (`?`) for `users_id` but directly concatenates `$this->videos_id` into the query string without parameteriz…

📅 Published: March 27, 2026, 4:12 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.

8.7

CVSS4.0

CVE-2026-4961 - Tenda AC6 POST Request QuickIndex formQuickIndex stack-based overflow

A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. The manipulation of the argument PPPOEPassword leads to stack-based buffer overflow. The attack is possible to…

📅 Published: March 27, 2026, 4:09 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

8.7

CVSS4.0

CVE-2026-4960 - Tenda AC6 POST Request WizardHandle fromWizardHandle stack-based overflow

A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of the argument WANT/WANS can lead to stack-based buffer overflow. The attack can be executed remotely.…

📅 Published: March 27, 2026, 4:09 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

5.3

CVSS4.0

CVE-2023-7340 - Wazuh authd service (os_auth) Heap-based Buffer Overflow

Wazuh authd contains a heap-buffer overflow vulnerability that allows attackers to cause memory corruption and malformed heap data by sending specially crafted input. Attackers can exploit this vulnerability to trigger a denial of service condition, resulting in low availability impact to the authe…

📅 Published: March 27, 2026, 3:52 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.

6.9

CVSS4.0

CVE-2026-32983 - SSL/TLS Renegotiation DoS in Wazuh Manager authd service

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack …

📅 Published: March 27, 2026, 3:44 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.

6.9

CVSS4.0

CVE-2026-4959 - OpenBMB XAgent ShareServer WebSocket Endpoint share.py check_user missing authentication

A vulnerability was found in OpenBMB XAgent 1.0.0. This impacts the function check_user of the file XAgentServer/application/websockets/share.py of the component ShareServer WebSocket Endpoint. Performing a manipulation of the argument interaction_id results in missing authentication. Remote exploi…

📅 Published: March 27, 2026, 3:31 p.m. 🔄 Last Modified: March 27, 2026, 8:28 p.m.
Total resulsts: 341070
Page 22 of 34,107
« previous page » next page
Filters