5.3

CVSS3.1

CVE-2026-33763 - AVideo has an Unauthenticated Video Password Brute-Force Vulnerability via Unrate-Limited Boolean O…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_correct` API endpoint allows any unauthenticated user to verify whether a given password is correct for any password-protected video. The endpoint returns a boolean `passwordIsCorrect`…

📅 Published: March 27, 2026, 2:25 p.m. 🔄 Last Modified: March 30, 2026, 7:01 a.m.

9.1

CVSS3.1

CVE-2026-27876 - RCE on Grafana via sqlExpressions

A chained attack via SQL Expressions and a Grafana Enterprise plugin can lead to a remote arbitrary code execution impact (RCE). This is enabled by a feature in Grafana (OSS), so all users are always recommended to update to avoid future attack vectors going this path. Only instances with the sqlE…

📅 Published: March 27, 2026, 2:24 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

5.3

CVSS3.1

CVE-2026-33761 - AVideo: Unauthenticated Access to Scheduler Plugin Endpoints Leaks Scheduled Tasks, Email Content, …

WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in the Scheduler plugin lack any authentication check, while every other endpoint in the same plugin directories (`add.json.php`, `delete.json.php`, `index.php`) requires `User::isAdm…

📅 Published: March 27, 2026, 2:24 p.m. 🔄 Last Modified: March 30, 2026, 7:01 a.m.

5.3

CVSS3.1

CVE-2026-33759 - AVideo: Unauthenticated IDOR in playlistsVideos.json.php Exposes Private Playlist Contents

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.php` endpoint returns the full video contents of any playlist by ID without any authentication or authorization check. Private playlists (including `watch_later` and `favorite` type…

📅 Published: March 27, 2026, 2:18 p.m. 🔄 Last Modified: March 30, 2026, 7:01 a.m.

9.3

CVSS4.0

CVE-2026-1496 - Coverity CLI Authentication Bypass

Vulnerable versions of Coverity Connect lack an error handler in the authentication logic for command line tooling that makes it vulnerable to an authentication bypass. A malicious actor with access to the /token API endpoint that either knows or guesses a valid username, can use this in a speciall…

📅 Published: March 27, 2026, 2:14 p.m. 🔄 Last Modified: March 30, 2026, 7:01 a.m.

8.2

CVSS3.1

CVE-2026-4984 - Botpress - Credential Disclosure via Twilio Webhook Handler

The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When processing media messages, it fetches user-controlled URLs ('MediaUrlN' parameters) using HTTP requests that include the integration's Twilio credentials in the 'Authorization' he…

📅 Published: March 27, 2026, 2:13 p.m. 🔄 Last Modified: March 30, 2026, 7:59 a.m.

5.3

CVSS4.0

CVE-2026-4954 - mingSoft MCMS Web Content List Endpoint ContentAction.java list sql injection

A security vulnerability has been detected in mingSoft MCMS up to 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoint. The manipulation leads to sql injection. The attack can be initiated remotely. The exploit ha…

📅 Published: March 27, 2026, 2:13 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

6.9

CVSS4.0

CVE-2026-4953 - mingSoft MCMS Editor Endpoint BaseAction.java catchImage server-side request forgery

A weakness has been identified in mingSoft MCMS up to 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a manipulation of the argument catchimage can lead to server-side request forgery. It is possible t…

📅 Published: March 27, 2026, 2:13 p.m. 🔄 Last Modified: March 29, 2026, 8:30 p.m.

9.4

CVSS4.0

CVE-2026-33758 - OpenBao has Reflected XSS in its OIDC authentication error message

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=direct` configured are vulnerable to XSS via the `error_description` parameter on the page for a fail…

📅 Published: March 27, 2026, 2:12 p.m. 🔄 Last Modified: March 30, 2026, 7:01 a.m.

7.5

CVSS3.1

CVE-2026-27880 - OpenFeature evaluation API reads input data with no bounds

The OpenFeature feature toggle evaluation endpoint reads unbounded values into memory, which can cause out-of-memory crashes.

📅 Published: March 27, 2026, 2:12 p.m. 🔄 Last Modified: March 30, 2026, 7:01 a.m.
Total resulsts: 341106
Page 28 of 34,111
« previous page » next page
Filters