8.7

CVSS4.0

CVE-2026-5214 - D-Link DNS-1550-04 account_mgr.cgi cgi_addgroup_get_group_quota_minsize stack-based overflow

A vulnerability was found in D-Link DNS-120, DNR-202L, DNS-315L, DNS-320, DNS-320L, DNS-320LW, DNS-321, DNR-322L, DNS-323, DNS-325, DNS-326, DNS-327L, DNR-326, DNS-340L, DNS-343, DNS-345, DNS-726-4, DNS-1100-4, DNS-1200-05 and DNS-1550-04 up to 20260205. Impacted is the function cgi_addgroup_get_gr…

πŸ“… Published: March 31, 2026, 9:15 p.m. πŸ”„ Last Modified: April 3, 2026, 9:19 a.m.

6.5

CVSS3.1

CVE-2026-34401 - XML Notepad: XML External Entity (XXE) Injection via Unsafe XmlTextReader in XML Diff and Schema Lo…

XML Notepad is a Windows program that provides a simple intuitive User Interface for browsing and editing XML documents. Prior to version 2.9.0.21, XML Notepad does not disable DTD processing by default which means external entities are resolved automatically. There is a well known attack related t…

πŸ“… Published: March 31, 2026, 9:05 p.m. πŸ”„ Last Modified: April 14, 2026, 4:42 p.m.

6.9

CVSS4.0

CVE-2026-34400 - alerta-server has potential SQL Injection vulnerability in Query String Syntax (q=) API

Alerta is a monitoring tool. Prior to version 9.1.0, the Query string search API (q=) was vulnerable to SQL injection via the Postgres query parser, which built WHERE clauses by interpolating user-supplied search terms directly into SQL strings via f-strings. This issue has been patched in version …

πŸ“… Published: March 31, 2026, 9 p.m. πŸ”„ Last Modified: April 10, 2026, 9:45 a.m.

6.5

CVSS3.1

CVE-2026-34740 - AVideo: Stored SSRF via Video EPG Link Missing isSSRFSafeURL() Validation

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the EPG (Electronic Program Guide) link feature in AVideo allows authenticated users with upload permissions to store arbitrary URLs that the server fetches on every EPG page visit. The URL is validated only with PHP's FILTER…

πŸ“… Published: March 31, 2026, 8:57 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

6.1

CVSS3.1

CVE-2026-34739 - AVideo: Reflected XSS via Unescaped ip Parameter in User_Location testIP.php

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the User_Location plugin's testIP.php page reflects the ip request parameter directly into an HTML input element without applying htmlspecialchars() or any other output encoding. This allows an attacker to inject arbitrary HT…

πŸ“… Published: March 31, 2026, 8:56 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

4.3

CVSS3.1

CVE-2026-34738 - AVideo: Video Publishing Workflow Bypass via Unauthorized overrideStatus Request Parameter

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's video processing pipeline accepts an overrideStatus request parameter that allows any uploader to set a video's status to any valid state, including "active" (a). This bypasses the admin-controlled moderation and dra…

πŸ“… Published: March 31, 2026, 8:55 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

6.5

CVSS3.1

CVE-2026-34737 - AVideo: Arbitrary Stripe Subscription Cancellation via Debug Endpoint and retrieveSubscriptions() B…

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the StripeYPT plugin includes a test.php debug endpoint that is accessible to any logged-in user, not just administrators. This endpoint processes Stripe webhook-style payloads and triggers subscription operations, including …

πŸ“… Published: March 31, 2026, 8:53 p.m. πŸ”„ Last Modified: April 3, 2026, 4:34 p.m.

6.5

CVSS3.1

CVE-2026-34733 - AVideo: Unauthenticated File Deletion via PHP Operator Precedence Bug in CLI Guard

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo installation script install/deleteSystemdPrivate.php contains a PHP operator precedence bug in its CLI-only access guard. The script is intended to run exclusively from the command line, but the guard condition !ph…

πŸ“… Published: March 31, 2026, 8:52 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

5.3

CVSS3.1

CVE-2026-34732 - AVideo: Missing Authentication in CreatePlugin list.json.php Template Affects 21 Endpoints

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin template for list.json.php does not include any authentication or authorization check. While the companion templates add.json.php and delete.json.php both require admin privileges, the list.json.php te…

πŸ“… Published: March 31, 2026, 8:51 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.

7.5

CVSS3.1

CVE-2026-34731 - AVideo: Unauthenticated Live Stream Termination via RTMP Callback on_publish_done.php

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo on_publish_done.php endpoint in the Live plugin allows unauthenticated users to terminate any active live stream. The endpoint processes RTMP callback events to mark streams as finished in the database, but perform…

πŸ“… Published: March 31, 2026, 8:50 p.m. πŸ”„ Last Modified: April 2, 2026, 8:10 p.m.
Total resulsts: 349182
Page 769 of 34,919
Β« previous page Β» next page
Filters