5.4

CVSS3.1

CVE-2026-34362 - AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyTokenSocket…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never expire despite being generated with a 12-hour timeout. This al…

📅 Published: March 27, 2026, 4:42 p.m. 🔄 Last Modified: March 31, 2026, 8 p.m.

5.4

CVSS3.1

CVE-2026-34247 - AVideo's IDOR in uploadPoster.php Allows Any Authenticated User to Overwrite Scheduled Live Stream …

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` endpoint allows any authenticated user to overwrite the poster image for any scheduled live stream by supplying an arbitrary `live_schedule_id`. The endpoint only checks `User::isL…

📅 Published: March 27, 2026, 4:39 p.m. 🔄 Last Modified: March 31, 2026, 8 p.m.

7.1

CVSS4.0

CVE-2025-15616 - Wazuh Agent and Manager OS Command Injection and Untrusted Search Path

Wazuh wazuh-agent and wazuh-manager versions 2.1.0 before 4.8.0 contain multiple shell injection and untrusted search path vulnerabilities that allow attackers to execute arbitrary commands through various components including logcollector configuration, maild SMTP server tags, and Kaspersky AR scr…

📅 Published: March 27, 2026, 4:38 p.m. 🔄 Last Modified: March 31, 2026, 8 p.m.

6.3

CVSS3.1

CVE-2026-34245 - AVideo's Missing Authorization in Playlist Schedule Creation Allows Cross-User Broadcast Hijacking

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endpoint allows any authenticated user with streaming permission to create or modify broadcast schedules targeting any playlist on the platform, regardles…

📅 Published: March 27, 2026, 4:32 p.m. 🔄 Last Modified: March 31, 2026, 8 p.m.

9.1

CVSS4.0

CVE-2026-33867 - AVideo has Plaintext Video Password Storage

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext — no hashing, salting, or encryption is applied. If an attacker gains read access to the …

📅 Published: March 27, 2026, 4:30 p.m. 🔄 Last Modified: March 31, 2026, 8:01 p.m.

6.9

CVSS4.0

CVE-2026-34411 - Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs

Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoints like /api/v1/consolidated-api/view and /api/v1/tenants/current to retrieve configuration metadata, license information, and unsalted SHA-256 hashe…

📅 Published: March 27, 2026, 4:24 p.m. 🔄 Last Modified: March 31, 2026, 8:01 p.m.

6.9

CVSS4.0

CVE-2025-15615 - Wazuh Manager authd service Improper SSL/TLS Renegotiation Handling leading to Denial of Service

Wazuh Manager authd service in wazuh-manager packages through version 4.7.3 contains an improper restriction of client-initiated SSL/TLS renegotiation vulnerability that allows remote attackers to cause a denial of service by sending excessive renegotiation requests. Attackers can exploit the lack …

📅 Published: March 27, 2026, 4:23 p.m. 🔄 Last Modified: March 31, 2026, 8:01 p.m.

8.1

CVSS3.1

CVE-2025-15381 - Unauthorized Access to Tracing and Assessment Endpoints in mlflow/mlflow

In the latest version of mlflow/mlflow, when the `basic-auth` app is enabled, tracing and assessment endpoints are not protected by permission validators. This allows any authenticated user, including those with `NO_PERMISSIONS` on the experiment, to read trace information and create assessments fo…

📅 Published: March 27, 2026, 4:17 p.m. 🔄 Last Modified: March 31, 2026, 8:01 p.m.

7.1

CVSS4.0

CVE-2026-33770 - AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title and id Var…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method in `objects/category.php` constructs a SQL SELECT query by directly interpolating both `$clean_title` and `$id` into the query string without using prepared statements or paramete…

📅 Published: March 27, 2026, 4:13 p.m. 🔄 Last Modified: March 31, 2026, 8:01 p.m.

8.7

CVSS3.1

CVE-2026-28369 - Undertow: undertow: request smuggling via malformed http request headers

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces. This behavior, which violates HTTP standards, can be exploited by a remote attacker to perform req…

📅 Published: March 27, 2026, 4:13 p.m. 🔄 Last Modified: April 8, 2026, 8:29 a.m.
Total resulsts: 349182
Page 829 of 34,919
« previous page » next page
Filters