5.5

CVSS4.0

CVE-2026-41130 - Craft CMS has a host header injection leading to SSRF via resource-js endpoint

Craft CMS is a content management system (CMS). In versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14, the `resource-js` endpoint in Craft CMS allows unauthenticated requests to proxy remote JavaScript resources. When `trustedHosts` is not explicitly restricted (default co…

πŸ“… Published: April 21, 2026, 11:36 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

5.5

CVSS4.0

CVE-2026-41129 - Craft CMS has Server-Side Request Forgery (SSRF) with Asset Uploads Mutations

Craft CMS is a content management system (CMS). Versions on the 4.x branch through 4.17.8 and the 5.x branch through 5.9.14 are vulnerable to Server-Side Request Forgery. The exploitation requires a few permissions to be enabled in the used GraphQL schema: "Edit assets in the <VolumeName> volume" a…

πŸ“… Published: April 21, 2026, 11:34 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

5.3

CVSS4.0

CVE-2026-41128 - Craft CMS has a Missing Authorization Check on User Group Removal via save-permissions Action

Craft CMS is a content management system (CMS). In versions 5.6.0 through 5.9.14, the `actionSavePermissions()` endpoint allows a user with only `viewUsers` permission to remove arbitrary users from all user groups. While `_saveUserGroups()` enforces per-group authorization for additions, it perfor…

πŸ“… Published: April 21, 2026, 11:32 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

6.5

CVSS3.1

CVE-2026-41127 - BigBlueButton's missing authorization allows viewer to inject/overwrite captions

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have a missing authorization that allows viewers to inject/overwrite captions Version 3.0.24 tightened the permissions on who is able to submit captions. No known workarounds are available.

πŸ“… Published: April 21, 2026, 11:24 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

4.3

CVSS3.1

CVE-2026-41126 - BigBlueButton has Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL"

BigBlueButton is an open-source virtual classroom. Versions prior to 3.0.24 have an Open Redirect through bigbluebutton/api/join via get-parameter "logoutURL." Version 3.0.24 has adjusted the handling of requests with incorrect checksum so that the default logoutURL is used. No known workarounds ar…

πŸ“… Published: April 21, 2026, 11:22 p.m. πŸ”„ Last Modified: April 22, 2026, 8:26 p.m.

9.1

CVSS3.1

CVE-2026-40575 - OAuth2 Proxy has an Authentication Bypass via X-Forwarded-Uri Header Spoofing

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 may trust a client-supplied `X-Forwarded-Uri` header when `--reverse-proxy` is enabled and `--skip-auth-regex` or `--skip-auth-route` is configured. An attacker can spoof this header s…

πŸ“… Published: April 21, 2026, 11:20 p.m. πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

8.2

CVSS3.1

CVE-2026-41059 - OAuth2 Proxy has an Authentication Bypass via Fragment Confusion in skip_auth_routes and skip_auth_…

OAuth2 Proxy is a reverse proxy that provides authentication using OAuth2 providers. Versions 7.5.0 through 7.15.1 have a configuration-dependent authentication bypass. Deployments are affected when all of the following are true: Use of `skip_auth_routes` or the legacy `skip_auth_regex`; use of pat…

πŸ“… Published: April 21, 2026, 11:17 p.m. πŸ”„ Last Modified: April 22, 2026, 9:23 p.m.

8.9

CVSS4.0

CVE-2026-41304 - WWBN AVideo vulnerable to RCE caused by clonesite plugin

WWBN AVideo is an open source video platform. In versions 29.0 and below, the `cloneServer.json.php` endpoint in the CloneSite plugin constructs shell commands using user-controlled input (`url` parameter) without proper sanitization. The input is directly concatenated into a `wget` command execute…

πŸ“… Published: April 21, 2026, 11:07 p.m. πŸ”„ Last Modified: April 24, 2026, 3:11 p.m.

9.3

CVSS3.1

CVE-2026-41064 - AVideo has an incomplete fix for CVE-2026-33502 (Command Injection)

WWBN AVideo is an open source video platform. In versions up to and including 29.0, an incomplete fix for AVideo's `test.php` adds `escapeshellarg` for wget but leaves the `file_get_contents` and `curl` code paths unsanitized, and the URL validation regex `/^http/` accepts strings like `httpevil[.]…

πŸ“… Published: April 21, 2026, 11:04 p.m. πŸ”„ Last Modified: April 24, 2026, 3:10 p.m.

5.4

CVSS3.1

CVE-2026-41063 - WWBN AVideo has incomplete fix for CVE-2026-33500 (XSS)

WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete XSS fix in AVideo's `ParsedownSafeWithLinks` class overrides `inlineMarkup` for raw HTML but does not override `inlineLink()` or `inlineUrlTag()`, allowing `javascript:` URLs in markdown link syntax to bypass sa…

πŸ“… Published: April 21, 2026, 10:59 p.m. πŸ”„ Last Modified: April 24, 2026, 3:08 p.m.
Total resulsts: 346554
Page 84 of 34,656
Β« previous page Β» next page
Filters