8.6

CVSS4.0

CVE-2025-15517 - Authorization Bypass in HTTP Server Endpoints on TP-Link Archer NX200, NX210, NX500 and NX600

A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configurat…

📅 Published: March 23, 2026, 6:01 p.m. 🔄 Last Modified: March 25, 2026, 8:37 p.m.

6.9

CVSS4.0

CVE-2026-4594 - erupts erupt EruptJpaUtils.java geneEruptHqlOrderBy sql injection

A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this issue is the function geneEruptHqlOrderBy of the file erupt-data/erupt-jpa/src/main/java/xyz/erupt/jpa/dao/EruptJpaUtils.java. Such manipulation of the argument sort.field leads to sql injection hibernate. It is possible …

📅 Published: March 23, 2026, 5:41 p.m. 🔄 Last Modified: March 24, 2026, 10:33 a.m.

5.3

CVSS4.0

CVE-2026-4593 - erupts erupt MCP Tool EruptDataQuery.java EruptDataQuery sql injection

A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the file erupt-ai/src/main/java/xyz/erupt/ai/call/impl/EruptDataQuery.java of the component MCP Tool Interface. This manipulation causes sql injection hibernate. It is possible to init…

📅 Published: March 23, 2026, 4:55 p.m. 🔄 Last Modified: March 25, 2026, 2:19 p.m.

8.8

CVSS3.1

CVE-2026-33507 - AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Execution via…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users to upload and install plugin ZIP files containing executable PHP code, but lacks any CSRF protection. Combined with the application explicitly setting …

📅 Published: March 23, 2026, 4:32 p.m. 🔄 Last Modified: March 25, 2026, 8:37 p.m.

9.3

CVSS3.1

CVE-2026-33502 - AVideo has Unauthenticated SSRF via plugin/Live/test.php

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to make the AVideo server send HTTP requests to arbitrary URLs. This can be used to probe localhost/inter…

📅 Published: March 23, 2026, 4:29 p.m. 🔄 Last Modified: March 25, 2026, 8:37 p.m.

5.3

CVSS3.1

CVE-2026-33501 - AVideo has Unauthenticated Information Disclosure of User Group Permission Mappings via Permissions…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/list.json.php` lacks any authentication or authorization check, allowing unauthenticated users to retrieve the complete permission matrix mapping user g…

📅 Published: March 23, 2026, 4:28 p.m. 🔄 Last Modified: March 25, 2026, 8:37 p.m.

5.4

CVSS3.1

CVE-2026-33500 - AVideo Vulnerable to Stored XSS via Markdown `javascript:` URI Bypasses ParsedownSafeWithLinks Sani…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcqw-6466-3mv7) introduced a custom `ParsedownSafeWithLinks` class that sanitizes raw HTML `<a>` and `<img>` tags in comments, but explicitly disables Parsedown's `safeMode`. This cr…

📅 Published: March 23, 2026, 4:24 p.m. 🔄 Last Modified: March 25, 2026, 8:37 p.m.

6.1

CVSS3.1

CVE-2026-33499 - AVideo has Reflected XSS via unlockPassword Parameter in forbiddenPage.php and warningPage.php

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `view/warningPage.php` templates reflect the `$_REQUEST['unlockPassword']` parameter directly into an HTML `<input>` tag's attributes without any output encoding or sanitization. An …

📅 Published: March 23, 2026, 4:11 p.m. 🔄 Last Modified: March 25, 2026, 8:37 p.m.

6.3

CVSS4.0

CVE-2026-4592 - kalcaddle kodbox Password Login index.class.php tfaVerify improper authentication

A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of the file /workspace/source-code/plugins/client/controller/tfa/index.class.php of the component Password Login. The manipulation leads to improper authentication. The attack is poss…

📅 Published: March 23, 2026, 3:56 p.m. 🔄 Last Modified: March 24, 2026, 10:33 a.m.

7.1

CVSS3.1

CVE-2026-33493 - AVideo has a Path Traversal in import.json.php that Allows Private Video Theft and Arbitrary File R…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoint accepts a user-controlled `fileURI` POST parameter with only a regex check that the value ends in `.mp4`. Unlike `objects/listFiles.json.php`, which was hardened with a `realpa…

📅 Published: March 23, 2026, 3:52 p.m. 🔄 Last Modified: March 25, 2026, 8:37 p.m.
Total resulsts: 340748
Page 129 of 34,075
« previous page » next page
Filters