8.8

CVSS3.1

CVE-2026-33648 - AVideo Vulnerable to OS Command Injection via Unsanitized `users_id` and `liveTransmitionHistory_id…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a log file path by embedding user-controlled `users_id` and `liveTransmitionHistory_id` values from the JSON request body without any sanitization. This log file path is then conca…

📅 Published: March 23, 2026, 6:25 p.m. 🔄 Last Modified: March 25, 2026, 8:37 p.m.

8.8

CVSS3.1

CVE-2026-33647 - AVideo Vulnerable to Remote Code Execution via MIME/Extension Mismatch in ImageGallery File Upload

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` method validates uploaded file content using `finfo` MIME type detection but derives the saved filename extension from the user-supplied original filename without an allowlist check. A…

📅 Published: March 23, 2026, 6:23 p.m. 🔄 Last Modified: March 25, 2026, 8:37 p.m.

8.6

CVSS3.1

CVE-2026-33513 - AVideo has an Unauthenticated Local File Inclusion in API locale (RCE possible with writable PHP)

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates user input into an `include` path with no canonicalization or whitelist. Path traversal is accepted, so arbitrary PHP files under the web root can be i…

📅 Published: March 23, 2026, 6:21 p.m. 🔄 Last Modified: March 25, 2026, 9:27 p.m.

7.5

CVSS3.1

CVE-2026-33512 - AVideo has an unauthenticated decrypt oracle leaking any ciphertext

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptString` action without any authentication. Anyone can submit ciphertext and receive plaintext. Ciphertext is issued publicly (e.g., `view/url2Embed.json.php`), so any user can recove…

📅 Published: March 23, 2026, 6:17 p.m. 🔄 Last Modified: March 25, 2026, 9:27 p.m.

8.5

CVSS4.0

CVE-2025-15605 - Hardcoded Cryptographic Key in Configuration Encryption Mechanism on TP-Link Archer NX200, NX210, N…

A hardcoded cryptographic key within the configuration mechanism on TP-Link Archer NX200, NX210, NX500 and NX600 enables decryption and re-encryption of device configuration data. An authenticated attacker may decrypt configuration files, modify them, and re-encrypt them, affecting the confidential…

📅 Published: March 23, 2026, 6:02 p.m. 🔄 Last Modified: March 25, 2026, 8:37 p.m.

8.5

CVSS4.0

CVE-2025-15519 - Command Injection in Modem Management CLI on TP-Link Archer NX200, NX210, NX500 and NX600

Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operati…

📅 Published: March 23, 2026, 6:01 p.m. 🔄 Last Modified: March 25, 2026, 8:37 p.m.

8.5

CVSS4.0

CVE-2025-15518 - Command Injection in Wireless Control CLI on TP-Link Archer NX200, NX210, NX500 and NX600

Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An authenticated attacker with administrative privileges may execute arbitrary commands on the operati…

📅 Published: March 23, 2026, 6:01 p.m. 🔄 Last Modified: March 25, 2026, 8:37 p.m.

8.6

CVSS4.0

CVE-2025-15517 - Authorization Bypass in HTTP Server Endpoints on TP-Link Archer NX200, NX210, NX500 and NX600

A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker may perform privileged HTTP actions without authentication, including firmware upload and configurat…

📅 Published: March 23, 2026, 6:01 p.m. 🔄 Last Modified: March 25, 2026, 8:37 p.m.

6.9

CVSS4.0

CVE-2026-4594 - erupts erupt EruptJpaUtils.java geneEruptHqlOrderBy sql injection

A vulnerability has been found in erupts erupt up to 1.13.3. Affected by this issue is the function geneEruptHqlOrderBy of the file erupt-data/erupt-jpa/src/main/java/xyz/erupt/jpa/dao/EruptJpaUtils.java. Such manipulation of the argument sort.field leads to sql injection hibernate. It is possible …

📅 Published: March 23, 2026, 5:41 p.m. 🔄 Last Modified: March 24, 2026, 10:33 a.m.

5.3

CVSS4.0

CVE-2026-4593 - erupts erupt MCP Tool EruptDataQuery.java EruptDataQuery sql injection

A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the file erupt-ai/src/main/java/xyz/erupt/ai/call/impl/EruptDataQuery.java of the component MCP Tool Interface. This manipulation causes sql injection hibernate. It is possible to init…

📅 Published: March 23, 2026, 4:55 p.m. 🔄 Last Modified: March 25, 2026, 2:19 p.m.
Total resulsts: 340786
Page 132 of 34,079
« previous page » next page
Filters