6.9

CVSS4.0

CVE-2026-32845 - jkuhlmann / cgltf <= 1.15 Sparse Accessor Validation Integer Overflow

cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating sparse accessors that allows attackers to trigger out-of-bounds reads by supplying crafted glTF/GLB input files with attacker-controlled size values. Attackers can exploit uncheckโ€ฆ

๐Ÿ“… Published: March 23, 2026, 3:50 p.m. ๐Ÿ”„ Last Modified: March 31, 2026, 3:12 p.m.

7.3

CVSS3.1

CVE-2026-33492 - AVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regeneration

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function accepts arbitrary session IDs via the `PHPSESSID` GET parameter and sets them as the active PHP session. A session regeneration bypass exists for specific blacklisted endpoints wโ€ฆ

๐Ÿ“… Published: March 23, 2026, 3:25 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 8:37 p.m.

7.4

CVSS3.1

CVE-2026-33488 - AVideo has a PGP 2FA Bypass via Cryptographically Broken 512-bit RSA Key Generation in LoginControlโ€ฆ

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the LoginControl plugin's PGP 2FA system generates 512-bit RSA keys, which have been publicly factorable since 1999. An attacker who obtains a target user's public key can factor the 5โ€ฆ

๐Ÿ“… Published: March 23, 2026, 3:23 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 9:27 p.m.

5.1

CVSS4.0

CVE-2026-4591 - kalcaddle kodbox fileThumb Endpoint app.php checkBin os command injection

A weakness has been identified in kalcaddle kodbox 1.64. This affects the function checkBin of the file /workspace/source-code/plugins/fileThumb/app.php of the component fileThumb Endpoint. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit hโ€ฆ

๐Ÿ“… Published: March 23, 2026, 3:15 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:32 p.m.

0.0

CVE-2026-4656 -

This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

๐Ÿ“… Published: March 23, 2026, 3:03 p.m. ๐Ÿ”„ Last Modified: April 7, 2026, 10:19 p.m.

9.4

CVSS3.1

CVE-2026-4404 - Use of hard coded credentials in GoHarbor Harbor

Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use the default password and gain access to the web UI.

๐Ÿ“… Published: March 23, 2026, 2:47 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 9:27 p.m.

2.3

CVSS4.0

CVE-2026-4590 - kalcaddle kodbox loginSubmit API index.class.php cross-site request forgery

A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /workspace/source-code/plugins/oauth/controller/bind/index.class.php of the component loginSubmit API. Performing a manipulation of the argument third results in cross-site request โ€ฆ

๐Ÿ“… Published: March 23, 2026, 2:24 p.m. ๐Ÿ”„ Last Modified: April 24, 2026, 4:32 p.m.

7.5

CVSS3.1

CVE-2026-33485 - AVideo has an Unauthenticated Blind SQL Injection in RTMP on_publish Callback via Stream Name Paramโ€ฆ

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `plugin/Live/on_publish.php` is accessible without authentication. The `$_POST['name']` parameter (stream key) is interpolated directly into SQL queries in two locations โ€” `LiveTranโ€ฆ

๐Ÿ“… Published: March 23, 2026, 2:14 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 9:28 p.m.

7.5

CVSS3.1

CVE-2026-33483 - AVideo Affected by Unauthenticated Disk Space Exhaustion via Unlimited Temp File Creation in aVideoโ€ฆ

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` endpoint is a completely standalone PHP script with no authentication, no framework includes, and no resource limits. An unauthenticated remote attacker can send arbitrary POST dataโ€ฆ

๐Ÿ“… Published: March 23, 2026, 2:12 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 9:28 p.m.

8.1

CVSS3.1

CVE-2026-33482 - AVideo has an OS Command Injection via $() Shell Substitution Bypass in sanitizeFFmpegCommand()

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/functions.php` is designed to prevent OS command injection in ffmpeg commands by stripping dangerous shell metacharacters (`&&`, `;`, `|`, `` ` ``, `<โ€ฆ

๐Ÿ“… Published: March 23, 2026, 2:10 p.m. ๐Ÿ”„ Last Modified: March 25, 2026, 9:28 p.m.
Total resulsts: 349182
Page 970 of 34,919
ยซ previous page ยป next page
Filters