5

CVSS3.1

CVE-2026-33294 - AVideo has SSRF in BulkEmbed Thumbnail Fetch that Allows Reading Internal Network Resources

WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkEmbed/save.json.php`) fetches user-supplied thumbnail URLs via `url_get_contents()` without SSRF protection. Unlike all six other URL-fetching endpoints in AVideo that were hardene…

πŸ“… Published: March 22, 2026, 4:58 p.m. πŸ”„ Last Modified: March 25, 2026, 2:50 p.m.

8.7

CVSS4.0

CVE-2026-4555 - D-Link DIR-513 boa formEasySetTimezone memory corruption

A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component boa. This manipulation of the argument curTime causes stack-based buffer overflow. The attack can be initiated remotely. The explo…

πŸ“… Published: March 22, 2026, 4:51 p.m. πŸ”„ Last Modified: April 7, 2026, 8:09 a.m.

5.3

CVSS4.0

CVE-2026-4554 - Tenda F453 WriteFacMac FormWriteFacMac privilege escalation

A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been released to the publ…

πŸ“… Published: March 22, 2026, 4:51 p.m. πŸ”„ Last Modified: April 3, 2026, 9:18 p.m.

8.1

CVSS3.1

CVE-2026-33293 - AVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump Parameter

WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed directly to `unlink()` without any path sanitization. An attacker with valid clone credentials can use path traversal sequences (e.g., `../../`) to de…

πŸ“… Published: March 22, 2026, 4:35 p.m. πŸ”„ Last Modified: March 25, 2026, 2:50 p.m.

5.9

CVSS3.1

CVE-2026-33319 - AVideo Vulnerable to OS Command Injection via Unescaped URL in LinkedIn Video Upload Shell Command

WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin constructs a shell command by directly interpolating an upload URL received from LinkedIn's API response, without sanitization via `escapeshellarg()`. If an a…

πŸ“… Published: March 22, 2026, 4:29 p.m. πŸ”„ Last Modified: March 25, 2026, 2:50 p.m.

7.5

CVSS3.1

CVE-2026-33292 - AVideo has Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Private/Paid Vi…

WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal attack that allows an unauthenticated attacker to stream any private or paid video on the platform. The `videoDirectory` GET parameter is used in two di…

πŸ“… Published: March 22, 2026, 4:26 p.m. πŸ”„ Last Modified: March 25, 2026, 2:50 p.m.

8.7

CVSS4.0

CVE-2026-4553 - Tenda F453 Parameters Natlimit fromNatlimit stack-based overflow

A vulnerability was identified in Tenda F453 1.0.0.3. Impacted is the function fromNatlimit of the file /goform/Natlimit of the component Parameters Handler. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is pu…

πŸ“… Published: March 22, 2026, 3:24 p.m. πŸ”„ Last Modified: April 3, 2026, 9:39 a.m.

8.7

CVSS4.0

CVE-2026-4552 - Tenda F453 Parameters VirtualSer fromVirtualSer memory corruption

A vulnerability was determined in Tenda F453 1.0.0.3. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component Parameters Handler. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. Th…

πŸ“… Published: March 22, 2026, 2:31 p.m. πŸ”„ Last Modified: April 3, 2026, 9:39 a.m.

8.7

CVSS4.0

CVE-2026-4551 - Tenda F453 Parameters SafeClientFilter fromSafeClientFilter memory corruption

A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeClientFilter of the component Parameters Handler. Performing a manipulation of the argument menufacturer/Go results in stack-based buffer overflow. The attack is pos…

πŸ“… Published: March 22, 2026, 2:31 p.m. πŸ”„ Last Modified: April 3, 2026, 9:39 a.m.

5.1

CVSS4.0

CVE-2026-4550 - code-projects Simple Gym Management System func.php sql injection

A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the publi…

πŸ“… Published: March 22, 2026, 1:47 p.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.
Total resulsts: 349182
Page 981 of 34,919
Β« previous page Β» next page
Filters