Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-84483 — WWBN AVideo Unauthenticated Password Hash Oracle via encryptPass.json.php

WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL a…

avideo | Remote | Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.8 HIGH
CVE-2026-84482 — WWBN AVideo Cross-Site Request Forgery via get_domain() validation

WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can …

avideo | Remote | Cross-Site Request Forgery
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
6.9 MEDIUM
CVE-2026-84481 — WWBN AVideo through 30.0 Information Disclosure via MobileManager

WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. …

avideo | Remote | Information Disclosure
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-84480 — WWBN AVideo Password Recovery Token Expiration Bypass

WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtai…

avideo | Remote | Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.3 CRITICAL
CVE-2026-84479 — WWBN AVideo Authentication Bypass via User-Agent Header

WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTT…

avideo | Remote | Authentication
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.3 HIGH
CVE-2026-84478 — WWBN AVideo Unauthenticated Arbitrary Log File Deletion

WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequen…

avideo | Remote | Path Traversal
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.4 MEDIUM
CVE-2026-84477 — AVideo Stored XSS via Live Schedule Title Description

AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access…

avideo | Remote | Cross-Site Scripting
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.7 HIGH
CVE-2026-84476 — WWBN AVideo Authentication Bypass via X-Real-IP Header

WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate t…

avideo | Remote | Misconfiguration
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
8.7 HIGH
CVE-2026-84208 — AVideo User_Location Plugin Unauthenticated SQL Injection

AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters…

avideo | Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-84642 — Allowed UNC hostnames for attachments interpreted as a regular expression

The values of the mail.allowed_attachment_hostnames advanced config setting were used in a regular expression without escaping. For some possible valid hostnames, this could allow certain unintended …

thunderbird | Misconfiguration
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-84641 — Information disclosure due to malicious IMAP server response

A malicious IMAP server can trigger use-after-free and heap-memory disclosure by sending a crafted ID response. Heap contents can ultimately be persisted to prefs.js. This vulnerability was fixed in …

thunderbird | Memory Corruption
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-84640 — One byte overflow read in mail parser

A maliciously constructed mail header could lead to a one byte read past the end of a buffer. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

thunderbird | Memory Corruption
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-84639 — Uninitialized memory in MIME parsing

Triggering an error condition in certain MIME bodies would cause uninitialized memory to be used. This vulnerability was fixed in Thunderbird 155, Thunderbird 140.15, and Thunderbird 153.2.

thunderbird | Memory Corruption
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
0.0 NA
CVE-2026-84637 — Calendar invitation attachments could launch local executables

Malicious calendar invitations could use file URI attachments to launch local or network-hosted executables on Windows, bypassing Thunderbird's normal executable attachment protections. With the new …

thunderbird | Misconfiguration
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.5 HIGH
CVE-2026-84375 — js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources

js-yaml is a JavaScript YAML parser and dumper. From 3.0.0 until 3.15.2 and 4.3.2, maxTotalMergeKeys in lib/js-yaml/loader.js and lib/loader.js does not count empty mapping sources while processing t…

js-yaml | Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
7.5 HIGH
CVE-2026-84374 — Laravel Excel writes exports outside the configured filesystem disk when given a caller-c…

Laravel Excel provides supercharged Excel exports and imports in Laravel. From 3.1.8 until 3.1.70, in src/Files/Disk.php the Maatwebsite\Excel\Files\Disk::copy() method resolves the caller-controlled…

Remote | Path Traversal
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
5.9 MEDIUM
CVE-2026-84373 — Vitest: Path Traversal / Arbitrary File Read via @vitest/mocker Redirect Mock

Vitest is a testing framework powered by Vite. From 2.1.0 until 4.1.11 and 5.0.0-rc.2, the public mockerPlugin and standalone interceptorPlugin exports in packages/mocker/src/node/interceptorPlugin.t…

Remote | Path Traversal
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
9.8 CRITICAL
CVE-2026-84372 — Predis: Redis command injection and denial of service via CRLF smuggling in pipelined com…

Predis is a flexible and feature-complete Redis and Valkey client for PHP. From version 3.0.0-RC1 until version 3.3.0, pipeline handling on aggregate cluster and replication connections reparses an a…

Remote | Injection
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
4.3 MEDIUM
CVE-2026-84289 — NousResearch hermes-agent MCP Tool mcp_tool.py list_tools memory allocation

A vulnerability was found in NousResearch hermes-agent up to 0.18.2. This vulnerability affects the function list_tools of the file tools/mcp_tool.py of the component MCP Tool. Performing a manipulat…

hermes-agent | Remote | Memory Corruption
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
4.3 MEDIUM
CVE-2026-84288 — NousResearch hermes-agent ACP Prompt Workflow session.py HermesACPAgent.prompt denial of …

A vulnerability has been found in NousResearch hermes-agent up to 0.18.2. This affects the function HermesACPAgent.prompt of the file acp_adapter/session.py of the component ACP Prompt Workflow. Such…

hermes-agent | Remote | Denial of Service
Sep 01, 2026 Sep 01, 2026
Sep 01, 2026
Sep 01, 2026
Showing 20 of 12531 Results