Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 HIGH
CVE-2026-4558 — Linksys MR9600 SmartConnect.lua smartConnectConfigure os command injection

A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configApPassph…

Remote | Injection
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
5.3 MEDIUM
CVE-2026-4557 — code-projects Exam Form Submission update_s1.php cross site scripting

A vulnerability was detected in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /admin/update_s1.php. Performing a manipulation of the argument sname results in c…

Remote | Cross-Site Scripting
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
9.0 HIGH
CVE-2026-4555 — D-Link DIR-513 boa formEasySetTimezone memory corruption

A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component boa. This manipulation of the …

dir-513_firmware | Remote | Memory Corruption
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.5 MEDIUM
CVE-2026-4554 — Tenda F453 WriteFacMac FormWriteFacMac privilege escalation

A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac results in comman…

f453_firmware | Remote | Injection
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
5.9 MEDIUM
CVE-2026-33319 — AVideo Vulnerable to OS Command Injection via Unescaped URL in LinkedIn Video Upload Shel…

WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin constructs a shell command by directly interpolating an up…

avideo | Remote | Injection
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
2.1 LOW
CVE-2026-33296 — AVideo has an Open Redirect via Unvalidated redirectUri in userLogin.php

WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a user-supplied redirectUri parameter is reflected dir…

avideo | Remote | Misconfiguration
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
8.2 HIGH
CVE-2026-33295 — AVideo Vulnerable to Stored XSS via Unescaped Video Title in CDN downloadButtons.php

WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plugin's download buttons component. The `clean_title`…

avideo | Remote | Cross-Site Scripting
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
5.0 MEDIUM
CVE-2026-33294 — AVideo has SSRF in BulkEmbed Thumbnail Fetch that Allows Reading Internal Network Resourc…

WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkEmbed/save.json.php`) fetches user-supplied thumbnail URLs via `url_get_contents…

avideo | Remote | Server-Side Request Forgery
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
8.1 HIGH
CVE-2026-33293 — AVideo Affected by Arbitrary File Deletion via Path Traversal in CloneSite deleteDump Par…

WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed directly to `unlink()` without any path sanitizati…

avideo | Remote | Path Traversal
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
7.5 HIGH
CVE-2026-33292 — AVideo has Authorization Bypass via Path Traversal in HLS Endpoint Allows Streaming Priva…

WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal attack that allows an unauthenticated attacker to st…

avideo | Remote | Path Traversal
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
9.0 HIGH
CVE-2026-4553 — Tenda F453 Parameters Natlimit fromNatlimit stack-based overflow

A vulnerability was identified in Tenda F453 1.0.0.3. Impacted is the function fromNatlimit of the file /goform/Natlimit of the component Parameters Handler. The manipulation of the argument page lea…

f453_firmware | Remote | Memory Corruption
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
9.0 HIGH
CVE-2026-4552 — Tenda F453 Parameters VirtualSer fromVirtualSer memory corruption

A vulnerability was determined in Tenda F453 1.0.0.3. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component Parameters Handler. Executing a manipulation of th…

f453_firmware | Remote | Memory Corruption
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
9.0 HIGH
CVE-2026-4551 — Tenda F453 Parameters SafeClientFilter fromSafeClientFilter memory corruption

A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeClientFilter of the component Parameters Handler. Performing a ma…

f453_firmware | Remote | Memory Corruption
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
5.8 MEDIUM
CVE-2026-4550 — code-projects Simple Gym Management System func.php sql injection

A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname lead…

Remote | Injection
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
3.1 LOW
CVE-2026-4549 — mickasmt next-saas-stripe-starter Stripe API open-customer-portal.ts openCustomerPortal a…

A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. Th…

Remote | Authorization
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.5 MEDIUM
CVE-2026-4548 — mickasmt next-saas-stripe-starter update-user-role.ts updateUserrole improper authorizati…

A vulnerability was detected in mickasmt next-saas-stripe-starter 1.0.0. Affected by this vulnerability is the function updateUserrole of the file actions/update-user-role.ts. The manipulation of the…

Remote | Authorization
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
5.3 MEDIUM
CVE-2026-4547 — mickasmt next-saas-stripe-starter Checkout generate-user-stripe.ts generateUserStripe log…

A security vulnerability has been detected in mickasmt next-saas-stripe-starter 1.0.0. Affected is the function generateUserStripe of the file actions/generate-user-stripe.ts of the component Checkou…

Remote
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
7.3 HIGH
CVE-2026-4546 — Flos Freeware Notepad2 TextShaping.dll uncontrolled search path

A weakness has been identified in Flos Freeware Notepad2 4.2.25. This impacts an unknown function in the library TextShaping.dll. Executing a manipulation can lead to uncontrolled search path. The at…

| Path Traversal
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
8.4 HIGH
CVE-2019-25619 — FTP Shell Server 6.83 Buffer Overflow via Account Name

FTP Shell Server 6.83 contains a buffer overflow vulnerability in the 'Account name to ban' field that allows local attackers to execute arbitrary code by supplying a crafted string. Attackers can in…

| Memory Corruption
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
6.2 MEDIUM
CVE-2019-25618 — AdminExpress 1.2.5 Denial of Service via System Compare

AdminExpress 1.2.5 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the System Compare feature. Attackers can past…

| Denial of Service
Mar 22, 2026 Mar 22, 2026
Mar 22, 2026
Mar 22, 2026
Showing 20 of 5246 Results