Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.3 LOW
CVE-2026-11765 — Argument Injection in TUBITAK BILGEM's Pardus Pen

Improper neutralization of argument delimiters in a command ('argument injection') vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus Pen allows Argument Injection. This…

| Injection
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.8 CRITICAL
CVE-2026-84390 — Fortinet FortiMonitorOnSight Information Exposure Vulnerability

A inclusion of sensitive information in source code vulnerability in Fortinet FortiMonitorOnSight 7.2.4 through 7.2.7, FortiMonitorOnSight 7.2.0 through 7.2.2 may allow attacker to improper access co…

fortimonitoronsight | Remote | Information Disclosure
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
10.0 CRITICAL
CVE-2026-80462 — Privilege Escalation in Progress Chef Automate

A vulnerability in the Chef Automate API gateway and identity validation path may allow an unauthenticated actor to gain elevated access to protected Chef Automate functionality under specific condit…

Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.8 CRITICAL
CVE-2026-89259 — Hugo before v0.165.0 Insufficient Permission Restriction via TailwindCSS

Hugo is a static site generator. From v0.161.0, Hugo executes Node tools under Node's permission model, but TailwindCSS — included in the default security.exec.allow list — requires a highly permissi…

hugo | Remote | Misconfiguration
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.3 CRITICAL
CVE-2026-89258 — Hugo before v0.165.0 Symlink Confinement Bypass via resources.Get

Hugo is a static site generator. In versions after v0.123.0 and before v0.165.0, symlinks in parent directories were not dropped during direct resource lookups, allowing path confinement to be bypass…

hugo | Remote | Path Traversal
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.4 MEDIUM
CVE-2026-89257 — AVideo through 29.0 Cross-User Category Asset Deletion via Missing Ownership Check

AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php. The endpoint validates only the Category::canCreateCategory() capabilit…

avideo | Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.3 CRITICAL
CVE-2026-89256 — AVideo Bookmark Plugin Stored XSS via Chapter Names

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenate…

avideo | Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.3 CRITICAL
CVE-2026-89255 — AVideo LoginControl Stored XSS via PGP Public Key

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a …

avideo | Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.3 CRITICAL
CVE-2026-89254 — AVideo CustomizeUser Stored XSS via field_name Parameter

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sa…

avideo | Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.3 CRITICAL
CVE-2026-89253 — AVideo Stored XSS via donationLink in watch page button

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/use…

avideo | Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.1 HIGH
CVE-2026-89252 — AVideo Missing Authorization in addLiveLink.php LiveLink Update

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canSt…

avideo | Remote | Authorization
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.1 HIGH
CVE-2026-89251 — AVideo Missing Authorization via AD_Server log.php Wallet Credit

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unv…

avideo | Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
8.7 HIGH
CVE-2026-89250 — WWBN AVideo Unauthenticated File Read via getRecordedFile.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the te…

avideo | Remote | Information Disclosure
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.3 CRITICAL
CVE-2026-89249 — AVideo YPTWallet Stored XSS via CryptoWallet Configuration

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded …

avideo | Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.9 MEDIUM
CVE-2026-89248 — AVideo WebRTC Plugin Information Disclosure via status.json.php

AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticate…

avideo | Remote | Authentication
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.1 MEDIUM
CVE-2026-89247 — WWBN AVideo XML Injection via plugin/AD_Server/VMAP.php

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_…

avideo | Remote | Injection
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
5.4 MEDIUM
CVE-2026-89246 — WWBN AVideo CSV Formula Injection via myComments.download.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in the myComments.download.php endpoint that fails to sanitize spreadsheet formula p…

avideo | Remote | Injection
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
7.1 HIGH
CVE-2026-89245 — WWBN AVideo Cross-Site Request Forgery via playlistRemove.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSR…

avideo | Remote | Cross-Site Request Forgery
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
6.1 MEDIUM
CVE-2026-89244 — WWBN AVideo Reflected XSS via Gallery Category getBackURL

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Gallery/view/Category.php when SubCategorys is enabled. The getBa…

avideo | Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
9.2 CRITICAL
CVE-2026-89243 — WWBN AVideo Stored XSS via UserGroups setGroup_name

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Admini…

avideo | Remote | Cross-Site Scripting
Sep 11, 2026 Sep 11, 2026
Sep 11, 2026
Sep 11, 2026
Showing 20 of 13372 Results