Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-56347 — AVideo TopMenu Plugin - Stored Cross-Site Scripting via Unescaped Menu Item Fields

AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encoding of icon classes, URLs, and text labels. Attackers…

avideo | Remote | Cross-Site Scripting
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.9 MEDIUM
CVE-2026-56346 — AVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint

AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated users to decrypt PGP messages. Remote attackers can sub…

Remote | Authentication
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
9.2 CRITICAL
CVE-2026-56345 — AVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint

AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verif…

Remote | Authorization
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.8 MEDIUM
CVE-2026-56342 — AVideo - Server-Side Request Forgery in Live/test.php via statsURL Parameter

AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators to read arbitrary URLs via the statsURL parameter, wh…

Remote | Server-Side Request Forgery
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
8.7 HIGH
CVE-2026-56341 — AVideo - Unauthenticated Access to Payment Log DataTables Endpoints via list.json.php

AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin tran…

Remote | Authorization
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
8.8 HIGH
CVE-2026-56340 — vLLM - Denial of Service via Unvalidated Multimodal Embeddings

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tensor invariant checks by default, an attacker can subm…

Remote | Denial of Service
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
5.3 MEDIUM
CVE-2025-71379 — vllm - Regular Expression Denial of Service in Multiple Components

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/lora/utils.py, the phi4mini tool parser, and the Ope…

Remote | Denial of Service
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
0.0 NA
CVE-2026-5366 — Git Argument Injection in prefecthq/prefect

Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. The `commit_sha` parameter, which is passed to gi…

| Injection
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
5.1 MEDIUM
CVE-2026-56332 — Capgo - Open Redirect via confirmation_url Parameter

Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to redirect users to arbitrary external websites. The confirmation_url parameter is …

Remote | Misconfiguration
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
4.8 MEDIUM
CVE-2026-56330 — Capgo - Open Redirect via Unvalidated Stripe Billing URLs

Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept unvalidated callbackUrl, successUrl, and cancelUrl parameters. Authenticated a…

Remote | Misconfiguration
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
5.3 MEDIUM
CVE-2026-56319 — Capgo - App Existence Oracle via GET /statistics/app/:app_id

Capgo before 12.128.2 contains an information disclosure vulnerability in the GET /statistics/app/:app_id endpoint that allows app-limited API keys to distinguish existing sibling app IDs through dif…

Remote | Information Disclosure
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
5.3 MEDIUM
CVE-2026-56307 — Cap-go - Broken Cursor Pagination in /private/devices Endpoint

Cap-go before 12.128.12 contains a broken cursor pagination vulnerability in the /private/devices endpoint on the Cloudflare/workerd path that allows authenticated attackers to cause duplicate-page l…

Remote | Denial of Service
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.9 MEDIUM
CVE-2026-56304 — picklescan - Arbitrary File Creation via logging.FileHandler Deserialization

picklescan before 1.0.1 contains an unsafe pickle deserialization vulnerability allowing unauthenticated attackers to create arbitrary zero-byte files via logging.FileHandler class instantiation. Att…

Remote | Misconfiguration
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.3 MEDIUM
CVE-2026-56295 — Capgo - Policy Enforcement Bypass in Webhook Management Endpoints via Non-Expiring API Ke…

Capgo before 12.128.2 contains an authorization bypass vulnerability in webhook management endpoints that allows non-expiring API keys to bypass the require_apikey_expiration organization policy. The…

Remote | Authorization
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
4.8 MEDIUM
CVE-2026-56294 — capacitor-native-biometric - Authentication Bypass via Unvalidated CryptoObject in onAuth…

capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSucceeded() method fails to validate CryptoObject parameters. Attackers can hook t…

| Authentication
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.9 MEDIUM
CVE-2026-56282 — Capgo - Information Disclosure via Unauthenticated /replication Endpoint

Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /replication endpoint that exposes internal PostgreSQL replication telemetry including slot names and WAL…

Remote | Information Disclosure
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.0 MEDIUM
CVE-2026-56276 — Flowise - Mass Assignment in PUT /api/v1/user Allows Password Hash Override

Flowise before 3.1.2 contains a mass assignment vulnerability in the PUT /api/v1/user endpoint that allows authenticated users to directly modify the credential field without validation. Attackers ca…

Remote | Authentication
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.9 MEDIUM
CVE-2026-56267 — Flowise - PII Disclosure via Unauthenticated Forgot Password Endpoint

Flowise before 3.0.13 contains an information exposure vulnerability in the POST /api/v1/account/forgot-password endpoint that returns full user objects including PII to unauthenticated attackers. An…

Remote | Information Disclosure
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.9 MEDIUM
CVE-2026-56235 — Capgo - Unauthenticated Cross-Tenant Metrics Disclosure via RPC Functions

Cap-go capgo before 12.128.2 contains an authorization bypass in several Supabase PostgREST RPC functions (get_app_metrics, get_global_metrics, get_total_metrics) that are granted to the anon role wi…

Remote | Authorization
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.9 MEDIUM
CVE-2026-56228 — Capgo - Denial of Service via Improper Password Policy Length Validation

Capgo before 12.128.2 fails to enforce a maximum value on the minimum password length field in its password policy configuration. An authenticated organization administrator can set an extremely larg…

Remote | Authentication
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
Showing 20 of 7489 Results