Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-90559 — snappy-java through 1.1.10.8 Out-of-Bounds Write via uncompress

snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerability in Snappy.uncompress(ByteBuffer, ByteBuffer) because destination buffer capacity is never validated against decompressed siz…

snappy-java | Remote | Memory Corruption
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
9.8 CRITICAL
CVE-2026-90558 — sngrep through 1.8.4 Stack Buffer Overflow via SIP Headers

sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in SIP attribute formatting routines when header values exceed the 255-byte buffer limit. Attackers can craft malicious SIP packets…

sngrep | Remote | Memory Corruption
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90557 — Freeciv 3.1.0 through 3.2.5 Out-of-Bounds Read via Savegame

Freeciv versions 3.1.0 through 3.2.5 contain an out-of-bounds read vulnerability in sg_load_player_unit() when processing savegame files with invalid unit activity indices. An attacker can craft a ma…

freeciv | Memory Corruption
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.5 HIGH
CVE-2026-90556 — Freeciv before 3.2.6 Heap Buffer Overflow via worklist_load

Freeciv versions before 3.2.6 contain a heap buffer overflow in worklist_load() when processing savegame files with declared worklist lengths exceeding the fixed array bound of 64 elements. Attackers…

freeciv | Memory Corruption
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
7.1 HIGH
CVE-2026-90555 — vLLM before 0.28.0 Denial of Service via Audio Header

vLLM versions before 0.28.0 fail to validate audio sample rate headers in the transcription endpoint, allowing authenticated clients to bypass duration checks. Attackers can submit forged FLAC header…

vllm vllm | Remote | Denial of Service
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90554 — vLLM before 0.28.0 Denial of Service via audio extraction

vLLM versions >=0.10.2 and <0.28.0 do not apply any audio decode-size or duration limit when extracting audio from video input for NanoNemotronVL models. In nano_nemotron_vl.py, _extract_audio_from_v…

vllm vllm | Denial of Service
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
8.5 HIGH
CVE-2026-90553 — vLLM before 0.28.0 Remote Code Execution via LlavaOnevision2 processor

vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores the trust_remote_code parameter when loading remote processor classes. Attackers…

vllm vllm | Supply Chain
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-90552 — WWBN AVideo Missing Authorization via Playlists_schedules list.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authen…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90551 — WWBN AVideo Missing Authorization via video_from_program API

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist co…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90550 — WWBN AVideo Missing Authorization via mediaSession.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticate…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90549 — WWBN AVideo Missing Authorization via videosAndroid.json.php Endpoint

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protect…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90548 — WWBN AVideo Missing Authorization in ImageGallery list.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery file…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90547 — WWBN AVideo Missing Authorization via getBookmarks.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to rea…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-90546 — WWBN AVideo Missing Authorization via like.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-prot…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-90545 — WWBN AVideo Missing Authorization via commentAddNew.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-90544 — WWBN AVideo Missing Authorization via videoAddViewCount.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticate…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90543 — WWBN AVideo Missing Authentication via socketMessageLiveOwner.json.php

WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.ph…

avideo | Remote | Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.4 MEDIUM
CVE-2026-90542 — WWBN AVideo Missing Authorization via remindMe.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated att…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
6.9 MEDIUM
CVE-2026-90541 — WWBN AVideo Unauthenticated Information Disclosure via menus.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all m…

avideo | Remote | Authentication
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
5.3 MEDIUM
CVE-2026-90540 — WWBN AVideo Missing Authorization via playListAddVideo.json.php

WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists. Authenticated attack…

avideo | Remote | Authorization
Sep 12, 2026 Sep 12, 2026
Sep 12, 2026
Sep 12, 2026
Showing 20 of 13182 Results