Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-43877 — WWBN AVideo: CSRF in userSavePhoto.php Allows Cross-Origin Overwrite of Any Logged-in Use…

WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/userSavePhoto.php is a legacy profile-photo endpoint that accepts a base64 POST parameter and writes the de…

avideo | Remote | Cross-Site Request Forgery
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.4 MEDIUM
CVE-2026-43876 — WWBN AVideo: HTML Injection in notifySubscribers.json.php Enables Platform-Branded Phishi…

WWBN AVideo is an open source video platform. In versions up to and including 29.0, objects/notifySubscribers.json.php takes the raw message POST parameter and passes it into sendSiteEmail(), which s…

avideo | Remote | Cross-Site Scripting
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.8 MEDIUM
CVE-2026-43875 — WWBN AVideo: Password Hash Leaked in MobileManager OAuth Redirect URL Enables Account Tak…

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/MobileManager/oauth2.php completes an OAuth login by sending an HTTP 302 Location: oauth2Success.php?user=<e…

avideo | Remote | Authentication
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-43873 — WWBN AVideo: Unauthenticated Disclosure of CloneSite `myKey` via Error Echo in `cloneClie…

WWBN AVideo is an open source video platform. In versions up to and including 29.0, plugin/CloneSite/cloneClient.json.php echoes the local CloneSite shared secret ($objClone->myKey, a constant md5($g…

avideo | Remote | Information Disclosure
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.9 MEDIUM
CVE-2026-42600 — MinIO: Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint

MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-R…

minio | Remote | Path Traversal
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.2 HIGH
CVE-2026-42564 — jotty·page: Unauthenticated Path Traversal leads to sensitive file disclosure and session…

jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-icons/[filename]. The filename route parameter is jo…

Remote | Path Traversal
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
2.4 LOW
CVE-2026-42188 — Geyser: Server-Side Request Forgery (SSRF) via Player Head Texture URL

Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request forgery (SSRF) vulnerability exists in Geyser’s handling of Bedrock player hea…

geyser | Remote | Server-Side Request Forgery
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
7.8 HIGH
CVE-2026-42046 — libcaca: Heap OOB write in canvas import functions caused by int overflow

libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows an attacker to cause a controlled heap out-of-boun…

libcaca | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-34961 — barebox ext4 Extent Parsing Out-of-Bounds Read

barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in fs/ext4/ext4_common.…

| Memory Corruption
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
6.5 MEDIUM
CVE-2026-34960 — barebox Out-of-Bounds Read in DHCP Option Parsing

barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options pointer remains within …

| Memory Corruption
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
7.2 HIGH
CVE-2026-43874 — WWBN AVideo: Incomplete Fix for YPTSocket autoEvalCodeOnHTML Strip: Unauthenticated Cross…

WWBN AVideo is an open source video platform. In versions up to and including 29.0, the server-side mitigation for the YPTSocket autoEvalCodeOnHTML eval sink (from CVE-2026-40911) only strips the pay…

avideo | Remote | Cross-Site Scripting
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-43668 — Apple iOS/PadOS/TVOS/WatchOS/macOS Use-After-Free Vulnerability

A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS T…

macos iphone_os tvos watchos ipados visionos | Remote | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-43666 — Apple iOS/PadOS/ macOS/tvOS/watchOS VisionOS Out-of-Bounds Write Denial-of-Service

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, mac…

macos iphone_os tvos watchos ipados visionos | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-43661 — Apple iOS/PadOS/TVOS/WatchOS Buffer Overflow Vulnerability

A buffer overflow issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. Processing a maliciously crafted image…

macos iphone_os tvos watchos ipados | Remote | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-43660 — Apple iOS/ iPadOS/ macOS/ tvOS/ visionOS/ watchOS CSP Validation Bypass

A validation issue was addressed with improved logic. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processi…

macos iphone_os tvos watchos ipados visionos | Remote | Misconfiguration
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
4.7 MEDIUM
CVE-2026-43659 — Apple iOS/ iPadOS/ macOS visionOS Sensitive User Data Access Race Condition

A race condition was addressed with additional validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, …

macos iphone_os ipados visionos | Race Condition
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-43658 — Apple Safari Web Content Crash Vulnerability

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously crafted web co…

macos iphone_os tvos watchos ipados visionos | Remote | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.3 HIGH
CVE-2026-43656 — Apple iOS/iPadOS/macOS Out-of-Bounds Write Vulnerability

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, ma…

macos iphone_os ipados | Remote | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.3 HIGH
CVE-2026-43655 — Apple iOS/WatchOS/TVOS/OS Out-of-Bounds Read Vulnerability

An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, watchOS 26.5. An app may be able to cause unexpected s…

macos iphone_os tvos watchos ipados | Remote | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
0.0 NA
CVE-2026-43654 — Apple iOS Kernel Memory Disclosure Vulnerability

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5, tvOS…

macos iphone_os tvos watchos ipados visionos | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
Showing 20 of 6269 Results