Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-4589 — kalcaddle kodbox fileGet Endpoint editor.class.php PathDriverUrl server-side request forg…

A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the componen…

kodbox | Remote | Server-Side Request Forgery
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
6.1 MEDIUM
CVE-2026-3635 — Fastify request.protocol and request.host spoofable via X-Forwarded-Proto/Host from untru…

Summary When trustProxy is configured with a restrictive trust function (e.g., a specific IP like trustProxy: '10.0.0.1', a subnet, a hop count, or a custom function), the request.protocol and reques…

fastify | Misconfiguration
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
9.8 CRITICAL
CVE-2026-33352 — AVideo has an Unauthenticated SQL Injection via `doNotShowCats` Parameter (Backslash Esca…

WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` in the `getAllCategories()` method. The `doNotShow…

avideo | Remote | Injection
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
9.1 CRITICAL
CVE-2026-33351 — AVideo has Unauthenticated SSRF via `webSiteRootURL` Parameter in saveDVR.json.php, Chain…

WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standAloneFiles/saveDVR.json.php`. When the AVideo Live …

avideo | Remote | Server-Side Request Forgery
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
9.1 CRITICAL
CVE-2026-33297 — AVideo has an IDOR - Any Admin Can Set Another User's Channel Password via setPassword.js…

WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administrators to set a channel password for any user. Due …

avideo | Remote | Authentication
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
9.3 CRITICAL
CVE-2025-41008 — SQL Injection in Sinturno

SQL injection vulnerability in Sinturno. This vulnerability allows an attacker to retrieve, create, update, and delete databases through the 'client' parameter in the '/_adm/scripts/modalReport_data.…

Remote | Injection
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
6.9 MEDIUM
CVE-2019-25625 — Blob Studio 2.17 Denial of Service via Malformed Input

Blob Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a t…

blob_studio | Denial of Service
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
6.9 MEDIUM
CVE-2019-25624 — Liquid Studio 2.17 Denial of Service via Malformed Input

Liquid Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger t…

liquid_studio | Denial of Service
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
6.9 MEDIUM
CVE-2019-25623 — Luminance Studio 2.17 Denial of Service via Malformed Input

Luminance Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can create…

luminance_studio | Denial of Service
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
6.9 MEDIUM
CVE-2019-25622 — Paint Studio 2.17 Denial of Service via Malformed Input

Paint Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the key entry mechanism. Attackers can create a …

paint_studio | Denial of Service
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
6.9 MEDIUM
CVE-2019-25621 — Pixel Studio 2.17 Denial of Service via Malformed Input

Pixel Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger th…

pixel_studio | Denial of Service
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
6.9 MEDIUM
CVE-2019-25620 — Tree Studio 2.17 Denial of Service via Malformed Input

Tree Studio 2.17 contains a denial of service vulnerability that allows local attackers to crash the application by providing malformed input through the keyboard interface. Attackers can trigger the…

tree_studio | Denial of Service
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
6.3 MEDIUM
CVE-2026-4588 — kalcaddle kodbox Site-level API key shareOut.class.php shareSafeGroup hard-coded key

A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/source-code/app/controller/explorer/shareOut.class.php of the component Site-le…

kodbox | Remote | Cryptography
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
6.3 MEDIUM
CVE-2026-4587 — HybridAuth SSL Curl.php certificate validation

A vulnerability was found in HybridAuth up to 3.12.2. This issue affects some unknown processing of the file src/HttpClient/Curl.php of the component SSL Handler. The manipulation of the argument cur…

Remote | Misconfiguration
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
6.5 MEDIUM
CVE-2026-4586 — CodePhiliaX Chat2DB JDBC Driver Upload JdbcDriverController.java upload unrestricted uplo…

A vulnerability was found in CodePhiliaX Chat2DB up to 0.3.7. This affects the function Upload of the file chat2db-server/chat2db-server-web/chat2db-server-web-api/src/main/java/ai/chat2db/server/web…

Remote | Misconfiguration
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
7.7 HIGH
CVE-2026-31851 — Lack of rate limiting allows brute-force attacks in Nexxt Nebula 300+

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement rate limiting or account lockout on the authentication interface.

| Authentication
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
6.8 MEDIUM
CVE-2026-31850 — Plaintext storage of credentials in configuration backup in Nexxt Nebula 300+

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores sensitive information, including administrative credentials and WiFi pre-shared keys, in plaintext within exported configuratio…

| Information Disclosure
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
7.2 HIGH
CVE-2026-31849 — Missing CSRF protection on state-changing endpoints in Nexxt Nebula 300+

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 does not implement CSRF protections on state-changing administrative endpoints. A remote attacker can induce an authenticated administ…

Remote | Cross-Site Request Forgery
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
8.7 HIGH
CVE-2026-31848 — Reversible ecos_pw cookie allows administrative authentication in Nexxt Nebula 300+

Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 stores administrative authentication material in the ecos_pw cookie using a reversible Base64-encoded format with a static suffix. An …

| Authentication
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
8.5 HIGH
CVE-2026-31847 — Hidden functionality allows remote Telnet enablement in Nexxt Nebula 300+

Hidden functionality in the /goform/setSysTools endpoint in Nexxt Solutions Nebula 300+ firmware through version 12.01.01.37 allows remote enablement of a Telnet service. Once enabled, the service ex…

| Misconfiguration
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
Showing 20 of 5706 Results