Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-4963 — huggingface smolagents Incomplete Fix CVE-2025-9959 local_python_executor.py evaluate_wit…

A weakness has been identified in huggingface smolagents 1.25.0.dev0. This affects the function evaluate_augassign/evaluate_call/evaluate_with of the file src/smolagents/local_python_executor.py of t…

Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.3 HIGH
CVE-2026-4962 — UltraVNC Service version.dll uncontrolled search path

A security flaw has been discovered in UltraVNC up to 1.6.4.0. Affected by this issue is some unknown functionality in the library version.dll of the component Service. The manipulation results in un…

| Path Traversal
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
9.0 HIGH
CVE-2026-4961 — Tenda AC6 POST Request QuickIndex formQuickIndex stack-based overflow

A vulnerability was identified in Tenda AC6 15.03.05.16. Affected by this vulnerability is the function formQuickIndex of the file /goform/QuickIndex of the component POST Request Handler. The manipu…

ac6_firmware | Remote | Memory Corruption
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
9.0 HIGH
CVE-2026-4960 — Tenda AC6 POST Request WizardHandle fromWizardHandle stack-based overflow

A vulnerability was determined in Tenda AC6 15.03.05.16. Affected is the function fromWizardHandle of the file /goform/WizardHandle of the component POST Request Handler. Executing a manipulation of …

ac6_firmware | Remote | Memory Corruption
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.9 MEDIUM
CVE-2026-34411 — Appsmith < 1.98 Unauthenticated Instance Configuration Disclosure via Management APIs

Appsmith versions prior to 1.98 expose sensitive instance management API endpoints without authentication. Unauthenticated attackers can query endpoints like /api/v1/consolidated-api/view and /api/v1…

appsmith | Remote | Authentication
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.4 MEDIUM
CVE-2026-34362 — AVideo's WebSocket Token Never Expires Due to Commented-Out Timeout Validation in verifyT…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented o…

avideo | Remote | Authentication
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.4 MEDIUM
CVE-2026-34247 — AVideo's IDOR in uploadPoster.php Allows Any Authenticated User to Overwrite Scheduled Li…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` endpoint allows any authenticated user to overwrite the poster image for any sch…

avideo | Remote | Authorization
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.3 MEDIUM
CVE-2026-34245 — AVideo's Missing Authorization in Playlist Schedule Creation Allows Cross-User Broadcast …

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endpoint allows any authenticated user with streaming …

avideo | Remote | Authorization
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
9.1 CRITICAL
CVE-2026-33867 — AVideo has Plaintext Video Password Storage

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in…

avideo | Remote | Cryptography
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.1 HIGH
CVE-2026-33770 — AVideo has SQL Injection in category.php fixCleanTitle() via Unparameterized clean_title …

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method in `objects/category.php` constructs a SQL SELECT query by directly interpolati…

avideo | Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.1 HIGH
CVE-2026-33767 — AVideo has SQL Injection via Partial Prepared Statement — videos_id Concatenated Directly…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike()` method constructs a SQL query using a prepared statement placeholder (`?`) f…

avideo | Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.5 HIGH
CVE-2026-30576 — SourceCodester Pharmacy Product Management System Business Logic Injection

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to validate the "txtprice" and "txttotalcost" parameter…

Remote | Misconfiguration
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.5 HIGH
CVE-2026-30575 — SourceCodester Pharmacy Product Management System Business Logic Injection

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-stock.php file. The application fails to validate the "txtqty" parameter during stock entry, …

Remote | Misconfiguration
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.5 HIGH
CVE-2026-30574 — SourceCodester Pharmacy Product Management System Business Logic Vulnerability

A Business Logic vulnerability exists in SourceCodester Pharmacy Product Management System 1.0 in the add-sales.php file. The application fails to verify if the requested sales quantity (txtqty) exce…

Remote | Authorization
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
0.0 NA
CVE-2026-30571 — SourceCodester Inventory System Reflected Cross-Site Scripting Vulnerability

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Inventory System 1.0 in the view_category.php file via the "limit" parameter. The application fails to sanitize the input…

| Cross-Site Scripting
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
0.0 NA
CVE-2026-30570 — SourceCodester Inventory System Reflected Cross-Site Scripting (XSS)

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Inventory System 1.0 in the view_sales.php file via the "limit" parameter. The application fails to sanitize the input, a…

| Cross-Site Scripting
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
0.0 NA
CVE-2026-30569 — SourceCodester Inventory System Reflected Cross-Site Scripting (XSS)

A Reflected Cross-Site Scripting (XSS) vulnerability exists in SourceCodester Inventory System 1.0. The vulnerability is located in the view_stock_availability.php file via the "limit" parameter. The…

| Cross-Site Scripting
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
8.7 HIGH
CVE-2026-28369 — Undertow: undertow: request smuggling via malformed http request headers

A flaw was found in Undertow. When Undertow receives an HTTP request where the first header line starts with one or more spaces, it incorrectly processes the request by stripping these leading spaces…

Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
8.7 HIGH
CVE-2026-28368 — Undertow: undertow: request smuggling via inconsistent header parsing

A flaw was found in Undertow. This vulnerability allows a remote attacker to construct specially crafted requests where header names are parsed differently by Undertow compared to upstream proxies. T…

Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
8.7 HIGH
CVE-2026-28367 — Undertow: undertow: request smuggling via `\r\r\r` as a header block terminator

A flaw was found in Undertow. A remote attacker can exploit this vulnerability by sending `\r\r\r` as a header block terminator. This can be used for request smuggling with certain proxy servers, suc…

Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
Showing 20 of 6120 Results