Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-39370 — WWBN AVideo has an Allowlisted downloadURL media extensions bypass SSRF protection and e…

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoder.json.php still allows attacker-controlled downloadURL values with common media or archive extensions su…

Remote | Server-Side Request Forgery
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
7.6 HIGH
CVE-2026-39369 — WWBN AVideo's GIF poster fetch bypasses traversal scrubbing and exposes local files throu…

WWBN AVideo is an open source video platform. In versions 26.0 and prior, objects/aVideoEncoderReceiveImage.json.php allowed an authenticated uploader to fetch attacker-controlled same-origin /videos…

Remote | Path Traversal
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.5 MEDIUM
CVE-2026-39368 — WWBN AVideo has a Live restream log callback flow enabling stored SSRF to internal servic…

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the Live restream log callback flow accepted an attacker-controlled restreamerURL and later fetched that stored URL server-si…

Remote | Server-Side Request Forgery
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
5.4 MEDIUM
CVE-2026-39367 — WWBN AVideo has Stored XSS via Malicious EPG XML Program Titles in AVideo EPG Page

WWBN AVideo is an open source video platform. In versions 26.0 and prior, AVideo's EPG (Electronic Program Guide) feature parses XML from user-controlled URLs and renders programme titles directly in…

Remote | Cross-Site Scripting
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.5 MEDIUM
CVE-2026-39366 — WWBN AVideo Affected by a PayPal IPN Replay Attack Enabling Wallet Balance Inflation via …

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the PayPal IPN v1 handler at plugin/PayPalYPT/ipn.php lacks transaction deduplication, allowing an attacker to replay a singl…

Remote | Misconfiguration
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.3 MEDIUM
CVE-2026-39365 — Vite has a Path Traversal in Optimized Deps `.map` Handling

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, the dev server’s handling of .map requests for optimized dependencies resolves file paths and calls …

Remote | Path Traversal
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.2 HIGH
CVE-2026-39364 — Vite has a `server.fs.deny` bypass with queries

Vite is a frontend tooling framework for JavaScript. From 7.1.0 to before 7.3.2 and 8.0.5, on the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved …

Remote | Misconfiguration
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.2 HIGH
CVE-2026-39363 — Vite Affected by Arbitrary File Read via Vite Dev Server WebSocket

Vite is a frontend tooling framework for JavaScript. From 6.0.0 to before 6.4.2, 7.3.2, and 8.0.5, if it is possible to connect to the Vite dev server’s WebSocket without an Origin header, an attacke…

Remote | Path Traversal
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
7.7 HIGH
CVE-2026-39361 — OpenObserve has a SSRF Protection Bypass via IPv6 Bracket Notation in validate_enrichment…

OpenObserve is a cloud-native observability platform. In 0.70.3 and earlier, the validate_enrichment_url function in src/handler/http/request/enrichment_table/mod.rs fails to block IPv6 addresses bec…

Remote | Server-Side Request Forgery
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
7.5 HIGH
CVE-2026-39356 — SQL Injection via escapeName() in all Drizzle ORM SQL dialects

Drizzle is a modern TypeScript ORM. Prior to 0.45.2 and 1.0.0-beta.20, Drizzle ORM improperly escaped quoted SQL identifiers in its dialect-specific escapeName() implementations. In affected versions…

Remote | Injection
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
9.2 CRITICAL
CVE-2026-39322 — PolarLearn: Any password authenticates banned accounts and grants API access

PolarLearn is a free and open-source learning program. In 0-PRERELEASE-15 and earlier, POST /api/v1/auth/sign-in creates a valid session for banned accounts before verifying the supplied password. Th…

Remote | Authentication
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.5 HIGH
CVE-2026-32864 — Out-of-Bounds Read in mgcore_SH_25_3!aligned_free()

There is a memory corruption vulnerability due to an out-of-bounds read in mgcore_SH_25_3!aligned_free() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code exec…

| Memory Corruption
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.5 HIGH
CVE-2026-32863 — Out-of-Bounds Read in sentry_transaction_context_set_operation()

There is a memory corruption vulnerability due to an out-of-bounds read in sentry_transaction_context_set_operation() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitr…

| Memory Corruption
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.5 HIGH
CVE-2026-32862 — Out-of-Bounds Write in ResFileFactory::InitResourceMgr()

There is a memory corruption vulnerability due to an out-of-bounds write in ResFileFactory::InitResourceMgr() in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code…

| Memory Corruption
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.5 HIGH
CVE-2026-32861 — Out-of-Bounds Write Vulnerability in NI LabVIEW when loading lvclass file

There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVCLASS file in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary cod…

| Memory Corruption
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.5 HIGH
CVE-2026-32860 — Out-of-Bounds Write Vulnerability in NI LabVIEW when loading lvlib file

There is a memory corruption vulnerability due to an out-of-bounds write when loading a corrupted LVLIB file in NI LabVIEW.  This vulnerability may result in information disclosure or arbitrary code …

| Memory Corruption
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
0.0 NA
CVE-2025-69515 — JXL Car Android GPS Spoofing Vulnerability

An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device report…

| Misconfiguration
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
0.0 NA
CVE-2025-56015 — GenieACS Unauthenticated NBI API Endpoint Access Vulnerability

In GenieACS 1.2.13, an unauthenticated access vulnerability exists in the NBI API endpoint.

| Authentication
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
7.0 HIGH
CVE-2025-14859 — Semtech LR11xx Secure Boot Bypass

The Semtech LR11xx LoRa transceivers implement secure boot functionality using digital signatures to authenticate firmware. However, the implementation uses a non-standard cryptographic hashing algor…

| Cryptography
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
5.1 MEDIUM
CVE-2025-14858 — Semtech LR11xx Encrypted Firmware Disclosure

The Semtech LR11xx LoRa transceivers running early versions of firmware contains an information disclosure vulnerability in its firmware validation functionality. When a host issues a firmware validi…

| Information Disclosure
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
Showing 20 of 6199 Results