Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-5027 — Apache File Upload Path Traversal Vulnerability

The 'POST /api/v2/files' endpoint does not sanitize the 'filename' parameter from the multipart form data, allowing an attacker to write files to arbitrary locations on the filesystem using path trav…

Remote | Path Traversal
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.0 HIGH
CVE-2026-5026 — Apache FusionReactor Stored Cross-Site Scripting (XSS)

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint serves SVG files with the 'image/svg+xml' content type without sanitizing their content. Since SVG files can contain embedded JavaScript, an…

Remote | Cross-Site Scripting
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.5 MEDIUM
CVE-2026-5025 — Apache Log Router Authentication Bypass

The '/logs' and '/logs-stream' endpoints in the log router allow any authenticated user to read the full application log buffer. These endpoints only require basic authentication ('get_current_active…

Remote | Authorization
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.3 MEDIUM
CVE-2026-5022 — Apache Flow Unauthenticated File Download

The '/api/v1/files/images/{flow_id}/{file_name}' endpoint does not enforce any authentication or authorization checks, allowing any unauthenticated user to download images belonging to any flow by kn…

Remote | Authentication
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.1 MEDIUM
CVE-2026-5010 — Clickedu Reflected XSS

A reflected Cross-Site Scripting (XSS) vulnerability has been discovered in Clickedu. This vulnerability allows an attacker to execute JavaScript code in the victim’s browser by sending them a malici…

Remote | Cross-Site Scripting
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
8.2 HIGH
CVE-2026-4984 — Twilio Webhook Signature Validation Bypass Remote Code Execution

The Twilio integration webhook handler accepts any POST request without validating Twilio's 'X-Twilio-Signature'. When processing media messages, it fetches user-controlled URLs ('MediaUrlN' paramet…

Remote | Authentication
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.3 MEDIUM
CVE-2026-4980 — Inkscape XML Include File Disclosure

A local file disclosure vulnerability in the XInclude processing component of Inkscape 1.1 before 1.3 allows a remote attacker to read local files via a crafted SVG file containing malicious xi:inclu…

| Path Traversal
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.1 MEDIUM
CVE-2026-4957 — OpenBMB XAgent Remote Information Disclosure

A flaw has been found in OpenBMB XAgent 1.0.0. The impacted element is the function FunctionHandler.handle_tool_call of the file XAgent/function_handler.py of the component API Key Handler. This mani…

Remote | Information Disclosure
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.5 HIGH
CVE-2026-4956 — Streamax Crocus SQL Injection Vulnerability

A vulnerability was detected in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. The affected element is an unknown function of the file /DevicePrint.do?Action=ReadTask of the component Parameter …

Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.5 HIGH
CVE-2026-4955 — Streamax Crocus SQL Injection Vulnerability

A vulnerability was found in Shenzhen Ruiming Technology Streamax Crocus 1.3.44. This impacts an unknown function of the file /OperateStatistic.do. The manipulation of the argument VehicleID results …

Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
6.5 MEDIUM
CVE-2026-4954 — MingSoft MCMS SQL Injection Vulnerability

A security vulnerability has been detected in mingSoft MCMS 迄 5.5.0. Impacted is the function list of the file net/mingsoft/cms/action/web/ContentAction.java of the component Web Content List Endpoin…

Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
7.5 HIGH
CVE-2026-4953 — MingSoft MCMS Server-Side Request Forgery (SSRF)

A weakness has been identified in mingSoft MCMS 迄 5.5.0. This issue affects the function catchImage of the file net/mingsoft/cms/action/BaseAction.java of the component Editor Endpoint. Executing a m…

Remote | Server-Side Request Forgery
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.3 MEDIUM
CVE-2026-33766 — WWBN AVideo SSRF Bypass Through Redirect

WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs against private/reserved IP ranges before fetching, but `url_get_contents()` follo…

Remote | Server-Side Request Forgery
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
4.3 MEDIUM
CVE-2026-33764 — WWBN AVideo AI Plugin JSON Endpoint Cross-Site Scripting Vulnerability

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endpoint loads AI response objects using an attacker-controlled `$_REQUEST['id']` p…

Remote | Information Disclosure
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.3 MEDIUM
CVE-2026-33763 — WWBN AVideo Password Verification Bypass

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_correct` API endpoint allows any unauthenticated user to verify whether a given pass…

Remote | Authentication
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.3 MEDIUM
CVE-2026-33761 — WWBN AVideo Unauthenticated Information Disclosure

WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in the Scheduler plugin lack any authentication check, while every other endpoint i…

Remote | Authentication
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
5.3 MEDIUM
CVE-2026-33759 — WWBN AVideo Unauthenticated Playlist Contents Disclosure

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.php` endpoint returns the full video contents of any playlist by ID without any a…

Remote | Authorization
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
9.4 CRITICAL
CVE-2026-33758 — OpenBao OIDC/JWT Authentication Cross-Site Scripting (XSS)

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao installations that have an OIDC/JWT authentication method enabled and a role with `callback_mode=di…

Remote | Cross-Site Scripting
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
9.6 CRITICAL
CVE-2026-33757 — OpenBao JWT/OIDC Authorization Remote Phishing

OpenBao is an open source identity-based secrets management system. Prior to version 2.5.2, OpenBao does not prompt for user confirmation when logging in via JWT/OIDC and a role with `callback_mode` …

Remote | Authentication
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
8.8 HIGH
CVE-2026-33755 — Group-Office SQL Injection Vulnerability

Group-Office is an enterprise customer relationship management and groupware tool. Prior to versions 6.8.158, 25.0.92, and 26.0.17, an authenticated SQL Injection vulnerability in the JMAP `Contact/q…

Remote | Injection
Mar 27, 2026 Mar 27, 2026
Mar 27, 2026
Mar 27, 2026
Showing 20 of 6099 Results