Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2025-15519 — Command Injection in Modem Management CLI on TP-Link Archer NX200, NX210, NX500 and NX600

Improper input handling in a modem-management administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An…

| Injection
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
8.5 HIGH
CVE-2025-15518 — Command Injection in Wireless Control CLI on TP-Link Archer NX200, NX210, NX500 and NX600

Improper input handling in a wireless-control administrative CLI command on TP-Link Archer NX200, NX210, NX500 and NX600 allows crafted input to be executed as part of an operating system command. An…

| Injection
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
8.6 HIGH
CVE-2025-15517 — Authorization Bypass in HTTP Server Endpoints on TP-Link Archer NX200, NX210, NX500 and N…

A missing authentication check in the HTTP server on TP-Link Archer NX200, NX210, NX500 and NX600 to certain cgi endpoints allows unauthenticated access intended for authenticated users. An attacker …

| Authentication
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
6.5 MEDIUM
CVE-2026-4593 — erupts erupt MCP Tool EruptDataQuery.java EruptDataQuery sql injection

A flaw has been found in erupts erupt bis 1.13.3. Affected by this vulnerability is the function EruptDataQuery of the file erupt-ai/src/main/java/xyz/erupt/ai/call/impl/EruptDataQuery.java of the co…

Remote | Injection
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
8.8 HIGH
CVE-2026-33507 — AVideo Affected by CSRF on Plugin Import Endpoint Enables Unauthenticated Remote Code Exe…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users to upload and install plugin ZIP files containing e…

avideo | Remote | Cross-Site Request Forgery
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
9.3 CRITICAL
CVE-2026-33502 — AVideo has Unauthenticated SSRF via plugin/Live/test.php

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to ma…

avideo | Remote | Server-Side Request Forgery
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
5.3 MEDIUM
CVE-2026-33501 — AVideo has Unauthenticated Information Disclosure of User Group Permission Mappings via P…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/list.json.php` lacks any authentication or authoriza…

avideo | Remote | Authentication
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
5.4 MEDIUM
CVE-2026-33500 — AVideo Vulnerable to Stored XSS via Markdown `javascript:` URI Bypasses ParsedownSafeWith…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcqw-6466-3mv7) introduced a custom `ParsedownSafeWithLinks` class that sanitizes …

avideo | Remote | Cross-Site Scripting
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
6.1 MEDIUM
CVE-2026-33499 — AVideo has Reflected XSS via unlockPassword Parameter in forbiddenPage.php and warningPag…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `view/warningPage.php` templates reflect the `$_REQUEST['unlockPassword']` paramet…

avideo | Remote | Cross-Site Scripting
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
6.2 MEDIUM
CVE-2026-30007 — XnSoft NConvert Use-After-Free Vulnerability

XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file

| Memory Corruption
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
6.2 MEDIUM
CVE-2026-30006 — NConvert TIFF Stack Buffer Overrun

XnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file.

| Memory Corruption
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
7.5 HIGH
CVE-2026-26829 — Owntone-Server NULL Pointer Dereference Denial of Service Vulnerability

A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allows attackers to cause a Denial of Service (DoS) via sending a series of crafted HTTP r…

Remote | Denial of Service
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
7.5 HIGH
CVE-2026-26828 — Owntone-Server NULL Pointer Dereference Denial of Service

A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652d allows attackers to cause a Denial of Service (DoS) via sending a crafted DAAP requ…

Remote | Denial of Service
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
0.0 NA
CVE-2026-24516 — DigitalOcean Droplet Agent Command Injection Vulnerability

A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshooting/actioner/actioner.go) processes metadata from th…

| Injection
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
6.3 MEDIUM
CVE-2026-4592 — kalcaddle kodbox Password Login index.class.php tfaVerify improper authentication

A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of the file /workspace/source-code/plugins/client/controller/tfa/index.class.php of…

Remote | Authentication
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
5.8 MEDIUM
CVE-2026-4591 — kalcaddle kodbox fileThumb Endpoint app.php checkBin os command injection

A weakness has been identified in kalcaddle kodbox 1.64. This affects the function checkBin of the file /workspace/source-code/plugins/fileThumb/app.php of the component fileThumb Endpoint. Executing…

Remote | Injection
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
7.1 HIGH
CVE-2026-33493 — AVideo has a Path Traversal in import.json.php that Allows Private Video Theft and Arbitr…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoint accepts a user-controlled `fileURI` POST parameter with only a regex check t…

avideo | Remote | Path Traversal
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
7.3 HIGH
CVE-2026-33492 — AVideo has Session Fixation via GET PHPSESSID Parameter With Disabled Login Session Regen…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function accepts arbitrary session IDs via the `PHPSESSID` GET parameter and sets them …

avideo | Remote | Authentication
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
7.4 HIGH
CVE-2026-33488 — AVideo has a PGP 2FA Bypass via Cryptographically Broken 512-bit RSA Key Generation in Lo…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the LoginControl plugin's PGP 2FA system generates 512-bit RSA keys, which have been…

avideo | Remote | Cryptography
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
8.4 HIGH
CVE-2026-32845 — jkuhlmann / cgltf <= 1.15 Sparse Accessor Validation Integer Overflow

cgltf version 1.15 and prior contain an integer overflow vulnerability in the cgltf_validate() function when validating sparse accessors that allows attackers to trigger out-of-bounds reads by supply…

| Memory Corruption
Mar 23, 2026 Mar 23, 2026
Mar 23, 2026
Mar 23, 2026
Showing 20 of 5264 Results