Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-33502 — AVideo has Unauthenticated SSRF via plugin/Live/test.php

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `plugin/Live/test.php` allows any remote user to ma…

avideo | Remote | Server-Side Request Forgery
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
5.3 MEDIUM
CVE-2026-33501 — AVideo has Unauthenticated Information Disclosure of User Group Permission Mappings via P…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/list.json.php` lacks any authentication or authoriza…

avideo | Remote | Authentication
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
5.4 MEDIUM
CVE-2026-33500 — AVideo Vulnerable to Stored XSS via Markdown `javascript:` URI Bypasses ParsedownSafeWith…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcqw-6466-3mv7) introduced a custom `ParsedownSafeWithLinks` class that sanitizes …

avideo | Remote | Cross-Site Scripting
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
6.1 MEDIUM
CVE-2026-33499 — AVideo has Reflected XSS via unlockPassword Parameter in forbiddenPage.php and warningPag…

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `view/warningPage.php` templates reflect the `$_REQUEST['unlockPassword']` paramet…

avideo | Remote | Cross-Site Scripting
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
6.2 MEDIUM
CVE-2026-30007 — XnSoft NConvert Use-After-Free Vulnerability

XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file

nconvert | Memory Corruption
Mar 23, 2026 Mar 26, 2026
Mar 23, 2026
Mar 26, 2026
6.2 MEDIUM
CVE-2026-30006 — NConvert TIFF Stack Buffer Overrun

XnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file.

nconvert | Memory Corruption
Mar 23, 2026 Mar 26, 2026
Mar 23, 2026
Mar 26, 2026
7.5 HIGH
CVE-2026-26829 — Owntone-Server NULL Pointer Dereference Denial of Service Vulnerability

A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allows attackers to cause a Denial of Service (DoS) via sending a series of crafted HTTP r…

Remote | Denial of Service
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
7.5 HIGH
CVE-2026-26828 — Owntone-Server NULL Pointer Dereference Denial of Service

A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652d allows attackers to cause a Denial of Service (DoS) via sending a crafted DAAP requ…

Remote | Denial of Service
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
8.8 HIGH
CVE-2026-24516 — DigitalOcean Droplet Agent Command Injection Vulnerability

A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshooting/actioner/actioner.go) processes metadata from th…

Remote | Injection
Mar 23, 2026 Mar 24, 2026
Mar 23, 2026
Mar 24, 2026
Showing 20 of 6449 Results