Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

29232
Total
2268
Critical
8711
High
9096
Medium
CVE ID Severity Score Description Published
CVE-2026-41061 MEDIUM 5.4 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isValidDuration()` regex at `objects/video.php:918` uses `/^[0-9]{1,2}:[0-9]{1,2}:[0-9]{1,2}/` without a `$` end anchor, … Apr 21, 2026
CVE-2026-41060 HIGH 7.7 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `isSSRFSafeURL()` function in `objects/functions.php` contains a same-domain shortcircuit (lines 4290-4296) that … Apr 21, 2026
CVE-2026-41058 HIGH 8.1 WWBN AVideo is an open source video platform. In versions 29.0 and below, the incomplete fix for AVideo's CloneSite `deleteDump` parameter does not apply path … Apr 21, 2026
CVE-2026-41057 HIGH 7.1 WWBN AVideo is an open source video platform. In versions 29.0 and below, the CORS origin validation fix in commit `986e64aad` is incomplete. Two separate … Apr 21, 2026
CVE-2026-41056 HIGH 8.1 WWBN AVideo is an open source video platform. In versions 29.0 and below, the `allowOrigin($allowAll=true)` function in `objects/functions.php` reflects any arbitrary `Origin` header back in … Apr 21, 2026
CVE-2026-41055 HIGH 8.6 WWBN AVideo is an open source video platform. In versions 29.0 and below, an incomplete SSRF fix in AVideo's LiveLinks proxy adds `isSSRFSafeURL()` validation but … Apr 21, 2026
CVE-2026-40935 MEDIUM 5.3 WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/getCaptcha.php` accepts the CAPTCHA length (`ql`) directly from the query string with … Apr 21, 2026
CVE-2026-40929 MEDIUM 5.4 WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/commentDelete.json.php` is a state-mutating JSON endpoint that deletes comments but performs no … Apr 21, 2026
CVE-2026-40928 MEDIUM 5.4 WWBN AVideo is an open source video platform. In versions 29.0 and prior, multiple AVideo JSON endpoints under `objects/` accept state-changing requests via `$_REQUEST`/`$_GET` and … Apr 21, 2026
CVE-2026-40926 HIGH 7.1 WWBN AVideo is an open source video platform. In versions 29.0 and prior, three admin-only JSON endpoints — `objects/categoryAddNew.json.php`, `objects/categoryDelete.json.php`, and `objects/pluginRunUpdateScript.json.php` — enforce only … Apr 21, 2026
CVE-2026-3307 UNKNOWN An authorization bypass vulnerability was identified in GitHub Enterprise Server that allowed an attacker with admin access on one repository to modify the secret scanning … Apr 21, 2026
CVE-2026-6832 HIGH 8.1 Hermes WebUI contains an arbitrary file deletion vulnerability in the /api/session/delete endpoint that allows authenticated attackers to delete files outside the session directory by supplying … Apr 21, 2026
CVE-2026-6830 LOW 3.3 nesquena hermes-webui contains an environment variable leakage vulnerability where profile switching does not clear environment variables from the previously active profile before loading the next … Apr 21, 2026
CVE-2026-6829 MEDIUM 6.3 nesquena hermes-webui contains a trust-boundary failure vulnerability that allows authenticated attackers to set or change a session workspace to an arbitrary existing directory on disk … Apr 21, 2026
CVE-2026-6799 MEDIUM 6.3 A security flaw has been discovered in Comfast CF-N1-S 2.6.0.1. Affected by this issue is some unknown functionality of the file /cgi-bin/mbox-config?method=SET&section=ping_config of the component … Apr 21, 2026
CVE-2026-41527 MEDIUM 6.9 KDE Kleopatra before 26.08.0 on Windows allows local users to obtain the privileges of a Kleopatra user, because there is an error in the mechanism … Apr 21, 2026
CVE-2026-40946 UNKNOWN Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in the go-oidc verifier configuration, disabling … Apr 21, 2026
CVE-2026-40945 UNKNOWN Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token is logged at DEBUG level in … Apr 21, 2026
CVE-2026-40944 UNKNOWN Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration only parses the first PEM block from … Apr 21, 2026
CVE-2026-40943 UNKNOWN Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing and session closure can cause the server … Apr 21, 2026
CVE-2026-40942 UNKNOWN The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, The OIDC JWKS … Apr 21, 2026
CVE-2026-40939 UNKNOWN The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had … Apr 21, 2026
CVE-2026-40933 CRITICAL 9.9 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio … Apr 21, 2026
CVE-2026-40931 HIGH 8.4 Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation … Apr 21, 2026
CVE-2026-40706 HIGH 8.4 In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root … Apr 21, 2026