CVE Feed

    Dashboard / CVE

    7.4
    High

    CVE-2026-4565

    Last Modified: 3 Apr 2026

    A vulnerability was detected in Tenda AC21 16.03.08.16. Impacted is the function formSetQosBand of the file /goform/SetNetControlList. Performing a manipulation of the argument list results in buffer overflow. The attack can be initiated remotely. The exploit is now public and may be used.

    Published: 23 Mar 2026
    6.1
    Medium

    CVE-2026-4647

    Last Modified: 13 Jul 2026

    A flaw was found in the GNU Binutils BFD library, a widely used component for handling binary files such as object files and executables. The issue occurs when processing specially crafted XCOFF object files, where a relocation type value is not properly validated before being used. This can cause the program to read memory outside of intended bounds. As a result, affected tools may crash or expose unintended memory contents, leading to denial-of-service or limited information disclosure risks.

    Published: 23 Mar 2026
    8.8
    High

    CVE-2026-24516

    Last Modified: 18 Jun 2026

    A command injection vulnerability exists in DigitalOcean Droplet Agent through 1.3.2. The troubleshooting actioner component (internal/troubleshooting/actioner/actioner.go) processes metadata from the metadata service endpoint and executes commands specified in the TroubleshootingAgent.Requesting array without adequate input validation. While the code validates that artifacts exist in the validInvestigationArtifacts map, it fails to sanitize the actual command content after the "command:" prefix. This allows an attacker who can control metadata responses to inject and execute arbitrary OS commands with root privileges. The attack is triggered by sending a TCP packet with specific sequence numbers to the SSH port, which causes the agent to fetch metadata from http://169.254.169.254/metadata/v1.json. The vulnerability affects the command execution flow in internal/troubleshooting/actioner/actioner.go (insufficient validation), internal/troubleshooting/command/exec.go (direct exec.CommandContext call), and internal/troubleshooting/command/command.go (command parsing without sanitization). This can lead to complete system compromise, data exfiltration, privilege escalation, and potential lateral movement across cloud infrastructure.

    Published: 23 Mar 2026
    8.8
    High

    CVE-2026-4679

    Last Modified: 25 Mar 2026

    Integer overflow in Fonts in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

    Published: 23 Mar 2026
    8.8
    High

    CVE-2026-4676

    Last Modified: 25 Mar 2026

    Use after free in Dawn in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 23 Mar 2026
    8.8
    High

    CVE-2026-4675

    Last Modified: 25 Mar 2026

    Heap buffer overflow in WebGL in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

    Published: 23 Mar 2026
    8.8
    High

    CVE-2026-4674

    Last Modified: 25 Mar 2026

    Out of bounds read in CSS in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform out of bounds memory access via a crafted HTML page. (Chromium security severity: High)

    Published: 23 Mar 2026
    7.5
    High

    CVE-2026-26828

    Last Modified: 25 Mar 2026

    A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652d allows attackers to cause a Denial of Service (DoS) via sending a crafted DAAP request to the server

    Published: 23 Mar 2026
    4.8
    Medium

    CVE-2024-51224

    Last Modified: 25 Mar 2026

    Multiple cross-site scripting (XSS) vulnerabilities in the component /admin/edit-vehicle.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the vehiclename, modelnumber, regnumber, vehiclesubtype, chasisnum and enginenumber parameters.

    Published: 23 Mar 2026
    4.8
    Medium

    CVE-2024-51223

    Last Modified: 25 Mar 2026

    A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Mobile Number parameter.

    Published: 23 Mar 2026
    4.8
    Medium

    CVE-2024-51222

    Last Modified: 25 Mar 2026

    A stored cross-site scripting (XSS) vulnerability in the component /admin/profile.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Name parameter.

    Published: 23 Mar 2026
    5.4
    Medium

    CVE-2024-46878

    Last Modified: 3 Apr 2026

    A Cross-Site Scripting (XSS) vulnerability exists in the page parameter of tiki-editpage.php in Tiki version 26.3 and earlier. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or unauthorized actions.

    Published: 23 Mar 2026
    7.5
    High

    CVE-2026-26829

    Last Modified: 25 Mar 2026

    A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allows attackers to cause a Denial of Service (DoS) via sending a series of crafted HTTP requests to the server.

    Published: 23 Mar 2026
    6.1
    Medium

    CVE-2024-51226

    Last Modified: 25 Mar 2026

    A stored cross-site scripting (XSS) vulnerability in the component /admin/search-vehicle.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the Search parameter.

    Published: 23 Mar 2026
    4.8
    Medium

    CVE-2024-51225

    Last Modified: 25 Mar 2026

    A stored cross-site scripting (XSS) vulnerability in the component /admin/add-brand.php of Phpgurukul Vehicle Record Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the brandname parameter.

    Published: 23 Mar 2026
    8.8
    High

    CVE-2026-4680

    Last Modified: 25 Mar 2026

    Use after free in FedCM in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 23 Mar 2026
    4.3
    Medium

    CVE-2026-4628

    Last Modified: 2 Apr 2026

    A flaw was found in Keycloak. An improper Access Control vulnerability in Keycloak’s User-Managed Access (UMA) resource_set endpoint allows attackers with valid credentials to bypass the allowRemoteResourceManagement=false restriction. This occurs due to incomplete enforcement of access control checks on PUT operations to the resource_set endpoint. This issue enables unauthorized modification of protected resources, impacting data integrity.

    Published: 23 Mar 2026
    5.4
    Medium

    CVE-2024-46879

    Last Modified: 3 Apr 2026

    A Reflected Cross-Site Scripting (XSS) vulnerability exists in the POST request data zipPath of tiki-admin_system.php in Tiki version 21.2. This vulnerability allows attackers to execute arbitrary JavaScript code via a crafted payload, leading to potential access to sensitive information or unauthorized actions.

    Published: 23 Mar 2026
    8.8
    High

    CVE-2026-4673

    Last Modified: 25 Mar 2026

    Heap buffer overflow in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: High)

    Published: 23 Mar 2026
    8.8
    High

    CVE-2026-4677

    Last Modified: 25 Mar 2026

    Inappropriate implementation in WebAudio in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: High)

    Published: 23 Mar 2026
    8.8
    High

    CVE-2026-4678

    Last Modified: 25 Mar 2026

    Use after free in WebGPU in Google Chrome prior to 146.0.7680.165 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 23 Mar 2026
    6.2
    Medium

    CVE-2026-30007

    Last Modified: 27 Mar 2026

    XnSoft NConvert 7.230 is vulnerable to Use-After-Free via a crafted .tiff file

    Published: 23 Mar 2026
    6.2
    Medium

    CVE-2026-30006

    Last Modified: 27 Mar 2026

    XnSoft NConvert 7.230 is vulnerable to Stack Buffer Overrun via a crafted .tiff file.

    Published: 23 Mar 2026
    6.1
    Medium

    CVE-2025-52204

    Last Modified: 26 Mar 2026

    A Cross-Site Scripting (XSS) vulnerability exists in Znuny::ITSM 6.5.x in the customer.pl endpoint via the OTRSCustomerInterface parameter

    Published: 23 Mar 2026
    2
    Low

    CVE-2026-4564

    Last Modified: 24 Apr 2026

    A security vulnerability has been detected in yangzongzhuan RuoYi up to 4.8.2. This issue affects some unknown processing of the file /monitor/job/ of the component Quartz Job Handler. Such manipulation of the argument invokeTarget leads to code injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Mar 2026
    2.1
    Low

    CVE-2026-4563

    Last Modified: 24 Apr 2026

    A weakness has been identified in MacCMS up to 2025.1000.4052. This vulnerability affects the function order_info of the file application/index/controller/User.php of the component Member Order Detail Interface. This manipulation of the argument order_id causes authorization bypass. It is possible to initiate the attack remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 22 Mar 2026
    7.5
    High

    CVE-2026-2580

    Last Modified: 24 Apr 2026

    The WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters plugin for WordPress is vulnerable to time-based SQL Injection via the ‘orderby’ parameter in all versions up to, and including, 4.9.1 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for unauthenticated attackers to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 22 Mar 2026
    5.5
    Medium

    CVE-2026-4562

    Last Modified: 24 Apr 2026

    A security flaw has been discovered in MacCMS 2025.1000.4052. This affects an unknown part of the file application/api/controller/Timming.php of the component Timming API Endpoint. The manipulation results in missing authentication. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks.

    Published: 22 Mar 2026
    7.4
    High

    CVE-2026-4558

    Last Modified: 30 Apr 2026

    A flaw has been found in Linksys MR9600 2.0.6.206937. Affected is the function smartConnectConfigure of the file SmartConnect.lua. Executing a manipulation of the argument configApSsid/configApPassphrase/srpLogin/srpPassword can lead to os command injection. The attack may be launched remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 22 Mar 2026
    2.1
    Low

    CVE-2026-4557

    Last Modified: 24 Apr 2026

    A vulnerability was detected in code-projects Exam Form Submission 1.0. This impacts an unknown function of the file /admin/update_s1.php. Performing a manipulation of the argument sname results in cross site scripting. The attack may be initiated remotely. The exploit is now public and may be used.

    Published: 22 Mar 2026
    2.1
    Low

    CVE-2026-33296

    Last Modified: 25 Mar 2026

    WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a user-supplied redirectUri parameter is reflected directly into a JavaScript `document.location` assignment without JavaScript-safe encoding. After a user completes the login popup flow, a timer callback executes the redirect using the unvalidated value, sending the victim to an attacker-controlled site. Version 26.0 fixes the issue.

    Published: 22 Mar 2026
    8.2
    High

    CVE-2026-33295

    Last Modified: 25 Mar 2026

    WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plugin's download buttons component. The `clean_title` field of a video record is interpolated directly into a JavaScript string literal without any escaping, allowing an attacker who can create or modify a video to inject arbitrary JavaScript that executes in the browser of any user who visits the affected download page. Version 26.0 fixes the issue.

    Published: 22 Mar 2026
    5
    Medium

    CVE-2026-33294

    Last Modified: 25 Mar 2026

    WWBN AVideo is an open source video platform. Prior to version 26.0, the BulkEmbed plugin's save endpoint (`plugin/BulkEmbed/save.json.php`) fetches user-supplied thumbnail URLs via `url_get_contents()` without SSRF protection. Unlike all six other URL-fetching endpoints in AVideo that were hardened with `isSSRFSafeURL()`, this code path was missed. An authenticated attacker can force the server to make HTTP requests to internal network resources and retrieve the responses by viewing the saved video thumbnail. Version 26.0 fixes the issue.

    Published: 22 Mar 2026
    7.4
    High

    CVE-2026-4555

    Last Modified: 7 Apr 2026

    A weakness has been identified in D-Link DIR-513 1.10. The impacted element is the function formEasySetTimezone of the file /goform/formEasySetTimezone of the component boa. This manipulation of the argument curTime causes stack-based buffer overflow. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. This vulnerability only affects products that are no longer supported by the maintainer.

    Published: 22 Mar 2026
    2.1
    Low

    CVE-2026-4554

    Last Modified: 3 Apr 2026

    A security flaw has been discovered in Tenda F453 1.0.0.3. The affected element is the function FormWriteFacMac of the file /goform/WriteFacMac. The manipulation of the argument mac results in command injection. It is possible to launch the attack remotely. The exploit has been released to the public and may be used for attacks.

    Published: 22 Mar 2026
    8.1
    High

    CVE-2026-33293

    Last Modified: 25 Mar 2026

    WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed directly to `unlink()` without any path sanitization. An attacker with valid clone credentials can use path traversal sequences (e.g., `../../`) to delete arbitrary files on the server, including critical application files such as `configuration.php`, causing complete denial of service or enabling further attacks by removing security-critical files. Version 26.0 fixes the issue.

    Published: 22 Mar 2026
    5.9
    Medium

    CVE-2026-33319

    Last Modified: 25 Mar 2026

    WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin constructs a shell command by directly interpolating an upload URL received from LinkedIn's API response, without sanitization via `escapeshellarg()`. If an attacker can influence the LinkedIn API response (via MITM, compromised OAuth token, or API compromise), they can inject arbitrary OS commands that execute as the web server user. Version 26.0 contains a fix for the issue.

    Published: 22 Mar 2026
    7.5
    High

    CVE-2026-33292

    Last Modified: 25 Mar 2026

    WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal attack that allows an unauthenticated attacker to stream any private or paid video on the platform. The `videoDirectory` GET parameter is used in two divergent code paths — one for authorization (which truncates at the first `/` segment) and one for file access (which preserves `..` traversal sequences) — creating a split-oracle condition where authorization is checked against one video while content is served from another. Version 26.0 contains a fix for the issue.

    Published: 22 Mar 2026
    7.4
    High

    CVE-2026-4553

    Last Modified: 3 Apr 2026

    A vulnerability was identified in Tenda F453 1.0.0.3. Impacted is the function fromNatlimit of the file /goform/Natlimit of the component Parameters Handler. The manipulation of the argument page leads to stack-based buffer overflow. It is possible to initiate the attack remotely. The exploit is publicly available and might be used.

    Published: 22 Mar 2026
    7.4
    High

    CVE-2026-4552

    Last Modified: 3 Apr 2026

    A vulnerability was determined in Tenda F453 1.0.0.3. This issue affects the function fromVirtualSer of the file /goform/VirtualSer of the component Parameters Handler. Executing a manipulation of the argument page can lead to stack-based buffer overflow. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized.

    Published: 22 Mar 2026
    7.4
    High

    CVE-2026-4551

    Last Modified: 3 Apr 2026

    A vulnerability was found in Tenda F453 1.0.0.3. This vulnerability affects the function fromSafeClientFilter of the file /goform/SafeClientFilter of the component Parameters Handler. Performing a manipulation of the argument menufacturer/Go results in stack-based buffer overflow. The attack is possible to be carried out remotely. The exploit has been made public and could be used.

    Published: 22 Mar 2026
    2
    Low

    CVE-2026-4550

    Last Modified: 24 Apr 2026

    A vulnerability has been found in code-projects Simple Gym Management System up to 1.0. This affects an unknown part of the file /gym/func.php. Such manipulation of the argument Trainer_id/fname leads to sql injection. The attack can be executed remotely. The exploit has been disclosed to the public and may be used.

    Published: 22 Mar 2026
    2.3
    Low

    CVE-2026-4549

    Last Modified: 24 Apr 2026

    A flaw has been found in mickasmt next-saas-stripe-starter 1.0.0. Affected by this issue is the function openCustomerPortal of the file actions/open-customer-portal.ts of the component Stripe API. This manipulation causes authorization bypass. Remote exploitation of the attack is possible. The complexity of an attack is rather high. The exploitation is known to be difficult.

    Published: 22 Mar 2026
    8.6
    High

    CVE-2019-25619

    Last Modified: 3 Apr 2026

    FTP Shell Server 6.83 contains a buffer overflow vulnerability in the 'Account name to ban' field that allows local attackers to execute arbitrary code by supplying a crafted string. Attackers can inject shellcode through the account name parameter in the Manage FTP Accounts dialog to overwrite the return address and execute calc.exe or other commands.

    Published: 22 Mar 2026
    6.9
    Medium

    CVE-2019-25618

    Last Modified: 16 Apr 2026

    AdminExpress 1.2.5 contains a denial of service vulnerability that allows local attackers to crash the application by submitting oversized input through the System Compare feature. Attackers can paste a large buffer of characters into the Folder Path field and trigger the comparison function to cause the application to become unresponsive or crash.

    Published: 22 Mar 2026
    6.9
    Medium

    CVE-2019-25617

    Last Modified: 16 Apr 2026

    Ease Audio Converter 5.30 contains a denial of service vulnerability in the Audio Cutter function that allows local attackers to crash the application by processing malformed MP4 files. Attackers can create a crafted MP4 file containing an oversized buffer and load it through the Audio Cutter interface to trigger an application crash.

    Published: 22 Mar 2026
    6.9
    Medium

    CVE-2019-25616

    Last Modified: 16 Apr 2026

    AnMing MP3 CD Burner 2.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by supplying an oversized string. Attackers can paste a 6000-byte payload into the registration name field to trigger a denial of service condition.

    Published: 22 Mar 2026
    8.6
    High

    CVE-2019-25615

    Last Modified: 16 Apr 2026

    Lavavo CD Ripper 4.20 contains a structured exception handling (SEH) buffer overflow vulnerability that allows local attackers to execute arbitrary code by supplying a malicious string in the License Activation Name field. Attackers can craft a payload with controlled buffer data, NSEH jump instructions, and SEH handler addresses to trigger code execution and establish a bind shell on port 3110.

    Published: 22 Mar 2026
    9.3
    Critical

    CVE-2019-25614

    Last Modified: 28 Jul 2026

    Free Float FTP 1.0 contains a buffer overflow vulnerability in the STOR command handler that allows remote attackers to execute arbitrary code by sending a crafted STOR request with an oversized payload. Attackers can authenticate with anonymous credentials and send a malicious STOR command containing 247 bytes of padding followed by a return address and shellcode to trigger code execution on the FTP server.

    Published: 22 Mar 2026
    8.7
    High

    CVE-2019-25613

    Last Modified: 2 Apr 2026

    Easy Chat Server 3.1 contains a denial of service vulnerability that allows remote attackers to crash the application by sending oversized data in the message parameter. Attackers can establish a session via the chat.ghp endpoint and then send a POST request to body2.ghp with an excessively large message parameter value to cause the service to crash.

    Published: 22 Mar 2026