Total CVEs

140,410

Critical Severity

3,747

High Severity

13,544

Last 7 Days

1,640
Quick preset (or use dates below)
Clear Filters
Showing 7,381 - 7,400 of 13,935 CVEs
CVE-2026-35452 MEDIUM - 5.3

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/CloneSite/client.log.php endpoint serves the clone operation log file without any authentication. Every other endpoint in the CloneSite plugin directory enforces User::isAdmin(). The log contains internal filesystem...

Vendor: composer
Product: wwbn/avideo
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35450 MEDIUM - 5.3

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/API/check.ffmpeg.json.php endpoint probes the FFmpeg remote server configuration and returns connectivity status without any authentication. All sibling FFmpeg management endpoints (kill.ffmpeg.json.php, list.ffmpeg...

Vendor: composer
Product: wwbn/avideo
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35449 MEDIUM - 5.3

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the install/test.php diagnostic script has its CLI-only access guard disabled by commenting out the die() statement. The script remains accessible via HTTP after installation, exposing video viewer statistics including IP addr...

Vendor: composer
Product: wwbn/avideo
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35441 MEDIUM - 6.5

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.17.0, Directus' GraphQL endpoints (/graphql and /graphql/system) did not deduplicate resolver invocations within a single request. An authenticated user could exploit GraphQL aliasing to repeat an expen...

Vendor: npm
Product: directus
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35413 MEDIUM - 5.3

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, when GRAPHQL_INTROSPECTION=false is configured, Directus correctly blocks standard GraphQL introspection queries (__schema, __type). However, the server_specs_graphql resolver on the /graphql/system en...

Vendor: npm
Product: directus
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35410 MEDIUM - 6.1

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, an open redirect vulnerability exists in the login redirection logic. The isLoginRedirectAllowed function fails to correctly identify certain malformed URLs as external, allowing attackers to bypass re...

Vendor: npm
Product: directus
Published: Apr 04, 2026
Source: GitHub
CVE-2026-35411 MEDIUM - 4.3

Directus is a real-time API and App dashboard for managing SQL database content. Prior to 11.16.1, Directus is vulnerable to an open redirect via the redirect query parameter on the /admin/tfa-setup page. When an administrator who has not yet configured Two-Factor Authentication (2FA) visits a craft...

Vendor: npm
Product: directus
Published: Apr 04, 2026
Source: GitHub
CVE-2026-2949 MEDIUM - 6.4

The Xpro Addons โ€” 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Icon Box widget in versions up to, and including, 1.4.24 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contrib...

Published: Apr 04, 2026
Source: NVD
CVE-2026-2924 MEDIUM - 6.4

The Gutenverse โ€“ Ultimate WordPress FSE Blocks Addons & Ecosystem plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'imageLoad' parameter in versions up to, and including, 3.4.6 due to insufficient input sanitization and output escaping. This makes it possible f...

Published: Apr 04, 2026
Source: NVD
CVE-2026-3571 MEDIUM - 6.5

The Pie Register โ€“ User Registration, Profiles & Content Restriction plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the pie_main() function in all versions up to, and including, 3.8.4.8. This makes it possible for unauthenticated atta...

Published: Apr 04, 2026
Source: NVD
CVE-2026-35181 MEDIUM - 4.3

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the player skin configuration endpoint at admin/playerUpdate.json.php does not validate CSRF tokens. The plugins table is explicitly excluded from the ORM's domain-based security check via ignoreTableSecurityCheck(), remo...

Vendor: composer
Product: wwbn/avideo
Published: Apr 03, 2026
Source: GitHub

Hugo is a static site generator. From 0.60.0 to before 0.159.2, links and image links in the default markdown to HTML renderer are not properly escaped. Hugo users who trust their Markdown content or have custom render hooks for links and images are not affected. This vulnerability is fixed in 0.159...

Vendor: go
Product: github.com/gohugoio/hugo
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35179 MEDIUM - 5.3

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the SocialMediaPublisher plugin exposes a publishInstagram.json.php endpoint that acts as an unauthenticated proxy to the Facebook/Instagram Graph API. The endpoint accepts user-controlled parameters including an access token,...

Vendor: composer
Product: wwbn/avideo
Published: Apr 03, 2026
Source: GitHub
CVE-2026-35468 MEDIUM - 5.3

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, two peer-facing consensus request handlers assume that the history index is always available and call blockchain.history_store.history_index().unw...

Vendor: nimiq
Product: core-rs-albatross
Published: Apr 03, 2026
Source: NVD
CVE-2026-34933 MEDIUM - 5.5

Avahi is a system which facilitates service discovery on a local network via the mDNS/DNS-SD protocol suite. Prior to version 0.9-rc4, any unprivileged local user can crash avahi-daemon by sending a single D-Bus method call with conflicting publish flags. This issue has been patched in version 0.9-r...

Vendor: avahi
Product: avahi
Published: Apr 03, 2026
Source: NVD
CVE-2026-34788 MEDIUM - 6.5

Emlog is an open source website building system. In versions 2.6.2 and prior, a SQL injection vulnerability exists in include/model/tag_model.php at line 168. The updateTagName() function directly interpolates user input into the SQL query string without using parameterized queries or proper escapin...

Vendor: emlog
Product: emlog
Published: Apr 03, 2026
Source: NVD
CVE-2026-34787 MEDIUM - 6.5

Emlog is an open source website building system. In versions 2.6.2 and prior, a Local File Inclusion (LFI) vulnerability exists in admin/plugin.php at line 80. The $plugin parameter from the GET request is directly used in a require_once path without proper sanitization. If the CSRF token check can ...

Vendor: emlog
Product: emlog
Published: Apr 03, 2026
Source: NVD
CVE-2026-34229 MEDIUM - 6.1

Emlog is an open source website building system. Prior to version 2.6.8, there is a stored cross-site scripting (XSS) vulnerability in emlog comment module via URI scheme validation bypass. This issue has been patched in version 2.6.8.

Vendor: emlog
Product: emlog
Published: Apr 03, 2026
Source: NVD
CVE-2026-34061 MEDIUM - 4.9

nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.3.0, an elected validator proposer can send an election macro block whose header.interlink does not match the canonical next interlink. Honest validato...

Vendor: nimiq
Product: core-rs-albatross
Published: Apr 03, 2026
Source: NVD
CVE-2017-20233 MEDIUM - 5.4

Hirschmann HiLCOS products OpenBAT, BAT450, WLC, BAT867 contains a firewall filtering vulnerability that fails to correctly filter IPv4 multicast and broadcast traffic when management IP address filtering is disabled, allowing configured filter rules to be bypassed. Attackers with network access can...

Vendor: Belden
Product: Hirschmann HiLCOS OpenBAT, BAT450, WLC, Hirschmann HiLCOS BAT867
Published: Apr 03, 2026
Source: NVD