Total CVEs

140,425

Critical Severity

3,747

High Severity

13,549

Last 7 Days

1,490
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 7,701 - 7,720 of 13,564 CVEs
CVE-2026-34732 MEDIUM - 5.3

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo CreatePlugin template for list.json.php does not include any authentication or authorization check. While the companion templates add.json.php and delete.json.php both require admin privileges, the list.json.php tem...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD
CVE-2026-34716 MEDIUM - 6.4

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo YPTSocket plugin's caller feature renders incoming call notifications using the jQuery Toast Plugin, passing the caller's display name directly as the heading parameter. The toast plugin constructs the hea...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD
CVE-2026-34613 MEDIUM - 6.5

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/pluginSwitch.json.php allows administrators to enable or disable any installed plugin. The endpoint checks for an active admin session but does not validate a CSRF token. Additionally, the plugins d...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD
CVE-2026-34611 MEDIUM - 6.5

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo endpoint objects/emailAllUsers.json.php allows administrators to send HTML emails to every registered user on the platform. While the endpoint verifies admin session status, it does not validate a CSRF token. Becaus...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD
CVE-2026-34586 MEDIUM - 6.5

PdfDing is a selfhosted PDF manager, viewer and editor offering a seamless user experience on multiple devices. Prior to version 1.7.1, check_shared_access_allowed() validates only session existence โ€” it does not check SharedPdf.inactive (expiration / max views) or SharedPdf.deleted. The Serve and D...

Vendor: mrmn2
Product: PdfDing
Published: Mar 31, 2026
Source: NVD
CVE-2026-34396 MEDIUM - 6.1

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the AVideo admin panel renders plugin configuration values in HTML forms without applying htmlspecialchars() or any other output encoding. The jsonToFormElements() function in admin/functions.php directly interpolates user-con...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD
CVE-2026-34395 MEDIUM - 6.5

WWBN AVideo is an open source video platform. In versions 26.0 and prior, the plugin/YPTWallet/view/users.json.php endpoint returns all platform users with their personal information and wallet balances to any authenticated user. The endpoint checks User::isLogged() but does not check User::isAdmin(...

Vendor: WWBN
Product: AVideo
Published: Mar 31, 2026
Source: NVD
CVE-2026-34384 MEDIUM - 4.5

Admidio is an open-source user management solution. Prior to version 5.0.8, the create_user, assign_member, and assign_user action modes in modules/registration.php approve pending user registrations via GET request without validating a CSRF token. Unlike the delete_user mode in the same file (which...

Vendor: Admidio
Product: admidio
Published: Mar 31, 2026
Source: NVD
CVE-2026-34383 MEDIUM - 4.3

Admidio is an open-source user management solution. Prior to version 5.0.8, the inventory module's item_save endpoint accepts a user-controllable POST parameter imported that, when set to true, completely bypasses both CSRF token validation and server-side form validation. An authenticated user...

Vendor: Admidio
Product: admidio
Published: Mar 31, 2026
Source: NVD
CVE-2026-34382 MEDIUM - 4.6

Admidio is an open-source user management solution. From version 5.0.0 to before version 5.0.8, the delete mode handler in mylist_function.php permanently deletes list configurations without validating a CSRF token. An attacker who can lure an authenticated user to a malicious page can silently dest...

Vendor: Admidio
Product: admidio
Published: Mar 31, 2026
Source: NVD
CVE-2026-34206 MEDIUM - 6.1

Captcha Protect is a Traefik middleware to add an anti-bot challenge to individual IPs in a subnet when traffic spikes are detected from that subnet. Prior to version 1.12.2, a reflected cross-site scripting (XSS) vulnerability exists in github.com/libops/captcha-protect. The challenge page accepted...

Vendor: libops
Product: captcha-protect
Published: Mar 31, 2026
Source: NVD
CVE-2026-30280 MEDIUM - 5.3

An arbitrary file overwrite vulnerability in RAREPROB SOLUTIONS PRIVATE LIMITED Video player Play All Videos v1.0.135 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure.

Vendor: rareprob
Product: video_player
Published: Mar 31, 2026
Source: NVD
CVE-2026-2950 MEDIUM - 6.5

Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototype pollution in the _.unset and _.omit functions. The fix for (CVE-2025-13465: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg) only guards against string key members, so an attacker can bypass the check b...

Vendor: npm
Product: lodash
Published: Mar 31, 2026
Source: NVD
CVE-2026-30521 MEDIUM - 6.5

A Business Logic vulnerability exists in SourceCodester Loan Management System v1.0 due to improper server-side validation. The application allows administrators to create "Loan Plans" with specific interest rates. While the frontend interface prevents users from entering negative numbers,...

Vendor: oretnom23
Product: loan_management_system
Published: Mar 31, 2026
Source: NVD
CVE-2026-5206 MEDIUM - 6.3

A security vulnerability has been detected in code-projects Simple Gym Management System 1.0. This vulnerability affects unknown code of the component Payment Handler. The manipulation of the argument Payment_id/Amount/customer_id/payment_type/customer_name leads to sql injection. Remote exploitatio...

Published: Mar 31, 2026
Source: NVD
CVE-2026-33415 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated moderator-level user could retrieve post content, topic titles, and usernames from categories they were not ...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-33073 MEDIUM - 5.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, the discourse-subscriptions plugin leaks stripe API keys across sites in a multisite cluster resulting in the potential for s...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-32951 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, an authenticated user can obtain shared draft topic titles by sending an inline onebox request with a category_id parameter m...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-32618 MEDIUM - 4.3

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, there is possible channel membership inference from chat user search without authorization. This issue has been patched in ve...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD
CVE-2026-32273 MEDIUM - 5.4

Discourse is an open-source discussion platform. From versions 2026.1.0-latest to before 2026.1.3, 2026.2.0-latest to before 2026.2.2, and 2026.3.0-latest to before 2026.3.0, updating a category description via API is not sanitizing the description string, which can lead to XSS attacks. This issue h...

Vendor: discourse
Product: discourse
Published: Mar 31, 2026
Source: NVD