Skip to content

Menu
  • Home
Menu

CVE-2026-84482 – WWBN AVideo Cross-Site Request Forgery via get_domain() validation

Posted on September 2, 2026

CVE ID :CVE-2026-84482 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions…

CVE-2026-84480 – WWBN AVideo Password Recovery Token Expiration Bypass

Posted on September 2, 2026

CVE ID :CVE-2026-84480 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens…

CVE-2026-84479 – WWBN AVideo Authentication Bypass via User-Agent Header

Posted on September 2, 2026

CVE ID :CVE-2026-84479 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent…

CVE-2026-84476 – WWBN AVideo Authentication Bypass via X-Real-IP Header

Posted on September 2, 2026

CVE ID :CVE-2026-84476 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof…

CVE-2026-84208 – AVideo User_Location Plugin Unauthenticated SQL Injection

Posted on September 2, 2026

CVE ID :CVE-2026-84208 Published : Sept. 1, 2026, 11:17 p.m. | 1 hour, 19 minutes ago Description :AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin’s regions.json.php and cities.json.php…

CVE-2026-83524 – RedPort Optimizer wXa-223 System Clock datetime.php exec command injection

Posted on September 1, 2026

CVE ID :CVE-2026-83524 Published : Aug. 31, 2026, 11:16 p.m. | 1 hour, 20 minutes ago Description :A security vulnerability has been detected in RedPort Optimizer wXa-203, Optimizer wXa-213 and Optimizer wXa-223 up to…

CVE-2026-82971 – QVidium Opera11 CGI Script net_tr.cgi command injection

Posted on September 1, 2026

CVE ID :CVE-2026-82971 Published : Aug. 31, 2026, 11:16 p.m. | 1 hour, 20 minutes ago Description :A vulnerability was determined in QVidium Opera11 3.3.2a26-Ax4x-opera11. This affects an unknown part of the file /cgi-bin/net_tr.cgi…

CVE-2026-82954 – Dokploy Settings application.ts writeTraefikConfigInPath path traversal

Posted on September 1, 2026

CVE ID :CVE-2026-82954 Published : Aug. 31, 2026, 10:17 p.m. | 2 hours, 19 minutes ago Description :A vulnerability was detected in Dokploy up to 0.29.7. This issue affects the function writeTraefikConfigInPath of the…

CVE-2026-82882 – Devtron through 2.2.0 Missing Authorization via webhook API token endpoint

Posted on September 1, 2026

CVE ID :CVE-2026-82882 Published : Aug. 31, 2026, 10:17 p.m. | 2 hours, 19 minutes ago Description :Devtron through 2.2.0 fails to enforce authorization checks on the GET /orchestrator/api-token/webhook endpoint, allowing authenticated users to…

CVE-2026-77348 – Wallos incomplete fix for CVE-2026-33407: unauthenticated httpoxy SSRF still reachable via `endpoints/payments/search.php`

Posted on September 1, 2026

CVE ID :CVE-2026-77348 Published : Aug. 31, 2026, 10:17 p.m. | 2 hours, 19 minutes ago Description :Wallos is an open-source, self-hostable personal subscription tracker. Prior to version 5.0.0, the fix for CVE-2026-33407 (GHSA-hhjq-82f8-m6rc,…

Posts pagination

1 2 … 138 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme