|
2031
|
4.3 |
MEDIUM
Network
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. Prior to version 26.0, the `listFiles.json.php` endpoint accepts a `path` POST parameter and passes it directly to `glob()` without restricting the path …
|
CWE-22
Path Traversal
|
CVE-2026-33238
|
2026-04-14 03:16 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2032
|
4.3 |
MEDIUM
Network
|
wwbn
|
avideo
|
WWBN AVideo es una plataforma de video de código abierto. Antes de la versión 26.0, el endpoint 'listFiles.json.php' acepta un parámetro POST 'path' y lo pasa directamente a 'glob()' sin restringir l…
|
CWE-22
Path Traversal
|
CVE-2026-33238
|
2026-04-14 03:16 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2033
|
5.5 |
MEDIUM
Network
|
wwbn
|
avideo
|
WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` calls `url_get_contents()` with an admin-configurable …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-33237
|
2026-04-14 03:16 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2034
|
5.5 |
MEDIUM
Network
|
wwbn
|
avideo
|
WWBN AVideo es una plataforma de video de código abierto. Antes de la versión 26.0, la función 'run()' del plugin Scheduler en 'plugin/Scheduler/Scheduler.php' llama a 'url_get_contents()' con una 'c…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-33237
|
2026-04-14 03:16 |
2026-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2035
|
3.1 |
LOW
Network
|
-
|
-
|
A flaw was found in the exsltFuncResultComp() function of libxslt, which handles EXSLT <func:result> elements during stylesheet parsing. Due to improper type handling, the function may treat an XML d…
|
CWE-843
Type Confusion
|
CVE-2025-11731
|
2026-04-14 03:16 |
2025-10-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2036
|
3.3 |
LOW
Local
|
samsung
|
android
|
External control of file name in AODManager prior to SMR Apr-2026 Release 1 allows privileged local attacker to create file with system privilege.
|
NVD-CWE-noinfo
|
CVE-2026-21012
|
2026-04-14 03:16 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2037
|
6.8 |
MEDIUM
Physics
|
samsung
|
android
|
Incorrect privilege assignment in Bluetooth in Maintenance mode prior to SMR Apr-2026 Release 1 allows physical attackers to bypass Extend Unlock.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-21011
|
2026-04-14 03:15 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2038
|
7.5 |
HIGH
Network
|
fka
|
prompts.chat
|
prompts.chat prior to commit 7b81836 contains multiple authorization bypass vulnerabilities due to missing isPrivate checks across API endpoints and page metadata generation that allow unauthorized u…
|
CWE-862
Missing Authorization
|
CVE-2026-22663
|
2026-04-14 03:15 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2039
|
7.8 |
HIGH
Local
|
samsung
|
android
|
Improper input validation in Retail Mode prior to SMR Apr-2026 Release 1 allows local attackers to trigger privileged functions.
|
NVD-CWE-noinfo
|
CVE-2026-21010
|
2026-04-14 03:14 |
2026-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2040
|
7.7 |
HIGH
Network
|
fka
|
prompts.chat
|
prompts.chat prior to commit 30a8f04 contains a server-side request forgery vulnerability in Fal.ai media status polling that allows authenticated users to perform arbitrary outbound requests by supp…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-22664
|
2026-04-14 03:13 |
2026-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|