| CVE ID | Published | Description | Score | Severity | |
|---|---|---|---|---|---|
CVE-2026-33507 |
2026-03-23 17h16 +00:00 |
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/plu... Cross-Site Request Forgery - CSRF |
8.8 |
High |
|
CVE-2026-33502 |
2026-03-23 17h16 +00:00 |
WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticat... Server-Side Request Forgery - SSRF |
9.3 |
Critical |
|
CVE-2026-4404 |
2026-03-23 15h16 +00:00 |
Use of hard coded credentials in GoHarbor Harbor version 2.15.0 and below, allows attackers to use t... |
9.4 |
Critical |
|
CVE-2026-33480 |
2026-03-23 15h16 +00:00 |
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeU... Server-Side Request Forgery - SSRF |
8.6 |
High |
|
CVE-2026-33479 |
2026-03-23 15h16 +00:00 |
WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plug... Code Injection |
8.8 |
High |
|
CVE-2026-33478 |
2026-03-23 15h16 +00:00 |
WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnera... OS Command Injection |
10 |
Critical |
|
CVE-2026-33352 |
2026-03-23 14h16 +00:00 |
WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injectio... SQL Injection |
9.8 |
Critical |
|
CVE-2026-33351 |
2026-03-23 14h16 +00:00 |
WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (... Server-Side Request Forgery - SSRF |
9.1 |
Critical |
|
CVE-2026-33297 |
2026-03-23 14h16 +00:00 |
WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endp... Authorization problems |
9.1 |
Critical |
|
CVE-2026-4585 |
2026-03-23 12h16 +00:00 |
A vulnerability has been found in Tiandy Easy7 Integrated Management Platform up to 7.17.0. This vul... Command InjectionOS Command Injection |
9.8 |
Critical |