← All credits
tonghuaroot
29 vulnerability records and advisories credit this contributor.
CVE-2026-48912
Apache Answer: Improper authorization in avatar update cleanup allows authenticated users to delete arbitrary uploaded files by URL
CVE-2026-50749
Apache Answer: Missing authorization in revision audit reject allows authenticated users to reject pending revisions
CVE-2026-63305
AVideo through 29.0 OS Command Injection via ffmpeg.json.php
CVE-2026-63304
AVideo through 29.0 OS Command Injection via listFFmpegProcesses
CVE-2026-60092
AVideo - Stored Cross-Site Scripting via Unescaped User-Agent in Participants Panel
CVE-2026-53916
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Stomp: Unbounded header buffer in STOMP NIO codec
CVE-2026-53917
Apache ActiveMQ, Apache ActiveMQ All, Apache ActiveMQ Client, Apache ActiveMQ Broker: Unbounded memory allocation in OpenWire property unmarshalling
CVE-2026-10592
Wildcard DNS SAN bypasses CA name-constraint checks
CVE-2024-56736
Apache HertzBeat: Server-Side Request Forgery (SSRF) in Api Config Oss