Vulnerability index

Browse CVEs

23 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.0 CVE-2016-20034 Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to adminis… Streaming Engine No fix yet Fix from $1,9502026-03-16 HIGH 7.8 CVE-2016-20033 Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing … Streaming Engine No fix yet Fix from $1,9502026-03-16 MEDIUM 6.1 CVE-2016-20036 Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager interface where input passed throu… Streaming Engine No fix yet Fix from $1,6002026-03-16 MEDIUM 6.5 CVE-2024-52056 Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to delete any directory on the file system… Streaming Engine 4.9.1+ Fix from $1,6002024-11-21 CRITICAL 9.6 CVE-2024-52053 Stored Cross-Site Scripting in the Manager component of Wowza Streaming Engine below 4.9.1 allows an unauthenticated attacker to inject client-side J… Streaming Engine 4.9.1+ Fix from $2,3002024-11-21 HIGH 7.2 CVE-2024-52052 Wowza Streaming Engine below 4.9.1 permits an authenticated Streaming Engine Manager administrator to define a custom application property and poison… Streaming Engine 4.9.1+ Fix from $1,9502024-11-21 HIGH 8.1 CVE-2021-35491 A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker to delete a user account via th… Streaming Engine 4.8.14+ Fix from $1,9502021-10-05 MEDIUM 6.5 CVE-2021-35492 Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources via the /enginemanager/server/v… Streaming Engine after 4.8.11 Fix from $1,6002021-10-05 HIGH 7.1 CVE-2021-31540 Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files in the conf/ directory. A regu… Streaming Engine after 4.8.5 Fix from $1,9502021-04-23 MEDIUM 5.5 CVE-2021-31539 Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.password file. A regular local us… Streaming Engine 4.8.8.01+ Fix from $1,6002021-04-23 HIGH 7.8 CVE-2019-19455 Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in / usr / local / WowzaStreamin… Streaming Engine 4.8.5+ Fix from $1,9502020-08-03 MEDIUM 5.4 CVE-2019-19453 Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license editing is able to insert a ma… Streaming Engine 4.8.5+ Fix from $1,6002020-08-03 HIGH 7.5 CVE-2019-19454 An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x. This issue was resolved in Wowza Streami… Streaming Engine after 4.8.0 Fix from $1,9502020-05-18 MEDIUM 6.1 CVE-2019-19456 A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza Streaming Engine <= 4.x.x. Th… Streaming Engine after 4.8.0 Fix from $1,6002020-05-18 HIGH 8.8 CVE-2020-9004 A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-only user to issue requests to … Streaming Engine after 4.8.0 Fix from $1,9502020-04-14 HIGH 7.8 CVE-2019-7656 A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to escalate privileges to root. T… Streaming Engine after 4.8.0 Fix from $1,9502020-01-29 MEDIUM 6.5 CVE-2019-7654 Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by following a link, can be trick… Streaming Engine after 4.8.0 Fix from $1,6002020-01-29 MEDIUM 5.4 CVE-2019-7655 Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.value field in enginemanager/s… Streaming Engine after 4.8.0 Fix from $1,6002020-01-29 CRITICAL 9.1 CVE-2018-19365EPSS 22% The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via a remote, specifically crafte… Streaming Engine No fix yet Fix from $2,3002019-03-21 MEDIUM 5.3 CVE-2017-16922 In com.wowza.wms.timedtext.http.HTTPProviderCaptionFile in Wowza Streaming Engine before 4.7.1, traversal of the directory structure and retrieval of… Streaming Engine 4.7.1+ Fix from $1,6002018-03-05 CRITICAL 9.8 CVE-2018-7047 An issue was discovered in the MBeans Server in Wowza Streaming Engine before 4.7.1. The file system may be read and written to via JMX using the def… Streaming Engine 4.7.1+ Fix from $2,3002018-03-01 HIGH 7.5 CVE-2018-7048 An issue was discovered in Wowza Streaming Engine before 4.7.1. There is a denial of service (memory consumption) via a crafted HTTP request. Streaming Engine 4.7.1+ Fix from $1,9502018-03-01 MEDIUM 6.1 CVE-2018-7049 An issue was discovered in Wowza Streaming Engine before 4.7.1. There is an XSS vulnerability in the HTTP providers (com.wowza.wms.http.HTTPProviderM… Streaming Engine 4.7.1+ Fix from $1,6002018-03-01