Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Avideo MEDIUM 5.3
CVE-2026-33761

WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in the Scheduler plugin lack any …

Fix: after 26.0
Fix from $1,600 2026-03-27
Avideo MEDIUM 5.3
CVE-2026-33763

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_correct` API endpoint allows any u…

Fix: after 26.0
Fix from $1,600 2026-03-27
Avideo CRITICAL 9.4
CVE-2026-33716

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/stand…

Fix: after 26.0
Fix from $2,300 2026-03-23
Avideo HIGH 8.8
CVE-2026-33717

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()` function in `objects/aVideoE…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 8.6
CVE-2026-33719

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN/status.json.php` and `plugin…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo MEDIUM 6.5
CVE-2026-33723

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `objects/subscribe.php` concate…

Fix: after 26.0
Fix from $1,600 2026-03-23
Avideo MEDIUM 5.3
CVE-2026-33688

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the password recovery endpoint at `objects/userRecoverPass.php` p…

Fix: after 26.0
Fix from $1,600 2026-03-23
Avideo MEDIUM 5.3
CVE-2026-33690

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `getRealIpAddr()` function in `objects/functions.php` trusts …

Fix: after 26.0
Fix from $1,600 2026-03-23
Avideo HIGH 8.8
CVE-2026-33649

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Permissions/setPermission.json.php` endpoint accepts …

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 8.8
CVE-2026-33651

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `remindMe.json.php` endpoint passes `$_REQUEST['live_schedule…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 7.6
CVE-2026-33650

WWBN AVideo is an open source video platform. In versions up to and including 26.0, a user with the "Videos Moderator" permission can escalate privil…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 7.2
CVE-2026-33681

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginRunDatabaseScript.json.php` endpoint accepts a…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo MEDIUM 5.4
CVE-2026-33683

WWBN AVideo is an open source video platform. In versions up to and including 26.0, a sanitization order-of-operations flaw in the user profile "abou…

Fix: after 26.0
Fix from $1,600 2026-03-23
Avideo MEDIUM 5.3
CVE-2026-33685

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/AD_Server/reports.json.php` endpoint performs no auth…

Fix: after 26.0
Fix from $1,600 2026-03-23
Avideo HIGH 8.8
CVE-2026-33647

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `ImageGallery::saveFile()` method validates uploaded file con…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 8.8
CVE-2026-33648

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the restreamer endpoint constructs a log file path by embedding u…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 7.5
CVE-2026-33512

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the API plugin exposes a `decryptString` action without any authe…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 7.5
CVE-2026-33513

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated API endpoint (`APIName=locale`) concatenates u…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 8.8
CVE-2026-33507

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/pluginImport.json.php` endpoint allows admin users t…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 8.2
CVE-2026-33502

WWBN AVideo is an open source video platform. In versions up to and including 26.0, an unauthenticated server-side request forgery vulnerability in `…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo MEDIUM 6.1
CVE-2026-33499

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `view/forbiddenPage.php` and `view/warningPage.php` templates…

Fix: after 26.0
Fix from $1,600 2026-03-23
Avideo MEDIUM 5.4
CVE-2026-33500

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the fix for CVE-2026-27568 (GHSA-rcqw-6466-3mv7) introduced a cus…

Fix: after 26.0
Fix from $1,600 2026-03-23
Avideo MEDIUM 5.3
CVE-2026-33501

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the endpoint `plugin/Permissions/View/Users_groups_permissions/li…

Fix: after 26.0
Fix from $1,600 2026-03-23
Avideo HIGH 8.1
CVE-2026-33488

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `createKeys()` function in the LoginControl plugin's PGP 2FA …

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 8.1
CVE-2026-33493

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/import.json.php` endpoint accepts a user-controlled …

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 7.3
CVE-2026-33492

WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo's `_session_start()` function accepts arbitrary session ID…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo CRITICAL 10.0
CVE-2026-33478EPSS 13%

WWBN AVideo is an open source video platform. In versions up to and including 26.0, multiple vulnerabilities in AVideo's CloneSite plugin chain toget…

Fix: after 26.0
Fix from $2,300 2026-03-23
Avideo HIGH 8.8
CVE-2026-33479

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the Gallery plugin's `saveSort.json.php` endpoint passes unsaniti…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 8.6
CVE-2026-33480

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `isSSRFSafeURL()` function in AVideo can be bypassed using IP…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 8.1
CVE-2026-33482

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `sanitizeFFmpegCommand()` function in `plugin/API/standAlone/…

Fix: after 26.0
Fix from $1,950 2026-03-23