Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Avideo HIGH 7.5
CVE-2026-33483

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` endpoint is a completely standa…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo HIGH 7.5
CVE-2026-33485

WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `plugin/Live/on_publish.php` is…

Fix: after 26.0
Fix from $1,950 2026-03-23
Avideo MEDIUM 6.5
CVE-2026-33354

WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.php` accepts a requester-contro…

Fix: after 26.0
Fix from $1,600 2026-03-23
Avideo CRITICAL 9.8
CVE-2026-33352

WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` …

Fix: 26.0+
Fix from $2,300 2026-03-23
Avideo CRITICAL 9.1
CVE-2026-33297

WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administr…

Fix: 26.0+
Fix from $2,300 2026-03-23
Avideo CRITICAL 9.1
CVE-2026-33351

WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standA…

Fix: 26.0+
Fix from $2,300 2026-03-23
Avideo HIGH 7.5
CVE-2026-33319

WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin construc…

Fix: 26.0+
Fix from $1,950 2026-03-22
Avideo MEDIUM 6.1
CVE-2026-33296

WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a us…

Fix: 26.0+
Fix from $1,600 2026-03-22
Avideo MEDIUM 5.4
CVE-2026-33295

WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plug…

Fix: 26.0+
Fix from $1,600 2026-03-22
Avideo HIGH 8.1
CVE-2026-33293

WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed …

Fix: 26.0+
Fix from $1,950 2026-03-22
Avideo HIGH 7.5
CVE-2026-33292

WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal at…

Fix: 26.0+
Fix from $1,950 2026-03-22
Avideo MEDIUM 5.5
CVE-2026-33237

WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` call…

Fix: 26.0+
Fix from $1,600 2026-03-21
Avideo HIGH 8.6
CVE-2026-33039

WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint validates user-supplied URLs agains…

Fix: 26.0+
Fix from $1,950 2026-03-20
Avideo HIGH 8.1
CVE-2026-33043

WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the current PHP session ID to any un…

Fix: 26.0+
Fix from $1,950 2026-03-20
Avideo MEDIUM 5.3
CVE-2026-33041

WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the application's password hashing al…

Fix: 26.0+
Fix from $1,600 2026-03-20
Avideo HIGH 8.1
CVE-2026-33037

WWBN AVideo is an open source video platform. In versions 25.0 and below, the official Docker deployment files (docker-compose.yml, env.example) ship…

Fix: 26.0+
Fix from $1,950 2026-03-20
Avideo HIGH 8.1
CVE-2026-33038

WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application takeover through the install/chec…

Fix: 26.0+
Fix from $1,950 2026-03-20
Avideo MEDIUM 6.1
CVE-2026-33035

WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that allows unauthenticated attacker…

Fix: 26.0+
Fix from $1,600 2026-03-20
Avideo Encoder CRITICAL 9.1
CVE-2026-33024

AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpo…

Fix: 8.0+
Fix from $2,300 2026-03-20
Avideo Encoder HIGH 8.8
CVE-2026-33025

AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlFromPost() method of Object.php. The $_P…

Fix: 8.0+
Fix from $1,950 2026-03-20
Avideo MEDIUM 5.3
CVE-2026-30885

WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user with…

Fix: 25.0+
Fix from $1,600 2026-03-10
Avideo Encoder CRITICAL 9.8
CVE-2026-29058

AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by inj…

Fix: 7.0+
Fix from $2,300 2026-03-06
Avideo CRITICAL 9.8
CVE-2026-28501

WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objec…

Fix: 24.0+
Fix from $2,300 2026-03-06
Avideo CRITICAL 9.8
CVE-2026-29093

WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 112…

Fix: 24.0+
Fix from $2,300 2026-03-06
Avideo HIGH 8.8
CVE-2026-28502

WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVi…

Fix: 24.0+
Fix from $1,950 2026-03-06
Avideo HIGH 8.1
CVE-2026-27732

WWBN AVideo is an open source video platform. Prior to version 22.0, the `aVideoEncoder.json.php` API endpoint accepts a `downloadURL` parameter and …

Fix: 22.0+
Fix from $1,950 2026-02-24
Avideo MEDIUM 6.1
CVE-2026-27568

WWBN AVideo is an open source video platform. Prior to version 21.0, AVideo allows Markdown in video comments and uses Parsedown (v1.7.4) without Saf…

Fix: 21.0+
Fix from $1,600 2026-02-24
Avideo HIGH 7.5
CVE-2020-37173

AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.js…

No fix yet
Fix from $1,950 2026-02-11
Avideo CRITICAL 9.8
CVE-2020-37172

AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password reco…

Mitigation only
Fix from $2,300 2026-02-11
Avideo HIGH 8.8
CVE-2020-37158

AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password reco…

No fix yet
Fix from $1,950 2026-02-11