Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Avideo HIGH 8.8
CVE-2025-34436

AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object…

Fix: 20.0+
Fix from $1,950 2025-12-17
Avideo HIGH 8.8
CVE-2025-34437

AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentic…

Fix: 20.0+
Fix from $1,950 2025-12-17
Avideo HIGH 8.1
CVE-2025-34438

AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation…

Fix: 20.0+
Fix from $1,950 2025-12-17
Avideo HIGH 7.5
CVE-2025-34441

AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, …

Fix: 20.0+
Fix from $1,950 2025-12-17
Avideo HIGH 7.5
CVE-2025-34442

AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata includes full server paths to m…

Fix: 20.0+
Fix from $1,950 2025-12-17
Avideo MEDIUM 6.1
CVE-2025-34439

AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An atta…

Fix: 20.0+
Fix from $1,600 2025-12-17
Avideo MEDIUM 6.1
CVE-2025-34440

AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedirectUri parameter during user r…

Fix: 20.0+
Fix from $1,600 2025-12-17
Avideo CRITICAL 9.1
CVE-2025-34434

AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints respon…

Fix: 20.0+
Fix from $2,300 2025-12-17
Avideo MEDIUM 6.5
CVE-2025-34435

AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files b…

Fix: 20.0+
Fix from $1,600 2025-12-17
Avideo CRITICAL 9.8
CVE-2025-48732

An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead …

Mitigation only
Fix from $2,300 2025-07-24
Avideo MEDIUM 6.1
CVE-2025-50128

A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commit …

No fix yet
Fix from $1,600 2025-07-24
Avideo MEDIUM 6.1
CVE-2025-53084

A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. …

No fix yet
Fix from $1,600 2025-07-24
Avideo CRITICAL 9.6
CVE-2025-36548

A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14.4 and dev maste…

No fix yet
Fix from $2,300 2025-07-24
Avideo CRITICAL 9.6
CVE-2025-41420

A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954…

No fix yet
Fix from $2,300 2025-07-24
Avideo MEDIUM 6.1
CVE-2025-46410

A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev ma…

No fix yet
Fix from $1,600 2025-07-24
Avideo HIGH 7.5
CVE-2025-25214

A race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A series …

No fix yet
Fix from $1,950 2025-07-24
Avideo MEDIUM 5.4
CVE-2024-34899

WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS).

Fix: after 12.4
Fix from $1,600 2024-05-14
Avideo CRITICAL 9.8
CVE-2024-31819EPSS 16%

An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.…

Fix: after 14.2
Fix from $2,300 2024-04-10
Avideo MEDIUM 6.5
CVE-2023-49863

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit …

No fix yet
Fix from $1,600 2024-01-10
Avideo MEDIUM 6.5
CVE-2023-49864

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit …

No fix yet
Fix from $1,600 2024-01-10
Avideo MEDIUM 5.3
CVE-2023-50172

A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fe…

No fix yet
Fix from $1,600 2024-01-10
Avideo CRITICAL 9.8
CVE-2023-49599

An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted se…

No fix yet
Fix from $2,300 2024-01-10
Avideo HIGH 8.8
CVE-2023-49589

An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed95…

No fix yet
Fix from $1,950 2024-01-10
Avideo HIGH 8.8
CVE-2023-49715

A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. …

No fix yet
Fix from $1,950 2024-01-10
Avideo HIGH 7.5
CVE-2023-49738

An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted …

No fix yet
Fix from $1,950 2024-01-10
Avideo MEDIUM 6.5
CVE-2023-49810

A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specia…

No fix yet
Fix from $1,600 2024-01-10
Avideo MEDIUM 6.5
CVE-2023-49862

An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit …

No fix yet
Fix from $1,600 2024-01-10
Avideo CRITICAL 9.8
CVE-2023-47862

A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially craf…

Mitigation only
Fix from $2,300 2024-01-10
Avideo MEDIUM 6.5
CVE-2023-47171

An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 1…

No fix yet
Fix from $1,600 2024-01-10
Avideo MEDIUM 6.1
CVE-2023-48728

A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb…

No fix yet
Fix from $1,600 2024-01-10