Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2026-33483 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `aVideoEncoderChunk.json.php` endpoint is a completely standa… Avideo after 26.0 Fix from $1,9502026-03-23 HIGH 7.5 CVE-2026-33485 WWBN AVideo is an open source video platform. In versions up to and including 26.0, the RTMP `on_publish` callback at `plugin/Live/on_publish.php` is… Avideo after 26.0 Fix from $1,9502026-03-23 MEDIUM 6.5 CVE-2026-33354 WWBN AVideo is an open source video platform. In versions up to and including 26.0, `POST /objects/aVideoEncoder.json.php` accepts a requester-contro… Avideo after 26.0 Fix from $1,6002026-03-23 CRITICAL 9.8 CVE-2026-33352 WWBN AVideo is an open source video platform. Prior to version 26.0, an unauthenticated SQL injection vulnerability exists in `objects/category.php` … Avideo 26.0+ Fix from $2,3002026-03-23 CRITICAL 9.1 CVE-2026-33297 WWBN AVideo is an open source video platform. Prior to version 26.0, the `setPassword.json.php` endpoint in the CustomizeUser plugin allows administr… Avideo 26.0+ Fix from $2,3002026-03-23 CRITICAL 9.1 CVE-2026-33351 WWBN AVideo is an open source video platform. Prior to version 26.0, a Server-Side Request Forgery (SSRF) vulnerability exists in `plugin/Live/standA… Avideo 26.0+ Fix from $2,3002026-03-23 HIGH 7.5 CVE-2026-33319 WWBN AVideo is an open source video platform. Prior to version 26.0, the `uploadVideoToLinkedIn()` method in the SocialMediaPublisher plugin construc… Avideo 26.0+ Fix from $1,9502026-03-22 MEDIUM 6.1 CVE-2026-33296 WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains an open redirect vulnerability in the login flow where a us… Avideo 26.0+ Fix from $1,6002026-03-22 MEDIUM 5.4 CVE-2026-33295 WWBN AVideo is an open source video platform. Prior to version 26.0, WWBN/AVideo contains a stored cross-site scripting vulnerability in the CDN plug… Avideo 26.0+ Fix from $1,6002026-03-22 HIGH 8.1 CVE-2026-33293 WWBN AVideo is an open source video platform. Prior to version 26.0, the `deleteDump` parameter in `plugin/CloneSite/cloneServer.json.php` is passed … Avideo 26.0+ Fix from $1,9502026-03-22 HIGH 7.5 CVE-2026-33292 WWBN AVideo is an open source video platform. Prior to version 26.0, the HLS streaming endpoint (`view/hls.php`) is vulnerable to a path traversal at… Avideo 26.0+ Fix from $1,9502026-03-22 MEDIUM 5.5 CVE-2026-33237 WWBN AVideo is an open source video platform. Prior to version 26.0, the Scheduler plugin's `run()` function in `plugin/Scheduler/Scheduler.php` call… Avideo 26.0+ Fix from $1,6002026-03-21 HIGH 8.6 CVE-2026-33039 WWBN AVideo is an open source video platform. In versions 25.0 and below, the plugin/LiveLinks/proxy.php endpoint validates user-supplied URLs agains… Avideo 26.0+ Fix from $1,9502026-03-20 HIGH 8.1 CVE-2026-33043 WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/phpsessionid.json.php exposes the current PHP session ID to any un… Avideo 26.0+ Fix from $1,9502026-03-20 MEDIUM 5.3 CVE-2026-33041 WWBN AVideo is an open source video platform. In versions 25.0 and below, /objects/encryptPass.json.php exposes the application's password hashing al… Avideo 26.0+ Fix from $1,6002026-03-20 HIGH 8.1 CVE-2026-33037 WWBN AVideo is an open source video platform. In versions 25.0 and below, the official Docker deployment files (docker-compose.yml, env.example) ship… Avideo 26.0+ Fix from $1,9502026-03-20 HIGH 8.1 CVE-2026-33038 WWBN AVideo is an open source video platform. Versions 25.0 and below are vulnerable to unauthenticated application takeover through the install/chec… Avideo 26.0+ Fix from $1,9502026-03-20 MEDIUM 6.1 CVE-2026-33035 WWBN AVideo is an open source video platform. In versions 25.0 and below, there is a reflected XSS vulnerability that allows unauthenticated attacker… Avideo 26.0+ Fix from $1,6002026-03-20 CRITICAL 9.1 CVE-2026-33024 AVideo is a video-sharing Platform. Versions prior to 8.0 contain a Server-Side Request Forgery vulnerability (CWE-918) in the public thumbnail endpo… Avideo Encoder 8.0+ Fix from $2,3002026-03-20 HIGH 8.8 CVE-2026-33025 AVideo is a video-sharing Platform. Versions prior to 8.0 contain a SQL Injection vulnerability in the getSqlFromPost() method of Object.php. The $_P… Avideo Encoder 8.0+ Fix from $1,9502026-03-20 MEDIUM 5.3 CVE-2026-30885 WWBN AVideo is an open source video platform. Prior to 25.0, the /objects/playlistsFromUser.json.php endpoint returns all playlists for any user with… Avideo 25.0+ Fix from $1,6002026-03-10 CRITICAL 9.8 CVE-2026-29058 AVideo is a video-sharing Platform software. Prior to version 7.0, an unauthenticated attacker can execute arbitrary OS commands on the server by inj… Avideo Encoder 7.0+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-28501 WWBN AVideo is an open source video platform. Prior to version 24.0, an unauthenticated SQL Injection vulnerability exists in AVideo within the objec… Avideo 24.0+ Fix from $2,3002026-03-06 CRITICAL 9.8 CVE-2026-29093 WWBN AVideo is an open source video platform. Prior to version 24.0, the official docker-compose.yml publishes the memcached service on host port 112… Avideo 24.0+ Fix from $2,3002026-03-06 HIGH 8.8 CVE-2026-28502 WWBN AVideo is an open source video platform. Prior to version 24.0, an authenticated Remote Code Execution (RCE) vulnerability was identified in AVi… Avideo 24.0+ Fix from $1,9502026-03-06 HIGH 8.1 CVE-2026-27732 WWBN AVideo is an open source video platform. Prior to version 22.0, the `aVideoEncoder.json.php` API endpoint accepts a `downloadURL` parameter and … Avideo 22.0+ Fix from $1,9502026-02-24 MEDIUM 6.1 CVE-2026-27568 WWBN AVideo is an open source video platform. Prior to version 21.0, AVideo allows Markdown in video comments and uses Parsedown (v1.7.4) without Saf… Avideo 21.0+ Fix from $1,6002026-02-24 HIGH 7.5 CVE-2020-37173 AVideo Platform 8.1 contains an information disclosure vulnerability that allows attackers to enumerate user details through the playlistsFromUser.js… Avideo No fix yet Fix from $1,9502026-02-11 CRITICAL 9.8 CVE-2020-37172 AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password reco… Avideo Mitigation only Fix from $2,3002026-02-11 HIGH 8.8 CVE-2020-37158 AVideo Platform 8.1 contains a cross-site request forgery vulnerability that allows attackers to reset user passwords by exploiting the password reco… Avideo No fix yet Fix from $1,9502026-02-11