Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 8.8 CVE-2025-34436 AVideo versions prior to 20.1 allow any authenticated user to upload files into directories belonging to other users due to an insecure direct object… Avideo 20.0+ Fix from $1,9502025-12-17 HIGH 8.8 CVE-2025-34437 AVideo versions prior to 20.1 permit any authenticated user to upload comment images to videos owned by other users. The endpoint validates authentic… Avideo 20.0+ Fix from $1,9502025-12-17 HIGH 8.1 CVE-2025-34438 AVideo versions prior to 20.1 contain an insecure direct object reference vulnerability allowing users with upload permissions to modify the rotation… Avideo 20.0+ Fix from $1,9502025-12-17 HIGH 7.5 CVE-2025-34441 AVideo versions prior to 20.1 expose sensitive user information through an unauthenticated public API endpoint. Responses include emails, usernames, … Avideo 20.0+ Fix from $1,9502025-12-17 HIGH 7.5 CVE-2025-34442 AVideo versions prior to 20.1 disclose absolute filesystem paths via multiple public API endpoints. Returned metadata includes full server paths to m… Avideo 20.0+ Fix from $1,9502025-12-17 MEDIUM 6.1 CVE-2025-34439 AVideo versions prior to 20.1 are vulnerable to an open redirect flaw due to missing validation of the cancelUri parameter during user login. An atta… Avideo 20.0+ Fix from $1,6002025-12-17 MEDIUM 6.1 CVE-2025-34440 AVideo versions prior to 20.1 contain an open redirect vulnerability caused by insufficient validation of the siteRedirectUri parameter during user r… Avideo 20.0+ Fix from $1,6002025-12-17 CRITICAL 9.1 CVE-2025-34434 AVideo versions prior to 20.1 with the ImageGallery plugin enabled is vulnerable to unauthenticated file upload and deletion. Plugin endpoints respon… Avideo 20.0+ Fix from $2,3002025-12-17 MEDIUM 6.5 CVE-2025-34435 AVideo versions prior to 20.1 are vulnerable to an insecure direct object reference (IDOR) that allows any authenticated user to delete media files b… Avideo 20.0+ Fix from $1,6002025-12-17 CRITICAL 9.8 CVE-2025-48732 An incomplete blacklist exists in the .htaccess sample of WWBN AVideo 14.4 and dev master commit 8a8954ff. A specially crafted HTTP request can lead … Avideo Mitigation only Fix from $2,3002025-07-24 MEDIUM 6.1 CVE-2025-50128 A cross-site scripting (xss) vulnerability exists in the videoNotFound 404ErrorMsg parameter functionality of WWBN AVideo 14.4 and dev master commit … Avideo No fix yet Fix from $1,6002025-07-24 MEDIUM 6.1 CVE-2025-53084 A cross-site scripting (xss) vulnerability exists in the videosList page parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. … Avideo No fix yet Fix from $1,6002025-07-24 CRITICAL 9.6 CVE-2025-36548 A cross-site scripting (xss) vulnerability exists in the LoginWordPress loginForm cancelUri parameter functionality of WWBN AVideo 14.4 and dev maste… Avideo No fix yet Fix from $2,3002025-07-24 CRITICAL 9.6 CVE-2025-41420 A cross-site scripting (xss) vulnerability exists in the userLogin cancelUri parameter functionality of WWBN AVideo 14.4 and dev master commit 8a8954… Avideo No fix yet Fix from $2,3002025-07-24 MEDIUM 6.1 CVE-2025-46410 A cross-site scripting (xss) vulnerability exists in the managerPlaylists PlaylistOwnerUsersId parameter functionality of WWBN AVideo 14.4 and dev ma… Avideo No fix yet Fix from $1,6002025-07-24 HIGH 7.5 CVE-2025-25214 A race condition vulnerability exists in the aVideoEncoder.json.php unzip functionality of WWBN AVideo 14.4 and dev master commit 8a8954ff. A series … Avideo No fix yet Fix from $1,9502025-07-24 MEDIUM 5.4 CVE-2024-34899 WWBN AVideo 12.4 is vulnerable to Cross Site Scripting (XSS). Avideo after 12.4 Fix from $1,6002024-05-14 CRITICAL 9.8 CVE-2024-31819EPSS 16% An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.… Avideo after 14.2 Fix from $2,3002024-04-10 MEDIUM 6.5 CVE-2023-49863 An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit … Avideo No fix yet Fix from $1,6002024-01-10 MEDIUM 6.5 CVE-2023-49864 An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit … Avideo No fix yet Fix from $1,6002024-01-10 MEDIUM 5.3 CVE-2023-50172 A recovery notification bypass vulnerability exists in the userRecoverPass.php captcha validation functionality of WWBN AVideo dev master commit 15fe… Avideo No fix yet Fix from $1,6002024-01-10 CRITICAL 9.8 CVE-2023-49599 An insufficient entropy vulnerability exists in the salt generation functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted se… Avideo No fix yet Fix from $2,3002024-01-10 HIGH 8.8 CVE-2023-49589 An insufficient entropy vulnerability exists in the userRecoverPass.php recoverPass generation functionality of WWBN AVideo dev master commit 15fed95… Avideo No fix yet Fix from $1,9502024-01-10 HIGH 8.8 CVE-2023-49715 A unrestricted php file upload vulnerability exists in the import.json.php temporary copy functionality of WWBN AVideo dev master commit 15fed957fb. … Avideo No fix yet Fix from $1,9502024-01-10 HIGH 7.5 CVE-2023-49738 An information disclosure vulnerability exists in the image404Raw.php functionality of WWBN AVideo dev master commit 15fed957fb. A specially crafted … Avideo No fix yet Fix from $1,9502024-01-10 MEDIUM 6.5 CVE-2023-49810 A login attempt restriction bypass vulnerability exists in the checkLoginAttempts functionality of WWBN AVideo dev master commit 15fed957fb. A specia… Avideo No fix yet Fix from $1,6002024-01-10 MEDIUM 6.5 CVE-2023-49862 An information disclosure vulnerability exists in the aVideoEncoderReceiveImage.json.php image upload functionality of WWBN AVideo dev master commit … Avideo No fix yet Fix from $1,6002024-01-10 CRITICAL 9.8 CVE-2023-47862 A local file inclusion vulnerability exists in the getLanguageFromBrowser functionality of WWBN AVideo dev master commit 15fed957fb. A specially craf… Avideo Mitigation only Fix from $2,3002024-01-10 MEDIUM 6.5 CVE-2023-47171 An information disclosure vulnerability exists in the aVideoEncoder.json.php chunkFile path functionality of WWBN AVideo 11.6 and dev master commit 1… Avideo No fix yet Fix from $1,6002024-01-10 MEDIUM 6.1 CVE-2023-48728 A cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master commit 3c6bb… Avideo No fix yet Fix from $1,6002024-01-10