Vulnerability index

Browse CVEs

183 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

MEDIUM 5.4 CVE-2023-47861 A cross-site scripting (xss) vulnerability exists in the channelBody.php user name functionality of WWBN AVideo 11.6 and dev master commit 15fed957fb… Avideo No fix yet Fix from $1,6002024-01-10 MEDIUM 5.4 CVE-2023-48730 A cross-site scripting (xss) vulnerability exists in the navbarMenuAndLogo.php user name functionality of WWBN AVideo dev master commit 15fed957fb. A… Avideo Mitigation only Fix from $1,6002024-01-10 HIGH 8.8 CVE-2023-32073EPSS 6% WWBN AVideo is an open source video platform. In versions 12.4 and prior, a command injection vulnerability exists at `plugin/CloneSite/cloneClient.j… Avideo after 12.4 Fix from $1,9502023-05-12 MEDIUM 5.4 CVE-2023-30860 WWBN AVideo is an open source video platform. In AVideo prior to version 12.4, a normal user can make a Meeting Schedule where the user can invite an… Avideo 12.4+ Fix from $1,6002023-05-08 HIGH 8.8 CVE-2023-30854EPSS 5% AVideo is an open source video platform. Prior to version 12.4, an OS Command Injection vulnerability in an authenticated endpoint `/plugin/CloneSite… Avideo 12.4+ Fix from $1,9502023-04-28 CRITICAL 9.8 CVE-2023-25313 OS injection vulnerability in World Wide Broadcast Network AVideo version before 12.4, allows attackers to execute arbitrary code via the video link … Avideo 12.4+ Fix from $2,3002023-04-25 MEDIUM 6.1 CVE-2023-25314 Cross Site Scripting (XSS) vulnerability in World Wide Broadcast Network AVideo before 12.4, allows attackers to gain sensitive information via the s… Avideo 12.4+ Fix from $1,6002023-04-25 HIGH 8.8 CVE-2022-30605 A privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted H… Avideo No fix yet Fix from $1,9502022-08-22 HIGH 8.8 CVE-2022-32282 An improper password check exists in the login functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. An attacker that owns a users' passw… Avideo No fix yet Fix from $1,9502022-08-22 HIGH 8.8 CVE-2022-32572EPSS 23% An os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-… Avideo No fix yet Fix from $1,9502022-08-22 HIGH 8.8 CVE-2022-33147 A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP requ… Avideo No fix yet Fix from $1,9502022-08-22 HIGH 8.8 CVE-2022-33148 A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP requ… Avideo Mitigation only Fix from $1,9502022-08-22 HIGH 8.8 CVE-2022-33149 A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP requ… Avideo Mitigation only Fix from $1,9502022-08-22 HIGH 8.8 CVE-2022-34652 A sql injection vulnerability exists in the ObjectYPT functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP requ… Avideo Mitigation only Fix from $1,9502022-08-22 HIGH 7.5 CVE-2022-32777 An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and… Avideo Mitigation only Fix from $1,9502022-08-22 HIGH 7.5 CVE-2022-32778 An information disclosure vulnerability exists in the cookie functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. The session cookie and… Avideo Mitigation only Fix from $1,9502022-08-22 MEDIUM 6.5 CVE-2022-32761 An information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A s… Avideo No fix yet Fix from $1,6002022-08-22 MEDIUM 6.1 CVE-2022-30690EPSS 84% A cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-craft… Avideo No fix yet Fix from $1,6002022-08-22 MEDIUM 6.1 CVE-2022-32770 A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-… Avideo Mitigation only Fix from $1,6002022-08-22 MEDIUM 6.1 CVE-2022-32771 A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-… Avideo Mitigation only Fix from $1,6002022-08-22 MEDIUM 6.1 CVE-2022-32772 A cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-… Avideo Mitigation only Fix from $1,6002022-08-22 MEDIUM 5.0 CVE-2022-32769 Multiple authentication bypass vulnerabilities exist in the objects id handling functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A s… Avideo Mitigation only Fix from $1,6002022-08-22 CRITICAL 9.9 CVE-2022-30547EPSS 64% A directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafte… Avideo No fix yet Fix from $2,3002022-08-22 CRITICAL 9.6 CVE-2022-26842 A reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master commit 3f7c0… Avideo No fix yet Fix from $2,3002022-08-22 CRITICAL 9.0 CVE-2022-28712 A cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-cr… Avideo No fix yet Fix from $2,3002022-08-22 HIGH 8.8 CVE-2022-29468 A cross-site request forgery (CSRF) vulnerability exists in WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted HTTP request can lea… Avideo No fix yet Fix from $1,9502022-08-22 HIGH 8.8 CVE-2022-30534EPSS 74% An OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A speci… Avideo Mitigation only Fix from $1,9502022-08-22 MEDIUM 6.5 CVE-2022-28710 An information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-crafted… Avideo No fix yet Fix from $1,6002022-08-22 MEDIUM 6.1 CVE-2022-27462 Cross Site Scripting (XSS) vulnerability in objects/function.php in function getDeviceID in WWBN AVideo through 11.6, via the yptDevice parameter to … Avideo after 11.6 Fix from $1,6002022-04-05 MEDIUM 6.1 CVE-2022-27463 Open redirect vulnerability in objects/login.json.php in WWBN AVideo through 11.6, allows attackers to arbitrarily redirect users from a crafted url … Avideo after 11.6 Fix from $1,6002022-04-05