Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1999 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.17% | — | Rareprob Video Player | 31/3/2026 | 24/7/2026 | An arbitrary file overwrite vulnerability in RAREPROB SOLUTIONS PRIVATE LIMITED Video player Play All Videos v1.0.135 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure. | |
| Analizada | Alta (8.2) | 0.34% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the YPTWallet Stripe payment confirmation page directly echoes the `$_REQUEST['plugin']` parameter into a JavaScript block without any encoding or sanitization. The `plugin` parameter is not included in any of the framework's input… | |
| Analizada | Crítica (9.1) | 0.50% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Live_schedule::keyExists()` method constructs a SQL query by interpolating a stream key directly into the query string without parameterization. This method is called as a fallback from `LiveTransmition::keyExists()` when the… | |
| Analizada | Media (5.3) | 0.38% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_file` and `get_api_video` API endpoints in AVideo return full video playback sources (direct MP4 URLs, HLS manifests) for password-protected videos without verifying the video password. While the normal web playback… | |
| Analizada | Media (5.3) | 0.25% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `transferBalance()` method in `plugin/YPTWallet/YPTWallet.php` contains a Time-of-Check-Time-of-Use (TOCTOU) race condition. The method reads the sender's wallet balance, checks sufficiency in PHP, then writes the new balance — all… | |
| Analizada | Media (5.3) | 0.34% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `categories.json.php` endpoint, which serves the category listing API, fails to enforce user group-based access controls on categories. In the default request path (no `?user=` parameter), user group filtering is entirely skipped,… | |
| Analizada | Media (5.4) | 0.27% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `verifyTokenSocket()` function in `plugin/YPTSocket/functions.php` has its token timeout validation commented out, causing WebSocket tokens to never expire despite being generated with a 12-hour timeout. This allows captured or… | |
| Analizada | Media (5.4) | 0.27% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/Live/uploadPoster.php` endpoint allows any authenticated user to overwrite the poster image for any scheduled live stream by supplying an arbitrary `live_schedule_id`. The endpoint only checks `User::isLogged()` but never… | |
| Analizada | Media (6.3) | 0.28% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `plugin/PlayLists/View/Playlists_schedules/add.json.php` endpoint allows any authenticated user with streaming permission to create or modify broadcast schedules targeting any playlist on the platform, regardless of ownership. When… | |
| Analizada | Crítica (9.1) | 0.16% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, AVideo allows content owners to password-protect individual videos. The video password is stored in the database in plaintext — no hashing, salting, or encryption is applied. If an attacker gains read access to the database (via SQL… | |
| Analizada | Alta (7.1) | 0.60% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `fixCleanTitle()` static method in `objects/category.php` constructs a SQL SELECT query by directly interpolating both `$clean_title` and `$id` into the query string without using prepared statements or parameterized queries. An… | |
| Analizada | Alta (7.1) | 0.60% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, in `objects/like.php`, the `getLike()` method constructs a SQL query using a prepared statement placeholder (`?`) for `users_id` but directly concatenates `$this->videos_id` into the query string without parameterization. An attacker… | |
| Analizada | Media (5.3) | 0.32% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, `isSSRFSafeURL()` validates URLs against private/reserved IP ranges before fetching, but `url_get_contents()` follows HTTP redirects without re-validating the redirect target. An attacker can bypass SSRF protection by redirecting from… | |
| Analizada | Media (4.3) | 0.29% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the AI plugin's `save.json.php` endpoint loads AI response objects using an attacker-controlled `$_REQUEST['id']` parameter without validating that the AI response belongs to the specified video. An authenticated user with AI… | |
| Analizada | Media (5.3) | 0.43% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `get_api_video_password_is_correct` API endpoint allows any unauthenticated user to verify whether a given password is correct for any password-protected video. The endpoint returns a boolean `passwordIsCorrect` field with no rate… | |
| Analizada | Media (5.3) | 0.43% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, three `list.json.php` endpoints in the Scheduler plugin lack any authentication check, while every other endpoint in the same plugin directories (`add.json.php`, `delete.json.php`, `index.php`) requires `User::isAdmin()`. An… | |
| Analizada | Media (5.3) | 0.41% | — | Wwbn Avideo | 27/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `objects/playlistsVideos.json.php` endpoint returns the full video contents of any playlist by ID without any authentication or authorization check. Private playlists (including `watch_later` and `favorite` types) are correctly… | |
| Aplazada | Media (6.9) | 0.18% | — | Myvideoconverter PROAI | 26/3/2026 | 17/6/2026 | MyVideoConverter Pro 3.14 contains a local buffer overflow vulnerability that allows attackers to crash the application by supplying an excessively long string to the registration code input field. Attackers can paste a malicious payload containing 10000 bytes into the 'Copy and Paste Registration Code' field to… | |
| Analizada | Alta (8.5) | 0.26% | — | Alloksoft Video Splitter | 26/3/2026 | 17/6/2026 | Allok Video Splitter 3.1.1217 contains a buffer overflow vulnerability that allows local attackers to cause a denial of service or execute arbitrary code by supplying an oversized string in the License Name field. Attackers can craft a malicious payload exceeding 780 bytes, paste it into the License Name registration… | |
| Pendiente de análisis | Alta (8.8) | 0.27% | — | Asp.net Jvideo KITAI | 26/3/2026 | 17/6/2026 | ASP.NET jVideo Kit 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to inject SQL commands through the 'query' parameter in the search functionality. Attackers can submit malicious SQL payloads via GET or POST requests to the /search endpoint to extract sensitive database information… | |
| Analizada | Media (6.9) | 0.23% | — | Direct-soft Winmpg Video Convert | 24/3/2026 | 17/6/2026 | WinMPG Video Convert 9.3.5 and older versions contain a buffer overflow vulnerability in the registration dialog that allows local attackers to crash the application by supplying oversized input. Attackers can paste a large payload of 6000 bytes into the Name and Registration Code field to trigger a denial of service… | |
| Analizada | Media (6.5) | 0.22% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `Subscribe::save()` method in `objects/subscribe.php` concatenates the `$this->users_id` property directly into an INSERT SQL query without sanitization or parameterized binding. This property originates from `$_POST['user_id']` in… | |
| Analizada | Alta (8.6) | 0.49% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the CDN plugin endpoints `plugin/CDN/status.json.php` and `plugin/CDN/disable.json.php` use key-based authentication with an empty string default key. When the CDN plugin is enabled but the key has not been configured (the default… | |
| Analizada | Alta (8.8) | 0.55% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the `downloadVideoFromDownloadURL()` function in `objects/aVideoEncoder.json.php` saves remote content to a web-accessible temporary directory using the original URL's filename and extension (including `.php`). By providing an invalid… | |
| Analizada | Crítica (9.4) | 0.57% | — | Wwbn Avideo | 23/3/2026 | 17/6/2026 | WWBN AVideo is an open source video platform. In versions up to and including 26.0, the standalone live stream control endpoint at `plugin/Live/standAloneFiles/control.json.php` accepts a user-supplied `streamerURL` parameter that overrides where the server sends token verification requests. An attacker can redirect… |