Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
2000 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.26% | — | DatatablesAIWwbn AvideoAI | 16/9/2026 | 22/9/2026 | AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which writes the caller's User-Agent (via getUserAgentInfo(), which returns unrecognized agent strings… | |
| Aplazada | Media (6.9) | 0.30% | — | Wwbn AvideoAI | 16/9/2026 | 22/9/2026 | AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protection by issuing concurrent requests. Attackers can submit parallel credential attempts to exceed the… | |
| Aplazada | Alta (7.1) | 0.18% | — | Wwbn AvideoAI | 16/9/2026 | 22/9/2026 | AVideo (WWBN/AVideo) through 29.0 (commit e01e41ecc) is vulnerable to cross-site request forgery. objects/videoAddNew.json.php disables AVideo's automatic CSRF guard ($global['skipAutoCSRFCheck']) and the untrusted-request check ($global['bypassSameDomainCheck']) merely because 'user' and 'pass' parameters are present… | |
| Aplazada | Media (5.3) | 0.29% | — | Wwbn AvideoAI | 16/9/2026 | 22/9/2026 | In AVideo through 29.0, Like::__construct() performs counter arithmetic on raw request values before validation, allowing array-typed parameters to desynchronize stored votes from counters. Authenticated attackers can send array-typed like parameters followed by ordinary requests to drive video like counts arbitrarily… | |
| Aplazada | Alta (8.7) | 1.4% | — | Wwbn AvideoAI | 16/9/2026 | 22/9/2026 | In AVideo through 29.0, the CloneSite plugin is vulnerable to stored OS command injection. In plugin/CloneSite/cloneClient.json.php (line ~270) the stored SSH password is substituted into the command string `sshpass -p '{password}' rsync ...` with a plain str_replace and no escaping, so a single quote in the password… | |
| Aplazada | Media (5.3) | 0.27% | — | LoginwordpressAIWwbn AvideoAI | 16/9/2026 | 22/9/2026 | In AVideo through 29.0, the autoCSRFGuard() function maintains a hardcoded allowlist of exempt basenames tested without directory context, allowing plugin files matching core filenames to inherit CSRF exemptions. The LoginWordPress plugin file login.json.php inherits an exemption and unconditionally logs out… | |
| Aplazada | Crítica (9.2) | 0.62% | — | Wwbn AvideoAI | 16/9/2026 | 22/9/2026 | WWBN AVideo through 29.0 contains an authentication bypass vulnerability where the stored password hash is accepted as a valid login credential through two independent code paths in loginFromRequest() and encryptPasswordVerify(). Attackers who obtain the stored users.password hash value can authenticate as any user by… | |
| Aplazada | Alta (8.7) | 0.43% | — | Wwbn AvideoAI | 16/9/2026 | 22/9/2026 | In AVideo through 29.0, the API get_api_video endpoint contains a broken access control vulnerability in the clean_title branch that returns user-group-restricted videos with owner PII to anonymous callers. Attackers can query videos by their public slug to bypass group restrictions and retrieve sensitive user fields… | |
| En análisis | Media (6.5) | 0.55% | — | VllmAINvidia PynvvideocodecAI | 16/9/2026 | 30/9/2026 | vLLM is an inference and serving engine for large language models. Prior to 0.28.0, request bodies for Chat Completions and Responses can set media_io_kwargs.video.video_backend to pynvvideocodec, and MediaConnector.fetch_video forwards that choice to VideoMediaIO even when startup configuration selected a software… | |
| Aplazada | Alta (7.5) | 1.7% | 💥 Exploit | C-mor Video SurveillanceAI | 15/9/2026 | 22/9/2026 | The C-MOR Video Surveillance web interface (up to version 6.0104) is vulnerable to Path Traversal via the 'cam' parameter in show-movies.pml. | |
| Aplazada | Media (6.1) | 0.91% | 💥 Exploit | C-mor Video SurveillanceAI | 15/9/2026 | 22/9/2026 | Cross Site Scripting vulnerability in za-internet GmbH C-MOR Video Surveillance <= V6.0104 allows a remote attacker to execute arbitrary code via the size parameter in ptzpreset.pml component and the showmovies.pml component | |
| Aplazada | Media (5.3) | 0.34% | — | Wwbn AvideoAI | 15/9/2026 | 17/9/2026 | AVideo through 29.0 contains a blind server-side request forgery vulnerability in the getHeaderContentTypeFromURL function that issues get_headers() calls guarded only by format validation. Authenticated users with canUpload permission can store attacker-chosen URLs as video links, triggering vulnerable function… | |
| Aplazada | Alta (8.7) | 0.45% | — | Wwbn AvideoAI | 15/9/2026 | 16/9/2026 | WWBN AVideo through 29.0 fails to enforce user-group restrictions in the plugin/Live/stats.json.php and plugin/Live/calendar.json.php endpoints. Unauthenticated attackers can retrieve restricted live transmission details including stream keys, titles, descriptions, owner information, and direct HLS playback URLs by… | |
| Aplazada | Alta (7.5) | 0.49% | — | Mediawiki EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, with the default $wgEmbedVideoRequireConsent configuration enabled, includes/EmbedService/EmbedHtmlFormatter.php places JSON… | |
| Aplazada | Alta (8.6) | 0.48% | — | Mediawiki EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedHtmlFormatter::toHtml in includes/EmbedService/EmbedHtmlFormatter.php passes the user-supplied class value directly to… | |
| Aplazada | Alta (7.5) | 0.49% | — | Star-citizen EmbedvideoAI | 15/9/2026 | 30/9/2026 | The EmbedVideo Extension is a MediaWiki extension which adds a parser function called #ev and various parser tags for embedding video clips from various video sharing services. Prior to 4.1.0, EmbedServiceFactory::newFromName in includes/EmbedService/EmbedServiceFactory.php interpolates an attacker-controlled unknown… | |
| Aplazada | Media (6.9) | 0.40% | — | Wwbn AvideoAI | 15/9/2026 | 19/9/2026 | AVideo through 29.0 contains an unauthenticated server-side request forgery vulnerability in the check_site_availability function that accepts attacker-controlled HTTP Host headers. Attackers can send requests to submitIndex.php or ajax.php with arbitrary Host headers to probe internal network hosts and ports,… | |
| Aplazada | Media (6.9) | 0.42% | — | Next-videoAI | 14/9/2026 | 30/9/2026 | next-video is a library for adding video to Next.js applications. Prior to 2.8.1, the GET endpoint exported by next-video/request-handler and commonly mounted at /api/video accepts an unauthenticated url query parameter, while src/utils/utils.ts isRemote() treats any value without an HTTP or HTTPS prefix as a local… | |
| Pendiente de análisis | Baja (2.3) | 0.29% | — | Triplelift Video-bundle.jsAI | 14/9/2026 | 24/9/2026 | TripleLift's ad rendering script (video-bundle.js) contains a DOM-based cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a publisher's domain by sending crafted postMessage payloads without origin validation. Attackers can cause a victim to visit an… | |
| Aplazada | Media (5.3) | 0.36% | — | Wwbn AvideoAI | 12/9/2026 | 15/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the Playlists_schedules/list.json.php and Live/calendar.json.php endpoints, allowing authenticated and unauthenticated users to read private playlist schedule metadata. Attackers with canStream privileges or no… | |
| Aplazada | Media (6.9) | 0.41% | — | Wwbn AvideoAI | 12/9/2026 | 14/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to check user authorization in the PlayerSkins mediaSession.json.php endpoint before returning video metadata. Unauthenticated attackers can request the endpoint with a video ID parameter to retrieve password-protected video titles and owner… | |
| Aplazada | Media (6.9) | 0.34% | — | Wwbn AvideoAI | 12/9/2026 | 14/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to properly authorize access to the videosAndroid.json.php endpoint, allowing unauthenticated guests to list password-protected videos with sensitive owner information. Attackers can retrieve video metadata including owner email, lastLogin,… | |
| Aplazada | Media (6.9) | 0.40% | — | Wwbn AvideoAI | 12/9/2026 | 14/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the ImageGallery list.json.php endpoint, allowing unauthenticated access to list gallery files. Attackers can retrieve filenames and URLs of password-protected image galleries by directly accessing the endpoint,… | |
| Aplazada | Media (6.9) | 0.41% | — | Wwbn AvideoAI | 12/9/2026 | 15/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate user permissions in the Bookmark plugin getBookmarks.json.php endpoint, allowing unauthenticated attackers to read chapter names from password-protected videos. Attackers can query the endpoint with a video ID parameter to retrieve… | |
| Aplazada | Media (5.3) | 0.29% | — | Wwbn AvideoAI | 12/9/2026 | 14/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the commentAddNew.json.php endpoint, allowing authenticated users to post comments on password-protected and group-restricted videos. Attackers can submit POST requests with a valid session to add comments… |