Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2000 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.26% | — | Wwbn AvideoAI | 12/9/2026 | 14/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the videoAddViewCount.json.php endpoint before updating view statistics. Authenticated attackers can increment view counts and watch-time on videos they cannot access by submitting requests with arbitrary… | |
| Aplazada | Media (6.9) | 0.60% | — | Wwbn AvideoAI | 12/9/2026 | 14/9/2026 | WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier, with the Live plugin enabled, contains a missing authentication vulnerability in plugin/Live/socketMessageLiveOwner.json.php. The script reads the `key` and `msg` parameters from $_REQUEST, resolves the stream owner via… | |
| Aplazada | Media (5.3) | 0.24% | — | Wwbn AvideoAI | 12/9/2026 | 15/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate that logged-in users can access live schedules before creating reminders via remindMe.json.php. Authenticated attackers can create scheduler reminders for private live schedules they cannot view and learn the private schedule title… | |
| Aplazada | Media (5.3) | 0.26% | — | Wwbn AvideoAI | 12/9/2026 | 14/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate watch permissions in the playListAddVideo.json.php endpoint when adding videos to playlists. Authenticated attackers can add password-protected videos they cannot watch to playlists they own by submitting the video ID and playlist ID… | |
| Aplazada | Media (6.9) | 0.41% | — | Wwbn AvideoAI | 12/9/2026 | 14/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authentication vulnerability in the plugin/TopMenu/menuItems.json.php endpoint that allows unauthenticated attackers to read inactive admin menu items by submitting a POST request with a menuId parameter. Attackers can retrieve… | |
| Aplazada | Media (6.9) | 0.36% | — | Wwbn AvideoAI | 12/9/2026 | 14/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in playlistsFromUser.json.php that allows unauthenticated attackers to read private playlists by requesting another user's identifier. Attackers can retrieve Favorite and Watch Later playlists belonging… | |
| Aplazada | Alta (8.8) | 0.36% | — | Wwbn AvideoAI | 12/9/2026 | 15/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/Scheduler/sendEmail.json.php that allows unauthenticated attackers to access scheduler email jobs by providing a site-wide daily token. Attackers can enumerate scheduler jobs, read private live… | |
| Aplazada | Media (6.9) | 0.40% | — | Wwbn AvideoAI | 12/9/2026 | 21/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate playlist ownership in the video_from_program API endpoint, allowing unauthenticated access to private playlist contents. Attackers can query the API without authentication to enumerate private playlist names, owner information, and… | |
| Aplazada | Media (5.3) | 0.36% | — | Wwbn AvideoAI | 12/9/2026 | 21/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate video access permissions in the like.json.php endpoint, allowing logged-in users to record likes on password-protected and group-restricted videos. Attackers can submit like requests for videos they cannot watch to increment like… | |
| Aplazada | Media (6.9) | 0.41% | — | Wwbn AvideoAI | 12/9/2026 | 19/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to require authentication in the plugin/TopMenu/menus.json.php endpoint, allowing unauthenticated attackers to retrieve all menu data. Attackers can send GET requests to the endpoint to read inactive and admin-only menu names that are not… | |
| Aplazada | Media (6.9) | 0.41% | — | Wwbn AvideoAI | 12/9/2026 | 21/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to authorize access to the adsInfo API endpoint, allowing unauthenticated attackers to retrieve password-protected video owner identifiers. Attackers can call the adsInfo API with a videos_id parameter to obtain the owner's user ID and… | |
| Aplazada | Media (5.3) | 0.30% | — | Wwbn AvideoAI | 11/9/2026 | 15/9/2026 | AVideo through 29.0 contains an insecure direct object reference (IDOR) vulnerability in objects/categoryDeleteAssets.json.php. The endpoint validates only the Category::canCreateCategory() capability and a CSRF nonce before passing the attacker-supplied $_REQUEST['id'] to Category::deleteAssets(), which recursively… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Wwbn AvideoAI | 11/9/2026 | 11/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the Bookmark plugin where chapter names are not encoded before being concatenated into public watch-page HTML. A video owner can inject malicious scripts via the bookmark name parameter, and every… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Avideo LogincontrolAIWwbn AvideoAI | 11/9/2026 | 11/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated attacker can inject malicious JavaScript by submitting a crafted public key, which… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Avideo Customize UserAIWwbn AvideoAI | 11/9/2026 | 11/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored raw without sanitization. Administrators can inject malicious scripts via the add.json.php endpoint that execute when viewing extra… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Wwbn AvideoAI | 11/9/2026 | 11/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the user 'donationLink' profile field. User::setDonationLink() (objects/user.php) stores the value and save() validates it only with filter_var(..., FILTER_VALIDATE_URL), which accepts strings… | |
| Aplazada | Alta (7.1) | 0.31% | — | Wwbn AvideoAI | 11/9/2026 | 15/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to verify ownership in addLiveLink.php when updating LiveLinks, allowing authenticated users to modify other users' links. A canStream user can overwrite another user's LiveLink HLS source and metadata by supplying an existing linkId, redirecting… | |
| Aplazada | Alta (7.1) | 0.18% | — | Wwbn AvideoAI | 11/9/2026 | 11/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate ad impressions in plugin/AD_Server/log.php, allowing logged-in users to submit arbitrary label values that trigger unverified wallet credits to campaign video owners. Attackers can repeatedly POST label=start requests to mint YPTWallet… | |
| Aplazada | Alta (8.7) | 0.50% | — | Wwbn AvideoAI | 11/9/2026 | 11/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files from the temporary directory. Attackers can request the endpoint with a known or guessed stream key to download recorded live video… | |
| Aplazada | Crítica (9.3) | 0.37% | — | YptwalletAIWwbn AvideoAI | 11/9/2026 | 11/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the YPTWallet plugin where user-supplied CryptoWallet values are base64-encoded but not HTML-escaped before storage in wallet_log.information. Administrators viewing pending withdrawal requests in… | |
| Aplazada | Media (6.9) | 0.50% | — | Wwbn AvideoAI | 11/9/2026 | 11/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 is missing an authentication/authorization check in plugin/WebRTC/status.json.php. When the WebRTC plugin is present, any unauthenticated remote user can request /plugin/WebRTC/status.json.php and receive JSON containing the absolute filesystem path of the… | |
| Aplazada | Media (5.3) | 0.36% | — | Wwbn AvideoAI | 11/9/2026 | 15/9/2026 | WWBN AVideo at commit c3edcc274c389816d434acadac07ee78eaf330c1 and earlier contains an XML injection vulnerability in plugin/AD_Server/VMAP.php, which is reachable without authentication when the AD_Server plugin is enabled. The script emits Content-Type: application/xml and writes the timeOffset and idTag values… | |
| Aplazada | Media (5.1) | 0.24% | — | Wwbn AvideoAI | 11/9/2026 | 11/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a CSV formula injection vulnerability in the myComments.download.php endpoint that fails to sanitize spreadsheet formula prefixes in comment text. Authenticated users can inject formulas starting with =, +, -, or @ characters that execute… | |
| Aplazada | Alta (7.1) | 0.17% | — | Wwbn AvideoAI | 11/9/2026 | 11/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in playlistRemove.php that allows attackers to delete playlists by skipping CSRF protection checks. Attackers can craft a malicious form that submits a POST request to playlistRemove.php, causing a… | |
| Aplazada | Media (5.3) | 0.26% | — | Wwbn AvideoAI | 11/9/2026 | 11/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Gallery/view/Category.php when SubCategorys is enabled. The getBackURL parameter is echoed into an href attribute without HTML encoding, allowing attackers to inject malicious scripts… |