Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
2000 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.38% | — | Wwbn AvideoAI | 11/9/2026 | 11/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in UserGroups::setGroup_name() that fails to sanitize group_name input. Administrators with canAdminUserGroups permission can inject malicious HTML and JavaScript that executes in the browser when… | |
| Aplazada | Media (6.9) | 0.28% | — | Wwbn AvideoAI | 11/9/2026 | 15/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a server-side request forgery vulnerability in the _json_decode function that fetches remote URLs and local file paths without SSRF validation. Unauthenticated attackers can POST file paths or HTTP URLs to login.json.php to read local files… | |
| Aplazada | Media (5.3) | 0.26% | — | Wwbn AvideoAI | 11/9/2026 | 11/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in confirmLivePassword.php that copies REQUEST_URI into a form action attribute without encoding. Attackers can craft a malicious URL with a quote character to break out of the action attribute… | |
| Aplazada | Media (5.3) | 0.31% | — | Wwbn AvideoAI | 11/9/2026 | 11/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in plugin/Live/confirmLivePassword.php. The script interpolates the unauthenticated GET parameter u (which is not covered by $securityFilter) directly into an <img src="..."> attribute without… | |
| Aplazada | Media (5.3) | 0.26% | — | Wwbn AvideoAI | 11/9/2026 | 11/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a reflected cross-site scripting vulnerability in the showAlertMessage() function that inserts the raw Referer header into a JavaScript comment without encoding. Attackers can craft a Referer header containing */ to close the comment and… | |
| Aplazada | Media (5.1) | 0.16% | — | Wwbn AvideoAI | 11/9/2026 | 11/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an open redirect in objects/playlistSort.php. Because the endpoint is not a *.json.php script, AVideo's automatic CSRF guard (autoCSRFGuard()/forbidIfIsUntrustedRequest()) does not run, and when the request includes the sort parameter the script… | |
| Aplazada | Media (6.9) | 0.54% | — | Kingdom Communication Associated Smart Video Intercom SystemAI | 11/9/2026 | 11/9/2026 | Smart Video Intercom System developed by Kingdom Communication Associated has a Client-Side Authentication vulnerability. Unauthenticated remote attackers can bypass authentication to access specific pages and obtain partial system configuration values. | |
| Aplazada | Alta (8.7) | 0.51% | — | Kingdom Communication Associated Smart Video Intercom SystemAI | 11/9/2026 | 11/9/2026 | Smart Video Intercom System developed by Kingdom Communication Associated has a Missing Brute-force Protection vulnerability. Unauthenticated remote attackers can gain access to valid accounts through a large number of login attempts. | |
| Aplazada | Media (6.9) | 0.44% | — | Kingdom Communication Associated Smart Video Intercom SystemAI | 11/9/2026 | 11/9/2026 | Smart Video Intercom System developed by Kingdom Communication Associated has a Sensitive Data Exposure vulnerability. Unauthenticated remote attackers can enumerate valid user accounts by exploiting differences in system responses. | |
| Aplazada | Alta (8.7) | 0.44% | — | Wwbn AvideoAI | 10/9/2026 | 15/9/2026 | AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 contains a missing authorization vulnerability in plugin/PlayerSkins/seo.php that allows unauthenticated attackers to access password-protected video sources by calling getSources() without password validation. Attackers can request the seo.php endpoint… | |
| Aplazada | Alta (8.7) | 0.55% | — | Wwbn AvideoAI | 10/9/2026 | 10/9/2026 | AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) does not enforce the Live stream password check on the stats endpoint or on the HLS origin. Live::_getStats() (plugin/Live/Live.php) returns a password-protected transmission's RTMP stream key, its isPasswordProtected flag, and its… | |
| Aplazada | Alta (7.1) | 0.18% | — | Wwbn AvideoAI | 10/9/2026 | 10/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in view/logArchive.json.php that allows unauthenticated attackers to archive application logs by making GET requests without CSRF token validation. Attackers can craft malicious pages that trigger… | |
| Aplazada | Alta (7.1) | 0.19% | — | Wwbn AvideoAI | 10/9/2026 | 10/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the setPassword.json.php endpoint that allows unauthenticated attackers to modify any user's channel password by sending a GET request. Attackers can craft a malicious webpage that, when visited by an… | |
| Aplazada | Media (5.3) | 0.18% | — | Wwbn AvideoAI | 10/9/2026 | 15/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) contains a cross-site request forgery vulnerability in the CustomizeUser plugin's plugin/CustomizeUser/setSubscribers.json.php endpoint. The script reads users_id and ExtraSubscribers from $_REQUEST and calls… | |
| Aplazada | Crítica (9.3) | 0.53% | — | Avideo AD ServerAIWwbn AvideoAI | 10/9/2026 | 10/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the AD_Server plugin's log.php endpoint that fails to escape the label parameter before storage. An unauthenticated attacker can inject malicious HTML through the label parameter, which is later… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Avideo LivelinksAIWwbn AvideoAI | 10/9/2026 | 10/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LiveLinks plugin where title and description fields are stored without sanitization. A user with canStream permission can inject malicious scripts that execute in the browser of every visitor… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Wwbn AvideoAI | 10/9/2026 | 10/9/2026 | WWBN AVideo, in versions up to and including commit c3edcc274c389816d434acadac07ee78eaf330c1, contains a stored cross-site scripting vulnerability. objects/categoryAddNew.json.php passes the POST parameters `name` and `iconClass` to Category::setName() and Category::setIconClass(), which store the values without… | |
| Aplazada | Crítica (9.3) | 0.45% | — | Wwbn AvideoAI | 10/9/2026 | 15/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to encode the User-Agent header before storing it in login history. Attackers with any valid login account can inject malicious scripts in the User-Agent header… | |
| Aplazada | Media (5.3) | 0.31% | — | Wwbn AvideoAI | 10/9/2026 | 18/9/2026 | AVideo through revision c3edcc274c389816d434acadac07ee78eaf330c1 (master, 2026-08-23) incompletely sanitizes sensitive user fields in the APIName=video response. Video rows include columns joined from the video owner's user record, and API::get_api_video() calls removeSensitiveUserFields() only when the caller is… | |
| Aplazada | Alta (7.1) | 0.17% | — | Wwbn AvideoAI | 10/9/2026 | 18/9/2026 | WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a cross-site request forgery vulnerability in the LoginControl plugin PGP key endpoints that lack CSRF token validation. Attackers can craft malicious pages with image tags pointing to savePublicKey.json.php to replace a logged-in victim's… | |
| Aplazada | Alta (8.6) | 0.36% | — | Wwbn AvideoAI | 10/9/2026 | 18/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 fails to validate restream ownership in getRestream.json.php, allowing authenticated users with canStream permission to mint tokens for arbitrary restreams. Attackers can exchange the token to retrieve other users' stream keys from getLiveKey.json.php and… | |
| Aplazada | Media (5.3) | 0.24% | — | Videolan VLC Media PlayerAI | 9/9/2026 | 14/9/2026 | Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build… | |
| Aplazada | Alta (7.3) | 0.12% | — | Videolan VLC Media PlayerAI | 9/9/2026 | 18/9/2026 | VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process. | |
| Aplazada | Crítica (9.1) | 0.38% | — | Wwbn AvideoAI | 8/9/2026 | 10/9/2026 | WWBN AVideo through commit e01e41ecc (no patched version available) exposes get_api_preauthorize in plugin/API/API.php as a second, undocumented login path. Unlike get_api_signIn, which enforces a rate limit of 10 attempts per 5 minutes via checkRateLimit(), get_api_preauthorize performs the same credential check with… | |
| Aplazada | Alta (8.7) | 0.55% | — | Wwbn AvideoAI | 8/9/2026 | 8/9/2026 | AVideo through 29.0 contains an authentication bypass vulnerability in plugin/PlayLists/epg.json.php that exposes live-stream keys and private EPG schedules to unauthenticated users. Attackers can request the endpoint with sequential user or playlist IDs to retrieve sensitive credentials, server identifiers, and… |