Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
356 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.45% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request to plugin/MobileManager/getConfiguration.json.php to obtain TLS… | |
| Aplazada | Crítica (9.3) | 0.51% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access. | |
| Aplazada | Crítica (9.3) | 0.55% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or shared secret. An… | |
| Aplazada | Media (6.9) | 0.56% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code parameter. Attackers can exploit this to destroy audit logs and probe for file existence on the server,… | |
| Aplazada | Media (5.1) | 0.29% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute stored XSS payloads in victim browsers without requiring authentication. | |
| Aplazada | Alta (8.7) | 0.43% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited credential guessing attacks. | |
| Aplazada | Alta (8.7) | 0.46% | — | Avideo User LocationAIWwbn AvideoAI | 1/9/2026 | 8/9/2026 | AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters are passed directly into SQL queries without escaping or prepared statement binding, allowing unauthenticated attackers… | |
| Aplazada | Alta (8.8) | 0.51% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with schedule identifiers. Attackers can exploit the unguarded RTMP callback endpoint to modify scheduled… | |
| Aplazada | Alta (7.2) | 0.23% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers can navigate a victim's browser to a malicious URL with API parameters to delete videos, deactivate accounts, or… | |
| Aplazada | Alta (7.1) | 0.32% | — | Wwbn AvideoAI | 30/8/2026 | 2/9/2026 | WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-encoded NAT64 addresses like 64:ff9b::a9fe:a9fe to reach cloud metadata services and… | |
| Aplazada | Media (5.3) | 0.15% | — | Wwbn AvideoAI | 30/8/2026 | 31/8/2026 | WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks and captcha validation. Attackers can craft a malicious web page that, when visited by an authenticated admin, sends… | |
| Aplazada | Media (5.3) | 0.26% | — | Wwbn AvideoAI | 30/8/2026 | 31/8/2026 | WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML metacharacters. Attackers can mint an encrypted evideo payload containing unescaped markup, then deliver it as a… | |
| Aplazada | Crítica (9.2) | 0.20% | — | Wwbn AvideoAI | 30/8/2026 | 31/8/2026 | AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the endpoint to return any restream's… | |
| Aplazada | Alta (8.7) | 0.45% | — | Wwbn AvideoAI | 30/8/2026 | 1/9/2026 | WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::setCacheGlobal) that silently discards writes for any client identified as a bot by… | |
| Aplazada | Media (6.9) | 0.34% | — | Wwbn AvideoAI | 30/8/2026 | 2/9/2026 | WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting. Attackers can submit correct credentials repeatedly to trigger uncapped two-factor confirmation emails and perform sustained password guessing… | |
| Aplazada | Media (5.1) | 0.22% | — | Wwbn AvideoAI | 28/8/2026 | 29/8/2026 | WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, customMessage, and autoRedirect parameters from $_REQUEST via a GET request without… | |
| Aplazada | Media (6.9) | 0.56% | — | Wwbn AvideoAI | 28/8/2026 | 29/8/2026 | WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send GET requests to these endpoints to retrieve daily and cumulative user-registration counts without any session or… | |
| Aplazada | Media (6.9) | 0.45% | — | Wwbn AvideoAI | 27/8/2026 | 29/8/2026 | AVideo before 24.0 contains a server-side request forgery vulnerability in the isSSRFSafeURL function that fails to extract embedded IPv4 addresses from NAT64, 6to4, and Teredo IPv6 transition address formats. Unauthenticated attackers can bypass SSRF protections via the LiveLinks proxy endpoint to reach internal… | |
| Aplazada | Alta (8.7) | 0.59% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | AVideo through commit 9c39d8c8 contains an authentication bypass vulnerability where deduplicateByEncoderQueueId() returns video_id_hash credentials for any video by encoder_queue_id without ownership verification, and useVideoHashOrLogin() converts this hash into passwordless login as the video owner. Attackers with… | |
| Aplazada | Alta (8.7) | 0.46% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | WWBN AVideo through commit 9c39d8c8 contains an authorization bypass vulnerability where getToken() creates tokens without binding to user identity or purpose, and plugin/Gallery/view/sections.php issues valid tokens to unauthenticated visitors. Attackers can retrieve a token from the Gallery endpoint and use it to… | |
| Aplazada | Alta (7.1) | 0.16% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the releaseVideoNow.json.php endpoint that lacks authenticity checks and accepts GET requests. Attackers can craft a malicious cross-site GET request carrying an administrator's session cookie to permanently publish any… | |
| Aplazada | Alta (7.1) | 0.21% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | WWBN AVideo through commit 9c39d8c8b4c1f75540788d6b391740852ceb0732 contains an authorization bypass vulnerability in the Users_affiliations add.json.php endpoint that allows authenticated users to forge two-party consent records by supplying the counterparty's agreement timestamp. Attackers can create a forged… | |
| Aplazada | Media (6.9) | 0.17% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in objects/videoEditLight.php that lacks request authenticity checks and accepts GET requests. Attackers can store an img tag in a video description that transfers video ownership to an attacker-controlled account when an… | |
| Aplazada | Media (5.3) | 0.14% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data. Attackers can craft a cross-site GET request carrying an administrator's session cookie to… | |
| Aplazada | Media (6.9) | 0.36% | — | Wwbn AvideoAI | 22/8/2026 | 26/8/2026 | AVideo through commit 9c39d8c8 contains an information exposure vulnerability in feed/index.php that allows unauthenticated attackers to retrieve channel owner email addresses by supplying a public channel name parameter. Attackers can enumerate all creator email addresses by iterating through public channel names and… |