Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
1999 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.9) | 0.34% | — | Wwbn AvideoAI | 3/9/2026 | 8/9/2026 | WWBN AVideo contains a broken access control vulnerability in the unauthenticated feed/index.php endpoint that disables per-video visibility checks when a program_id parameter is supplied. Attackers can enumerate playlist identifiers and retrieve unlisted and group-restricted videos by requesting the RSS feed with any… | |
| Aplazada | Media (6.9) | 0.34% | — | Wwbn AvideoAI | 3/9/2026 | 8/9/2026 | WWBN AVideo fails to properly validate access controls on the public channel page, allowing unauthenticated visitors to view unlisted and group-restricted videos through hardcoded visibility flags and an undefined property. Attackers can access the channel endpoint to retrieve sensitive video content that should be… | |
| Aplazada | Alta (8.7) | 0.46% | — | Wwbn AvideoAI | 3/9/2026 | 8/9/2026 | WWBN AVideo contains a SQL injection vulnerability in the sort column parameter of the get.json.php endpoint with APIName=channels that allows unauthenticated attackers to order results by arbitrary database columns including users.password and users.recoverPass. Attackers can exploit this ordering oracle to infer… | |
| Aplazada | Crítica (9.3) | 0.64% | — | Wwbn AvideoAI | 3/9/2026 | 8/9/2026 | WWBN AVideo contains an authentication failure vulnerability where the video_id_hash credential is a non-expiring, non-revocable bearer token that grants full administrator session access to the video owner's account. Attackers who obtain a video_id_hash can replay it indefinitely to authenticate as the video owner… | |
| Pendiente de análisis | Alta (7.5) | 0.37% | — | Cisco Desk Phone 9800 SeriesAICisco IP Phone 7800 SeriesAICisco IP Phone 8800 SeriesAICisco Video Phone 8875AI+1 | 2/9/2026 | 2/9/2026 | A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is… | |
| Aplazada | Media (6.9) | 0.45% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | WWBN AVideo through commit 9c39d8c8 contains an incomplete authentication bypass in encryptPass.json.php that allows unauthenticated attackers to compute valid HMAC tokens using the public site URL and current time. Attackers can forge authentication tokens by computing hash_hmac with the site's base URL as the key… | |
| Aplazada | Alta (8.7) | 0.21% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | WWBN AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in the get_domain() and isSameDomain() functions that fail to properly validate referer origins. Attackers can forge requests from sibling subdomains or unparseable long-gTLD origins to perform administrative ObjectYPT writes… | |
| Aplazada | Media (6.9) | 0.45% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | WWBN AVideo through 30.0 contains an information disclosure vulnerability in the MobileManager plugin getConfiguration endpoint that returns sensitive configuration data to unauthenticated visitors. Attackers can send an unauthenticated GET request to plugin/MobileManager/getConfiguration.json.php to obtain TLS… | |
| Aplazada | Crítica (9.3) | 0.51% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | WWBN AVideo fails to validate password recovery token expiration in userRecoverPassSave.json.php, allowing attackers to use expired tokens to reset account passwords indefinitely. Attackers who obtain a recovery token can use it at any time to change the target account's password and gain full account access. | |
| Aplazada | Crítica (9.3) | 0.55% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | WWBN AVideo (current e01e41ecc and earlier) makes three login-time security controls depend solely on the client-supplied User-Agent header. The isAVideoEncoder()/isAVideoMobileApp() checks match HTTP_USER_AGENT against a hardcoded literal ("AVideoEncoder"/"AVideoMobileApp") with no IP check or shared secret. An… | |
| Aplazada | Media (6.9) | 0.56% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | WWBN AVideo contains a path traversal vulnerability in the API get_api_login_code endpoint that allows unauthenticated attackers to delete arbitrary .log files by supplying directory traversal sequences in the code parameter. Attackers can exploit this to destroy audit logs and probe for file existence on the server,… | |
| Aplazada | Media (5.1) | 0.29% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | AVideo Live_schedule::setTitle() and setDescription() store POST input without sanitization, allowing users with streaming permission to inject malicious scripts. Unauthenticated attackers can access remindMe.php to execute stored XSS payloads in victim browsers without requiring authentication. | |
| Aplazada | Alta (8.7) | 0.43% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | WWBN AVideo fails to validate trusted proxies before accepting X-Real-IP and X-Forwarded-For headers, allowing attackers to spoof the client address used by enforceRateLimit(). Attackers can rotate the header value per request to bypass login rate limiting and perform unlimited credential guessing attacks. | |
| Aplazada | Alta (8.7) | 0.46% | — | Avideo User LocationAIWwbn AvideoAI | 1/9/2026 | 8/9/2026 | AVideo through version 29.0 contains an unauthenticated SQL injection vulnerability in the User_Location plugin's regions.json.php and cities.json.php endpoints. The country and region GET parameters are passed directly into SQL queries without escaping or prepared statement binding, allowing unauthenticated attackers… | |
| Aplazada | Alta (8.8) | 0.51% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | AVideo contains a missing authentication vulnerability in plugin/Live/on_publish.php that allows unauthenticated attackers to mark arbitrary scheduled broadcasts as failed by sending crafted POST requests with schedule identifiers. Attackers can exploit the unguarded RTMP callback endpoint to modify scheduled… | |
| Aplazada | Alta (7.2) | 0.23% | — | Wwbn AvideoAI | 1/9/2026 | 8/9/2026 | AVideo contains a cross-site request forgery vulnerability in plugin/API/set.json.php that allows attackers to perform state-changing actions by crafting GET requests that bypass CSRF protection. Attackers can navigate a victim's browser to a malicious URL with API parameters to delete videos, deactivate accounts, or… | |
| Aplazada | Alta (7.1) | 0.32% | — | Wwbn AvideoAI | 30/8/2026 | 2/9/2026 | WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses written in hexadecimal form. Attackers can bypass SSRF protections by supplying hex-encoded NAT64 addresses like 64:ff9b::a9fe:a9fe to reach cloud metadata services and… | |
| Aplazada | Media (5.3) | 0.15% | — | Wwbn AvideoAI | 30/8/2026 | 31/8/2026 | WWBN AVideo contains a cross-site request forgery vulnerability in sendEmail.json.php that allows authenticated administrators to send mail from the site's contact address by bypassing origin checks and captcha validation. Attackers can craft a malicious web page that, when visited by an authenticated admin, sends… | |
| Aplazada | Media (5.3) | 0.26% | — | Wwbn AvideoAI | 30/8/2026 | 31/8/2026 | WWBN AVideo contains an unauthenticated reflected cross-site scripting vulnerability in the url2Embed.json.php endpoint that allows attackers to inject malicious scripts by supplying URLs with HTML metacharacters. Attackers can mint an encrypted evideo payload containing unescaped markup, then deliver it as a… | |
| Aplazada | Crítica (9.2) | 0.20% | — | Wwbn AvideoAI | 30/8/2026 | 31/8/2026 | AVideo (current commit e01e41ecc and earlier) exposes stream credentials through the plugin/Live/view/Live_restreams/getLiveKey.json.php endpoint. Supplying a 'token' request parameter waives both the Live::canRestream() access gate and the restream ownership check, causing the endpoint to return any restream's… | |
| Aplazada | Alta (8.7) | 0.45% | — | Wwbn AvideoAI | 30/8/2026 | 1/9/2026 | WWBN AVideo (current e01e41ecc and earlier) contains a brute-force rate limiting bypass in enforceRateLimit(), which protects login.json.php and 13 other endpoints. The function stores its attempt counter via a cache layer (ObjectYPT::setCacheGlobal) that silently discards writes for any client identified as a bot by… | |
| Aplazada | Media (6.9) | 0.34% | — | Wwbn AvideoAI | 30/8/2026 | 2/9/2026 | WWBN AVideo contains an unauthenticated credential submission vulnerability in plugin/Live/api/preauthorize.json.php that accepts credentials over GET without rate limiting. Attackers can submit correct credentials repeatedly to trigger uncapped two-factor confirmation emails and perform sustained password guessing… | |
| Aplazada | Media (5.1) | 0.22% | — | Wwbn AvideoAI | 28/8/2026 | 29/8/2026 | WWBN AVideo through 30.0 (and master up to commit 4cb576e) contains a cross-site request forgery vulnerability in plugin/Live/myLiveControls.save.json.php. The endpoint only checks that a user is logged in and processes customUrl, customMessage, and autoRedirect parameters from $_REQUEST via a GET request without… | |
| Aplazada | Media (6.9) | 0.56% | — | Wwbn AvideoAI | 28/8/2026 | 29/8/2026 | WWBN AVideo through version 30.0 fails to enforce authentication on the report4.json.php and report4.1.json.php endpoints, allowing unauthenticated access to user registration statistics. Attackers can send GET requests to these endpoints to retrieve daily and cumulative user-registration counts without any session or… | |
| Aplazada | Media (5.3) | 0.44% | — | Mrvinoth ALL Video ShareAI | 28/8/2026 | 28/8/2026 | Joomla Extension - mrvinoth.com - Reflected XSS in All Video Share 1.0.0-4.5.0 - Various user supplied inputs lacked escaping, leading to reflected XSS vectors |