Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1999 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.38% | — | Broadcast Live VideoAI | 23/7/2026 | 23/7/2026 | Unauthenticated Arbitrary File Deletion in Broadcast Live Video <= 7.2.4 versions. | |
| Aplazada | Alta (7.1) | 0.41% | — | Videowhisper Picture GalleryAI | 23/7/2026 | 23/7/2026 | Contributor Arbitrary File Deletion in Picture Gallery <= 1.6.5 versions. | |
| Aplazada | Media (5.3) | 0.32% | — | Wwbn AvideoAI | 20/7/2026 | 23/7/2026 | AVideo versions from commit 0dbadbca through latest master contain a server-side request forgery vulnerability in the encoder download-by-URL flow due to an unpinned retry fallback that bypasses DNS pinning validation. An authenticated attacker can supply a downloadURL that redirects to an internal address, causing… | |
| Aplazada | Crítica (9.3) | 0.60% | — | Wwbn AvideoAI | 20/7/2026 | 23/7/2026 | AVideo before 29.0 contains an incomplete fix for CVE-2026-45578 where execAsync() re-wraps escaped commands in double-quoted sh -c, allowing command substitution via $() and backticks. Attackers can inject arbitrary OS commands through the Live plugin on_publish.php endpoint despite escapeshellarg() protection. | |
| Aplazada | Crítica (9.1) | 0.44% | — | Vimesoft Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Aplazada | Crítica (9.4) | 0.46% | — | Vimesoft Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Authorization bypass through User-Controlled key vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Aplazada | Crítica (9.8) | 0.64% | — | Vimesoft Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Unverified password change vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Aplazada | Alta (7.5) | 0.52% | — | Vimesoft INC Enterprise Video PlatformAI | 17/7/2026 | 17/7/2026 | Missing authentication for critical function vulnerability in Vimesoft Inc. Enterprise Video Platform allows Authentication Bypass. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0. | |
| Aplazada | Alta (8.1) | 3.4% | — | Wwbn AvideoAI | 16/7/2026 | 17/7/2026 | WWBN AVideo is an open source video platform. Versions 29.0 and below remain vulnerable to OS command injection because the fix for CVE-2026-33482 was incomplete and still does not neutralize a single & ( the shell background operator). CVE-2026-33482 reported that sanitizeFFmpegCommand()… | |
| Aplazada | Media (6.5) | 0.21% | — | Wwbn AvideoAI | 16/7/2026 | 17/7/2026 | WWBN AVideo is an open source video platform. In versions prior to 29.0, the Authorize.Net webhook handler at plugin/AuthorizeNet/webhook.php contains a signature verification bypass that allows an attacker to forge webhook requests with arbitrary payment amounts and target user IDs. By supplying a valid transaction… | |
| Aplazada | Alta (7.5) | 0.45% | — | ApacheAIWwbn AvideoAI | 16/7/2026 | 17/7/2026 | WWBN AVideo is an open source video platform. Versions prior to 29.0 expose .env files to unauthenticated users through the official Docker compose configuration. The official docker-compose.yml mounts the entire project root directory as the Apache document root, causing the .env file — which contains database… | |
| Aplazada | Crítica (9.2) | 2.5% | — | FfmpegAIWwbn AvideoAI | 16/7/2026 | 20/7/2026 | AVideo through 29.0 contains an OS command injection vulnerability in the ffmpeg.json.php endpoint where notifyCode and callback parameters are concatenated into a shell command without escaping. Attackers who can craft a valid encrypted payload can inject arbitrary shell metacharacters into these fields to execute OS… | |
| Aplazada | Crítica (9.2) | 2.5% | — | Wwbn AvideoAI | 16/7/2026 | 20/7/2026 | AVideo through 29.0 contains an OS command injection vulnerability in plugin/API/standAlone/functions.php where the listFFmpegProcesses() function interpolates unsanitized keyword parameters inside single quotes without escaping. Attackers who can craft a valid encrypted codeToExec payload can break out of the… | |
| Aplazada | Crítica (9.6) | 0.51% | — | Wwbn AvideoAI | 15/7/2026 | 16/7/2026 | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain a stored DOM Cross-Site Scripting vulnerability in the YPTSocket plugin. Any unauthenticated remote attacker can execute arbitrary JavaScript in the authenticated origin of every administrator currently viewing a page that renders the… | |
| Aplazada | Media (4.7) | 0.26% | — | Wwbn AvideoAI | 15/7/2026 | 16/7/2026 | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a stored Cross-Site Scripting vulnerability in the YouTubeAPI plugin. The plugin renders the snippet.title field returned by the YouTube Data API into the homepage gallery markup with no HTML encoding. The title is set by the YouTube video… | |
| Aplazada | Media (6.1) | 0.29% | — | Wwbn AvideoAI | 15/7/2026 | 17/7/2026 | WWBN AVideo is an open source video platform. Versions prior to 29.0 contain an unauthenticated Reflected XSS vulnerability through AVideo YouTubeAPI Gallery Pagination. The $_GET['search'] query parameter is concatenated directly into the href attribute of two pagination links in plugin/YouTubeAPI/gallerySection.php… | |
| Aplazada | Alta (7.7) | 0.54% | — | Wwbn AvideoAI | 15/7/2026 | 18/7/2026 | WWBN AVideo is an open source video platform. Versions 29.0 and below contain a Stored XSS vulnerability through the autoEvalCodeOnHTML parameter in the MessageSQLite WebSocket Handler. The MessageSQLite.php handler only strips autoEvalCodeOnHTML from $json['msg'], but msgToResourceId() reads from $msg['json'] with… | |
| Aplazada | Media (5.3) | 0.33% | — | Wwbn AvideoAI | 15/7/2026 | 16/7/2026 | WWBN AVideo is an open source video platform. Prior to version 29.0, Privilege Escalation is possible through unguarded permission parameters in signUp API, which allows any user who can solve a CAPTCHA to self-grant elevated permissions during account registration. The set_api_signUp method in the API plugin accepts… | |
| Aplazada | Crítica (9.8) | 0.77% | — | Shenzhou Shihan Video Conference SystemAI | 13/7/2026 | 15/7/2026 | SQL Injection vulnerability in Shenzhou Shihan Video Conference System v.1.0 allows a remote attacker to execute arbitrary code via the /user/getUserLogin endpoint | |
| Aplazada | Media (4.4) | 0.40% | — | Videousermanuals White Label CMSAI | 11/7/2026 | 15/7/2026 | The White Label CMS plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 2.7.12 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Media (4.3) | 0.41% | — | MUX Video UploaderAI | 11/7/2026 | 13/7/2026 | The Mux Video Uploader plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.1.4 via the muxvideo_enqueue_settings_script. This makes it possible for authenticated attackers, with subscriber-level access and above, to extract sensitive data including Mux API… | |
| Aplazada | Media (6.4) | 0.42% | — | ALL IN ONE Video GalleryAI | 10/7/2026 | 10/7/2026 | The All-in-One Video Gallery plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.8.5 via the 'vdl' parameter. This makes it possible for authenticated attackers, with subscriber-level access and above, to make web requests to arbitrary locations originating from… | |
| Analizada | Alta (8.8) | 0.11% | — | Qualcomm Wsa8835 FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Cq7790 Firmware+124 | 6/7/2026 | 7/7/2026 | Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations. | |
| Analizada | Media (5.3) | 0.08% | — | Qualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6900 FirmwareQualcomm Fastconnect 7800 FirmwareQualcomm Lemans AU Lgit Firmware+75 | 6/7/2026 | 7/7/2026 | Memory Corruption when updating prepared commands with invalid port indices based on user space input exceeds supported read client limits. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Aqt1000 FirmwareQualcomm Cologne FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+43 | 6/7/2026 | 7/7/2026 | Memory Corruption when allocating memory with sizes that exceed the maximum allowed value. |