Vulnerabilities in WWBN

199 results
Vexday analysis

O portfólio de vulnerabilidades do WWBN reúne 187 CVEs catalogadas, com 30 classificadas como críticas e 67 surgidas apenas nos últimos 90 dias — volume recente que indica aceleração no ritmo de descoberta e demanda atenção contínua ao ciclo de atualização. Embora nenhuma CVE esteja no catálogo KEV da CISA, situando a taxa de exploração ativa abaixo da média geral do catálogo, o CVE-2022-30690 apresenta EPSS de 0,8358, sinalizando alta probabilidade estimada de exploração e devendo ser tratado com prioridade. A falha mais recorrente é CWE-79 (Cross-Site Scripting), categoria que, combinada com a existência de ao menos uma prova de conceito pública, amplia a superfície de risco para ambientes que ainda não aplicaram as correções disponíveis.

CVE-2022-30690CRITICALA cross-site scripting (xss) vulnerability exists in the image403 functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A speciaEPSS 83.6%CVE-2022-30534CRITICALAn OS command injection vulnerability exists in the aVideoEncoder chunkfile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364EPSS 74.5%CVE-2022-30547CRITICALA directory traversal vulnerability exists in the unzipDirectory functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specialEPSS 63.7%CVE-2022-32572CRITICALAn os command injection vulnerability exists in the aVideoEncoder wget functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A sEPSS 23.2%CVE-2026-33478CRITICALAVideo Multi-Chain Attack: Unauthenticated Remote Code Execution via Clone Key Disclosure, Database Dump, and Command InjectionEPSS 13.3%CVE-2023-32073HIGHAVideo command injection vulnerabilityEPSS 6.5%CVE-2023-30854HIGHWWBN AVideo vulnerable to OS Command InjectionEPSS 5.2%CVE-2022-30605HIGHA privilege escalation vulnerability exists in the session id functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A specially-EPSS 4.2%CVE-2026-33482HIGHAVideo has an OS Command Injection via $() Shell Substitution Bypass in sanitizeFFmpegCommand()EPSS 4.2%CVE-2022-32770CRITICALA cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A sEPSS 3.5%CVE-2022-32771CRITICALA cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A sEPSS 3.3%CVE-2022-32772CRITICALA cross-site scripting (xss) vulnerability exists in the footer alerts functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A sEPSS 3.1%CVE-2022-26842CRITICALA reflected cross-site scripting (xss) vulnerability exists in the charts tab selection functionality of WWBN AVideo 11.6 and dev master comEPSS 3.0%CVE-2022-32761MEDIUMAn information disclosure vulnerability exists in the aVideoEncoderReceiveImage functionality of WWBN AVideo 11.6 and dev master commit 3f7cEPSS 2.5%CVE-2022-28712CRITICALA cross-site scripting (xss) vulnerability exists in the videoAddNew functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A speEPSS 2.5%CVE-2022-28710MEDIUMAn information disclosure vulnerability exists in the chunkFile functionality of WWBN AVideo 11.6 and dev master commit 3f7c0364. A speciallEPSS 2.4%CVE-2023-48728CRITICALA cross-site scripting (xss) vulnerability exists in the functiongetOpenGraph videoName functionality of WWBN AVideo 11.6 and dev master comEPSS 2.3%CVE-2026-41304HIGHWWBN AVideo vulnerable to RCE caused by clonesite pluginEPSS 2.2%CVE-2026-55173HIGHAVideo incomplete fix for CVE-2026-33482: sanitizeFFmpegCommand still allows a single '&' (background operator), giving OS command execution at the same execAsync sh -c sinkEPSS 2.2%CVE-2026-29058CRITICALAVideo: Unauthenticated OS Command Injection via base64Url in objects/getImage.phpEPSS 2.1%