Known vulnerabilities in AVideo 11 - page 4

Software: AVideo
Version: 11
Software CPE: cpe:2.3:a:wwbn:avideo:*:*:*:*:*:*:*:*
Total vulnerabilities: 120
Public exploits: 16
Known exploited (KEV): 1
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting AVideo version 11 AVideo 11 is affected by 120 vulnerabilities: 25 high, 48 medium, 47 low Critical High Medium Low

Vulnerabilities (120)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU129510 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-33478
CWE-78 High
No
No
29.0 04.05.2026 SB2026050470
#VU129509 - Improper Control of Generation of Code ('Code Injection')
CVE-2026-33479
CWE-94 High
No
No
29.0 04.05.2026 SB2026050470
#VU129508 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-33352
CWE-89 High
No
No
29.0 04.05.2026 SB2026050470
#VU129507 - Missing Authentication for Critical Function
CVE-2026-56346
CWE-306 Medium
No
No
26.0 04.05.2026 SB2026050468
#VU129506 - Exposure of sensitive information to an unauthorized actor
CVE-2026-33041
CWE-200 Medium
No
No
14.3.1 04.05.2026 SB2026050466
#VU128358 - Improper Neutralization of CRLF Sequences ('CRLF Injection')
CVE-2026-43882
CWE-93 Low
Public exploit available
No
- 28.04.2026 SB20260428201
#VU128274 - Authorization Bypass Through User-Controlled Key
CVE-2026-43883
CWE-639 Low
Public exploit available
No
- 28.04.2026 SB20260428201
#VU125459 - Server-Side Request Forgery (SSRF)
CVE-2026-33480
CWE-918 High
No
No
29.0 08.04.2026 SB2026050470
#VU125458 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-33482
CWE-78 High
No
No
29.0 08.04.2026 SB2026050470
#VU125457 - Allocation of Resources Without Limits or Throttling
CVE-2026-33483
CWE-770 Medium
No
No
29.0 08.04.2026 SB2026050470
#VU125456 - Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CVE-2026-33485
CWE-89 Medium
No
No
29.0 08.04.2026 SB2026050470
#VU125453 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-33292
CWE-22 Medium
No
No
26.0 08.04.2026 SB2026050469
#VU125450 - Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
CVE-2026-33319
CWE-78 Low
No
No
26.0 08.04.2026 SB2026050468
#VU125448 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-33295
CWE-79 Low
No
No
26.0 08.04.2026 SB2026050468
#VU125447 - URL Redirection to Untrusted Site ('Open Redirect')
CVE-2026-33296
CWE-601 Medium
No
No
26.0 08.04.2026 SB2026050468
#VU125446 - Authorization Bypass Through User-Controlled Key
CVE-2026-33297
CWE-639 Low
No
No
26.0 08.04.2026 SB2026050468
#VU125445 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2026-33238
CWE-22 Low
No
No
14.3 08.04.2026 SB2026050467
#VU125444 - Server-Side Request Forgery (SSRF)
CVE-2026-33237
CWE-918 Low
No
No
14.3 08.04.2026 SB2026050467
#VU125443 - Exposure of sensitive information to an unauthorized actor
CVE-2026-33043
CWE-200 High
No
No
14.3.1 08.04.2026 SB2026050466
#VU125439 - Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2026-33035
CWE-79 Medium
No
No
25.0 08.04.2026 SB2026050465
SB2026050471


Showing elements 61 - 80 out of 120