| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2024-20492 | Cisco Expressway Series Privilege Escalation Vulnerability | Cisco | Cisco TelePresence Video Communication Server (VCS) Expressway | Medium | 6.0 | 2024-10-02 16:55:34 | Deep Dive |
| CVE-2024-7869 | 123.chat - Video Chat <= 1.3.1 - Unauthenticated Stored Cross-Site Scripting | 123.chat | 123.chat - Video Chat | High | 7.2 | 2024-10-01 07:30:10 | Deep Dive |
| CVE-2019-25212 | video carousel slider with lightbox <= 1.0.6 - Authenticated (Admin+) SQL Injection | nik00726 | video carousel slider with lightbox | Medium | 4.9 | 2024-09-11 08:31:04 | Deep Dive |
| CVE-2024-7727 | HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.32 - Missing Authorization in multiple functions via h5vp_ajax_handler | bplugins | HTML5 Video Player – Embed and Play Videos in Custom Player | Medium | 5.3 | 2024-09-11 04:31:21 | Deep Dive |
| CVE-2024-7721 | HTML5 Video Player – mp4 Video Player Plugin and Block <= 2.5.34 - Missing Authorization to Authenticated (Subscriber+) Limited Options Update | bplugins | HTML5 Video Player – Embed and Play Videos in Custom Player | Medium | 4.3 | 2024-09-11 04:31:20 | Deep Dive |
| CVE-2023-50360 | Video Station | QNAP Systems Inc. | Video Station | High | 8.8 | 2024-09-06 16:26:55 | Deep Dive |
| CVE-2023-47563 | Video Station | QNAP Systems Inc. | Video Station | High | 7.4 | 2024-09-06 16:26:50 | Deep Dive |
| CVE-2024-20497 | Cisco Expressway Edge Improper Authorization Vulnerability | Cisco | Cisco TelePresence Video Communication Server (VCS) Expressway | Medium | 4.3 | 2024-09-04 16:29:14 | Deep Dive |
| CVE-2024-43319 | WordPress HTML5 Video Player plugin <= 2.5.31 - Sensitive Data Exposure vulnerability | bPlugins LLC | Flash & HTML5 Video | Medium | 4.3 | 2024-08-26 16:05:03 | Deep Dive |
| CVE-2024-7629 | Responsive Video <= 1.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | marla14 | Responsive Video | Medium | 6.4 | 2024-08-21 05:30:24 | Deep Dive |
| CVE-2024-6629 | All-in-One Video Gallery <= 3.7.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Video Shortcode | plugins360 | All-in-One Video Gallery | Medium | 6.4 | 2024-07-24 06:42:24 | Deep Dive |
| CVE-2024-6338 | FV Player <= 7.5.46.7212 - Authenticated (Subscriber+) SQL Injection via exclude Parameter | foliovision | FV Flowplayer Video Player | High | 8.8 | 2024-07-19 07:36:49 | Deep Dive |
| CVE-2024-6599 | Meks Video Importer <= 1.0.12 - Missing Authorization to Authenticated (Subscriber+) API Keys Modification | mekshq | Meks Video Importer | Medium | 4.3 | 2024-07-18 02:03:59 | Deep Dive |
| CVE-2024-20400 | Cisco Expressway Series 安全漏洞 | Cisco | Cisco TelePresence Video Communication Server (VCS) Expressway | Medium | 4.7 | 2024-07-17 16:29:36 | Deep Dive |
| CVE-2024-5811 | Simple Video Directory < 1.4.4 - Contributor+ Stored XSS | Unknown | Simple Video Directory | 中危 | - | 2024-07-12 06:00:06 | Deep Dive |
| CVE-2024-6256 | Feeds for YouTube (YouTube video, channel, and gallery plugin) <= 2.2.1 - Authenticated (Contributor+) DOM-Based Stored Cross-Site Scripting | smub | Feeds for YouTube (YouTube video, channel, and gallery plugin) | Medium | 6.4 | 2024-07-11 06:43:13 | Deep Dive |
| CVE-2024-5456 | Panda Video <= 1.4.0 - Authenticated (Contributor+) Local File Inclusion | pandavideo | Panda Video | High | 8.8 | 2024-07-09 08:33:09 | Deep Dive |
| CVE-2024-5457 | Panda Video <= 1.4.0 - Authenticated (Contributor+) Stored Cross-Site Scripting | pandavideo | Panda Video | Medium | 6.4 | 2024-07-09 08:33:08 | Deep Dive |
| CVE-2024-5424 | Gallery Blocks with Lightbox. Image Gallery, (HTML5 video , YouTube, Vimeo) Video Gallery and Lightbox for native gallery <= 3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via galleryID and className Parameters | gallerycreator | Mixed Media Gallery Blocks | Medium | 6.4 | 2024-06-28 08:33:28 | Deep Dive |
| CVE-2024-5169 | Video Widget <= 1.2.3 - Admin+ Stored XSS via Widget | Unknown | Video Widget | - | - | 2024-06-26 06:00:05 | Deep Dive |