| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2019-25353 | Foscam Video Management System 1.1.4.9 - 'Username' Denial of Service | Diy Security SL | Foscam Video Management System | High | 7.5 | 2026-02-18 21:54:59 | Deep Dive |
| CVE-2025-13727 | Video Share VOD <= 2.7.11 - Authenticated (Editor+) Stored Cross-Site Scripting via Custom Field Meta Values | videowhisper | Video Share VOD – Turnkey Video Site Builder Script | Medium | 4.4 | 2026-02-18 09:25:52 | Deep Dive |
| CVE-2026-1368 | Video Conferencing with Zoom API < 4.6.6 - Unauthenticated SDK Signature Generation | Unknown | Video Conferencing with Zoom | - | - | 2026-02-18 06:00:10 | Deep Dive |
| CVE-2026-1254 | Modula Image Gallery – Photo Grid & Video Gallery <= 2.13.6 - Missing Authorization to Authenticated (Contributor+) Arbitrary Post/Page Editing | wpchill | Modula Image Gallery – Photo Grid & Video Gallery | Medium | 4.3 | 2026-02-14 08:26:47 | Deep Dive |
| CVE-2020-37184 | Allok Video Converter 4.6.1217 - Stack Overflow (SEH) | Allok Soft | Allok Video Converter | Critical | 9.8 | 2026-02-11 20:37:07 | Deep Dive |
| CVE-2026-1608 | Video Onclick <= 0.4.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | tigor4eg | Video Onclick | Medium | 6.4 | 2026-02-07 08:26:38 | Deep Dive |
| CVE-2026-1888 | Docus <= 1.0.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes | htplugins | Docus – YouTube Video Playlist | Medium | 6.4 | 2026-02-06 06:46:29 | Deep Dive |
| CVE-2021-47921 | Free Photo & Video Vault 0.0.2 Directory Traversal Vulnerability via Web Request | Author: Scott Ferreira | Free Photo & Video Vault - WiFi Transfer | Medium | 6.5 | 2026-02-01 12:56:57 | Deep Dive |
| CVE-2026-1165 | Popup Box <= 6.1.1 - Cross-Site Request Forgery to Popup Status Change | ays-pro | Popup Box – Create Countdown, Coupon, Video, Contact Form Popups | Medium | 4.3 | 2026-01-31 14:22:29 | Deep Dive |
| CVE-2020-37028 | Socusoft Photo to Video Converter Professional 8.07 - 'Output Folder' Buffer Overflow | SOCUSOFT | Photo to Video Converter Professional | High | 8.4 | 2026-01-30 22:07:11 | Deep Dive |
| CVE-2020-36971 | Nidesoft 3GP Video Converter 2.6.18 - Local Stack Buffer Overflow | Nidesoft | Nidesoft 3GP Video Converter | High | 8.4 | 2026-01-28 17:35:12 | Deep Dive |
| CVE-2025-8072 | Target Video Easy Publish <= 3.8.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via placeholder_img Parameter | nebojsadabic | Target Video Easy Publish | Medium | 6.4 | 2026-01-28 05:30:18 | Deep Dive |
| CVE-2025-15516 | All-in-One Video Gallery 4.1.0 - 4.6.4 - Missing Authorization to Authenticated (Subscriber+) Limited User Meta Update | plugins360 | All-in-One Video Gallery | Medium | 4.3 | 2026-01-24 08:26:33 | Deep Dive |
| CVE-2025-14906 | WP Youtube Video Gallery <= 1.0 - Cross-Site Request Forgery to Plugin Settings Update | waqasvickey0071 | WP Youtube Video Gallery | Medium | 4.3 | 2026-01-24 07:26:42 | Deep Dive |
| CVE-2025-14947 | All-in-One Video Gallery <= 4.6.4 - Missing Authorization to Unauthenticated Bunny Stream Video Creation/Deletion | plugins360 | All-in-One Video Gallery | Medium | 6.5 | 2026-01-23 17:26:07 | Deep Dive |
| CVE-2025-69053 | WordPress Universal Video Player plugin <= 3.8.4 - Reflected Cross Site Scripting (XSS) vulnerability | LambertGroup | Universal Video Player | - | - | 2026-01-22 16:52:21 | Deep Dive |
| CVE-2025-69048 | WordPress Universal Video Player plugin <= 3.8.4 - Reflected Cross Site Scripting (XSS) vulnerability | LambertGroup | Universal Video Player | - | - | 2026-01-22 16:52:20 | Deep Dive |
| CVE-2025-68906 | WordPress JNews - Video plugin <= 11.0.2 - Reflected Cross Site Scripting (XSS) vulnerability | jegtheme | JNews - Video | - | - | 2026-01-22 16:52:14 | Deep Dive |
| CVE-2025-49049 | WordPress DZS Video Gallery plugin <= 12.39 - SQL Injection vulnerability | ZoomIt | DZS Video Gallery | High | 8.5 | 2026-01-22 16:51:42 | Deep Dive |
| CVE-2025-47666 | WordPress Image&Video FullScreen Background plugin <= 1.6.7 - Reflected Cross Site Scripting (XSS) vulnerability | LambertGroup | Image&Video FullScreen Background | High | 7.1 | 2026-01-22 16:51:41 | Deep Dive |