Daniel Neto
98 exploits
Active since Dec 2025
AVideo has a Path Traversal in listFiles.json.php that Enables Server Filesystem Enumeration
CVSS 4.3
AVideo-Encoder has Unauthenticated Blind Server-Side Request Forgery via Public Thumbnail Generator
CVSS 9.1
AVideo-Encoder is Vulnerable to Authenticated SQL Injection via ORDER BY Clause
CVSS 8.8
Unauthenticated Reflected XSS via innerHTML in AVideo
CVSS 6.1
WWBN AVideo has predictable default admin credentials in official Docker deployment path
CVSS 8.1
AVideo affected by unauthenticated application takeover via exposed web installer on uninitialized deployments
CVSS 8.1
AVideo vulnerable to unauthenticated SSRF via HTTP redirect bypass in LiveLinks proxy
CVSS 8.6
AVideo has an Unauthenticated Password Hash Oracle via encryptPass.json.php
CVSS 5.3
AVideo affected by Session Hijacking via Unauthenticated Session ID Disclosure with Permissive CORS
CVSS 8.1
WWBN AVideo <25.0 - Info Disclosure
CVSS 5.3
WWBN AVideo <24.0 - SQL Injection
CVSS 9.8
WWBN AVideo <24.0 - Authenticated RCE
CVSS 8.8
WWBN AVideo <21.0 - XSS
CVSS 6.1
WWBN AVideo <22.0 - SSRF
CVSS 8.1
Wwbn Avideo < 20.0 - Missing Authentication
CVSS 9.1
Wwbn Avideo < 20.0 - IDOR
CVSS 6.5
Wwbn Avideo < 20.0 - IDOR
CVSS 8.8
Wwbn Avideo < 20.0 - IDOR
CVSS 8.8
Wwbn Avideo < 20.0 - IDOR
CVSS 8.1
Wwbn Avideo < 20.0 - Open Redirect
CVSS 6.1
Wwbn Avideo < 20.0 - Open Redirect
CVSS 6.1
AVideo <20.1 - Info Disclosure
CVSS 7.5
AVideo <20.1 - Info Disclosure
CVSS 7.5