CPE
critical
advisory
WWBN AVideo SSRF Filter Bypass via NAT64 Hex Encoding
3 rules 8 TTPs 1 CVEWWBN AVideo is vulnerable to a Server-Side Request Forgery (SSRF) bypass in the isSSRFSafeURL function due to improper normalization of hex-encoded NAT64 addresses.
AVideo +3
credential-access
web-application
authentication-bypass
web-application-vulnerability
path-traversal
reconnaissance
web-vulnerability
csrf
+3
3r
8t
1c
updated
medium
advisory
Unauthorized Memcached Data Manipulation via CVE-2026-29093
1 rule 1 TTP 1 CVEUnauthorized actors can leverage the lack of native authentication in Memcached to perform data manipulation or session hijacking, as identified in CVE-2026-29093.
Memcached
network-security
cve-2026-29093
impact
1r
1t
1c
high
advisory
AVideo OS Command Injection via Unescaped m3u8 URL (CVE-2026-45578)
2 rules 1 TTP 2 CVEs 3 IOCsAVideo is vulnerable to OS command injection (CVE-2026-45578) in the `on_publish.php` file due to improper sanitization of the m3u8 URL, allowing attackers to execute arbitrary commands by injecting shell metacharacters.
AVideo +1
command injection
webserver
2r
1t
2c
3i
updated