VYPR

Streaming Engine

by Wowza

CVEs (26)

  • CVE-2024-52055MedNov 21, 2024
    risk 0.32cvss 4.9epss 0.01

    Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to read any file on the file system if the target directory contains an XML definition file.

  • CVE-2024-52054LowNov 21, 2024
    risk 0.18cvss 2.7epss 0.01

    Path Traversal in the Manager component of Wowza Streaming Engine below 4.9.1 allows an administrator user to create an XML definition file anywhere on the file system.

  • CVE-2016-20036Mar 15, 2026
    risk 0.00cvss epss 0.00

    Wowza Streaming Engine 4.5.0 contains multiple reflected cross-site scripting vulnerabilities in the enginemanager interface where input passed through various parameters is not properly sanitized before being returned to users. Attackers can inject malicious script code through…

  • CVE-2016-20035Mar 15, 2026
    risk 0.00cvss epss 0.00

    Wowza Streaming Engine 4.5.0 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions by crafting malicious web pages. Attackers can trick logged-in administrators into visiting a malicious site that submits POST requests to the…

  • CVE-2016-20034Mar 15, 2026
    risk 0.00cvss epss 0.00

    Wowza Streaming Engine 4.5.0 contains a privilege escalation vulnerability that allows authenticated read-only users to elevate privileges to administrator by manipulating POST parameters. Attackers can send POST requests to the user edit endpoint with accessLevel set to 'admin'…

  • CVE-2016-20033Mar 15, 2026
    risk 0.00cvss epss 0.00

    Wowza Streaming Engine 4.5.0 contains a local privilege escalation vulnerability that allows authenticated users to escalate privileges by replacing executable files due to improper file permissions granting full access to the Everyone group. Attackers can replace the…

Page 2 of 2