Streaming Engine

Wowza · 26 CVEs

CVE-2016-20036
MEDIUM

Wowza Streaming Engine 4.5.0 Multiple Cross-Site Scripting Vulnerabilities

Mar 15, 2026

CVE-2016-20035
MEDIUM

Wowza Streaming Engine 4.5.0 CSRF via user edit endpoint

Mar 15, 2026

CVE-2016-20034
HIGH

Wowza Streaming Engine 4.5.0 Privilege Escalation via user edit

Mar 15, 2026

CVE-2016-20033
HIGH

Wowza Streaming Engine 4.5.0 Local Privilege Escalation via nssm_x64.exe

Mar 15, 2026

CVE-2024-52056
MEDIUM

Application Delete Path Traversal in Wowza Streaming Engine

Nov 21, 2024

CVE-2024-52055
HIGH

Application Copy Path Traversal in Wowza Streaming Engine

Nov 21, 2024

CVE-2024-52054
MEDIUM

Application Creation Path Traversal in Wowza Streaming Engine

Nov 21, 2024

CVE-2024-52053
HIGH

Stored Cross-Site Scripting in Wowza Streaming Engine

Nov 21, 2024

CVE-2024-52052
CRITICAL

Stream Target Remote Code Execution in Wowza Streaming Engine

Nov 21, 2024

CVE-2021-35492
MEDIUM

Wowza Streaming Engine through 4.8.11+5 could allow an authenticated, remote attacker to exhaust filesystem resources v…

Oct 5, 2021

CVE-2021-35491
HIGH

A Cross-Site Request Forgery (CSRF) vulnerability in Wowza Streaming Engine through 4.8.11+5 allows a remote attacker t…

Oct 5, 2021

CVE-2021-31539
MEDIUM

Wowza Streaming Engine before 4.8.8.01 (in a default installation) has cleartext passwords stored in the conf/admin.pas…

Apr 23, 2021

CVE-2021-31540
HIGH

Wowza Streaming Engine through 4.8.5 (in a default installation) has incorrect file permissions of configuration files…

Apr 23, 2021

CVE-2019-19455
HIGH

Wowza Streaming Engine before 4.8.5 has Insecure Permissions which may allow a local attacker to escalate privileges in…

Aug 3, 2020

CVE-2019-19453
MEDIUM

Wowza Streaming Engine before 4.8.5 allows XSS (issue 1 of 2). An authenticated user, with access to the proxy license…

Aug 3, 2020

CVE-2019-19456
MEDIUM

A Reflected XSS was found in the server selection box inside the login page at: enginemanager/loginfailed.html in Wowza…

May 18, 2020

CVE-2019-19454
HIGH

An arbitrary file download was found in the "Download Log" functionality of Wowza Streaming Engine <= 4.x.x. This issue…

May 18, 2020

CVE-2020-9004
HIGH

A remote authenticated authorization-bypass vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any read-o…

Apr 14, 2020

CVE-2019-7655
MEDIUM

Wowza Streaming Engine 4.8.0 and earlier from multiple authenticated XSS vulnerabilities via the (1) customList%5B0%5D.…

Jan 29, 2020

CVE-2019-7656
HIGH

A privilege escalation vulnerability in Wowza Streaming Engine 4.8.0 and earlier allows any unprivileged Linux user to…

Jan 29, 2020

CVE-2019-7654
MEDIUM

Wowza Streaming Engine 4.8.0 and earlier suffers from multiple CSRF vulnerabilities. For example, an administrator, by…

Jan 29, 2020

CVE-2018-19365
CRITICAL

The REST API in Wowza Streaming Engine 4.7.4.01 allows traversal of the directory structure and retrieval of a file via…

Mar 18, 2019

CVE-2017-16922
MEDIUM

In com.wowza.wms.timedtext.http.HTTPProviderCaptionFile in Wowza Streaming Engine before 4.7.1, traversal of the direct…

Mar 5, 2018

CVE-2018-7049
MEDIUM

An issue was discovered in Wowza Streaming Engine before 4.7.1. There is an XSS vulnerability in the HTTP providers (co…

Mar 1, 2018

CVE-2018-7048
HIGH

An issue was discovered in Wowza Streaming Engine before 4.7.1. There is a denial of service (memory consumption) via a…

Mar 1, 2018

Showing 1 to 25 of 26 CVEs