All verified exploits

CVE-2026-33478 Unauthenticated RCE via CloneSite Plugin

Deterministic critical AVideo Added cve-verified-cve-2026-33478

Detects AVideo instances where the CloneSite plugin exposes clone configuration data (including secret keys) without authentication. These keys enable a full attack chain: database dump, credential extraction, and OS command injection via rsync. Update AVideo past commit c85d076 or to the next release.

Is your app exploitable through CVE-2026-33478?

Scan your domain free