FOFA[verified]@fofabotDisclosure
The post announces a severe unauthenticated RCE (CVE-2026-33478) in AVideo via CloneSite, citing a CVSS score of 10 and providing a FOFA query and GitHub advisory for reference.
maruomosquit[verified]@maru1151157Patch
The tweet discloses CVE-2026-33478, which allows unauthenticated remote code execution in CloneSite plugin up to AVideo 26.0 through key leakage and command injection, and recommends upgrading the plugin to mitigate the vulnerability.
pdnuclei-bot@pdnuclei_botDisclosure
The post announces CVE‑2026‑33478 as a critical remote code execution flaw in WWBN AVideo <= 26.0’s CloneSite plugin, links to a ProjectDiscovery library for detection, but does not provide exploit code, active usage claims, or remediation details.
PulsePatch.io@pulsepatchioDisclosure
The post details an unauthenticated RCE vulnerability (CVE‑2026‑33478) in AVideo, describing its multi‑step exploitation chain and recommending network restriction as a workaround, but it does not provide a PoC or evidence of active exploitation.
CTIWatch@ctiwatchcloudGeneral
The tweet lists three CVEs with CVSS 10.0, but offers no additional technical details, PoCs, exploit code, or evidence of active exploitation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
The source provides a brief disclosure of a new RCE vulnerability (CVE‑2026‑33478) affecting the WWBN AVideo Platform, but lacks detailed technical information, PoC, or exploitation evidence.
CVEFind.com@CveFindComDisclosure
The post announces a CVE-2026-33478 vulnerability in AVideo's CloneSite plugin, highlighting a remote code execution risk that allows attackers to access sensitive data through exposed endpoints, affecting versions up to 26.0.
The Hacker Wire@TheHackerWireDisclosure
A new critical CVE in WWBN AVideo’s CloneSite plugin chain allows unauthenticated exploitation, with initial details announced in the linked article; no evidence of active exploitation or available patch is provided.