Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Sin puntuar | — | — | CP Media PlayerAI | 7/10/2026 | 7/10/2026 | The CP Media Player WordPress plugin before 1.3.4 does not perform a capability check on its settings-page handler, allowing users with only Contributor-level access to create, modify, duplicate and delete the site-wide media player configurations and change a CP Media Player WordPress plugin before 1.3.4 option that… | |
| Aplazada | Media (6.5) | 0.16% | — | Sonaar MP3 Audio Player FOR Music Radio PodcastAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.14.2. | |
| Aplazada | Media (6.5) | 0.16% | — | Brainstormforce Presto PlayerAI | 5/10/2026 | 6/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Brainstorm Force Presto Player presto-player allows Stored XSS.This issue affects Presto Player: from n/a through 4.5.2. | |
| Aplazada | Alta (8.7) | 0.53% | — | Codeart Google MP3 Audio PlayerAI | 2/10/2026 | 6/10/2026 | CodeArt Google MP3 Audio Player plugin (google-mp3-audio-player) for WordPress through 1.0.11 contains an unauthenticated arbitrary file read vulnerability that allows remote attackers to retrieve sensitive files by supplying a path-traversal payload in the file parameter of direct_download.php. Attackers can request… | |
| Aplazada | Alta (7.2) | 0.37% | — | Music Player FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. | |
| Aplazada | Alta (7.1) | 0.18% | — | Longtailvideo JW PlayerAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. | |
| Aplazada | Media (6.8) | 0.24% | — | Audio Player BlockAI | 30/9/2026 | 30/9/2026 | The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or… | |
| Pendiente de análisis | Alta (8.5) | 0.17% | — | Videolan VLC Media PlayerAI | 29/9/2026 | 30/9/2026 | VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua… | |
| Aplazada | Baja (1.9) | 0.17% | — | Flb-music-playerAI | 28/9/2026 | 28/9/2026 | A vulnerability has been found in FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1. This impacts the function path.join of the file /src/main/core/createParsedTrack.ts. The manipulation leads to path traversal. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The… | |
| Aplazada | Alta (8.7) | 0.56% | — | Paella PlayerAIOpencastAI | 17/9/2026 | 24/9/2026 | Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11. | |
| Aplazada | Crítica (9.8) | 0.69% | — | Actions Semiconductor CO LTD Tool - Media Player UtilitiesAI | 9/9/2026 | 10/9/2026 | An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components | |
| Aplazada | Media (5.3) | 0.24% | — | Videolan VLC Media PlayerAI | 9/9/2026 | 14/9/2026 | Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build… | |
| Aplazada | Alta (7.3) | 0.12% | — | Videolan VLC Media PlayerAI | 9/9/2026 | 18/9/2026 | VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process. | |
| Aplazada | Media (6.8) | 0.39% | — | Video Player FOR YoutubeAI | 5/9/2026 | 8/9/2026 | The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks and read arbitrary data from the database. | |
| Aplazada | Alta (7.1) | 0.25% | — | Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI | 2/9/2026 | 2/9/2026 | Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions. | |
| Aplazada | Media (6.4) | 0.19% | — | Easy Waveform PlayerAI | 2/9/2026 | 3/9/2026 | The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… | |
| Aplazada | Media (4.9) | 0.33% | — | Fluent Player PROAI | 27/8/2026 | 28/8/2026 | Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Music Player FOR WoocommerceAI | 27/8/2026 | 28/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | CP Media PlayerAI | 27/8/2026 | 28/8/2026 | Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions. | |
| Aplazada | Crítica (9.1) | 0.44% | — | Zyplayer-docAI | 26/8/2026 | 31/8/2026 | Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download(). | |
| Aplazada | Media (5.3) | 0.32% | — | Podcast PlayerAI | 10/8/2026 | 26/8/2026 | The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML. | |
| Aplazada | Media (5.3) | 0.29% | — | Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. | |
| Aplazada | Media (5.3) | 0.29% | — | YT PlayerAI | 23/7/2026 | 23/9/2026 | Missing Authorization vulnerability in bPlugins YT Player yt-player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YT Player: from n/a through 2.1.2. | |
| Aplazada | Alta (8.3) | 0.40% | — | Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.40% | — | Geovision GeowebplayerAIGeovision Gv-vmsAIGeovision Gv-cloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… |