Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.27% | — | Latin Angels Music HD Project Latin Angels Music HD | 23/9/2014 | 17/6/2026 | The Latin Angels Music HD (aka com.applizards.lafreetj) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Groovemusic Project Groovemusic | 19/9/2014 | 17/6/2026 | The GrooveMusic (aka com.mobincube.android.sc_2HKFF) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Musicjustnow 10000 Kindle Books Downloads | 18/9/2014 | 17/6/2026 | The 10000 Kindle Books Downloads (aka com.ww10000KindleBooksLatestnBestSellers) application 0.312 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Vevo-watch HD Music Videos | 9/9/2014 | 17/6/2026 | The Vevo - Watch HD Music Videos (aka com.vevo) application 2.0.27 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 5.7% | 💥 Exploit | Musanim Music Animation Machine Midi Player | 20/1/2011 | 16/6/2026 | Music Animation Machine MIDI Player 2006aug19 Release 035 and possibly other versions allows user-assisted remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a long line in a MIDI (.mid) file. | |
| Modificada | Alta (9.3) | 16% | 💥 Exploit | Musanim Music Animation Machine Midi Player | 20/1/2011 | 16/6/2026 | Stack-based buffer overflow in Music Animation Machine MIDI Player 2006aug19 Release 035 and possibly other versions allows user-assisted remote attackers to execute arbitrary code via a long line in a .mamx file. | |
| Modificada | Media (6.8) | 4.8% | 💥 Exploit | Danieljamesscott COM Music | 25/7/2010 | 16/6/2026 | Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the cid parameter to album.html. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Musicboxv2 Musicbox | 23/4/2010 | 16/6/2026 | SQL injection vulnerability in genre_artists.php in MusicBox 3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (9.3) | 4.8% | 💥 Exploit | Evils-world Ew-musicplayer | 29/3/2010 | 16/6/2026 | Stack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Masa2el Music City | 23/3/2010 | 16/6/2026 | SQL injection vulnerability in index.php in MASA2EL Music City 1.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a singer action. | |
| Modificada | Alta (7.5) | 0.90% | 💥 Exploit | Itamar Elharar COM Musicgallery | 7/12/2009 | 16/6/2026 | SQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an itempage action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third… | |
| Modificada | Alta (9.3) | 5.8% | 💥 Exploit | Assistanttools Music TAG Editor | 27/10/2009 | 16/6/2026 | Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 0.99% | 💥 Exploit | Bpowerhouse Bpmusic | 30/9/2009 | 16/6/2026 | SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter. | |
| Modificada | Alta (9.3) | 6.1% | 💥 Exploit | Otbcode Easy Music Player | 25/9/2009 | 16/6/2026 | Stack-based buffer overflow in Easy Music Player 1.0.0.2 allows remote attackers to execute arbitrary code via a crafted .wav file. | |
| Modificada | Media (6.8) | 0.87% | 💥 Exploit | Sappy.dk Impleo Music Collection | 22/6/2009 | 16/6/2026 | SQL injection vulnerability in admin/login.php in Impleo Music Collection 2.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (4.3) | 1.3% | 💥 Exploit | Sappy.dk Impleo Music Collection | 22/6/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in Impleo Music Collection 2.0 allows remote attackers to inject arbitrary web script or HTML via the sort parameter. | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomla COM MusicaMambo-foundation COM Musica | 21/2/2009 | 16/6/2026 | SQL injection vulnerability in the com_musica module in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Jesse-web Jmweb MP3 Music Audio Search AND Download Script | 9/10/2008 | 16/6/2026 | Multiple directory traversal vulnerabilities in JMweb MP3 Music Audio Search and Download Script allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the src parameter to (1) listen.php and (2) download.php. | |
| Modificada | Alta (7.5) | 1.0% | 💥 Exploit | Nersoft Live Music Plus | 28/7/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a Singer action. | |
| Modificada | Media (4.3) | 1.1% | — | Maianscriptworld Maian Music | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Music 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter in a search action to index.php, and the (2) msg_script parameter to admin/inc/footer.php. | |
| Modificada | Alta (7.5) | 1.1% | — | Maianscriptworld Maian Music | 14/5/2008 | 16/6/2026 | SQL injection vulnerability in index.php in Maian Music 1.1 allows remote attackers to execute arbitrary SQL commands via the album parameter in an album action. | |
| Modificada | Alta (7.5) | 0.98% | 💥 Exploit | Musicbox | 9/5/2008 | 16/6/2026 | SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary SQL commands via the artistId parameter. | |
| Modificada | Media (4.3) | 8.1% | 💥 Exploit | Yahoo Music Jukebox | 6/2/2008 | 16/6/2026 | Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddBitmap method. | |
| Modificada | Media (4.3) | 9.2% | 💥 Exploit | Yahoo Music Jukebox | 6/2/2008 | 16/6/2026 | Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows remote attackers to execute arbitrary code via a long argument to the AddImage method. | |
| Modificada | Media (4.3) | 7.6% | 💥 Exploit | Yahoo Music Jukebox | 6/2/2008 | 16/6/2026 | Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddButton method, a different vulnerability than CVE-2008-0623. |