Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

282 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.27%—Latin Angels Music HD Project Latin Angels Music HD23/9/201417/6/2026
The Latin Angels Music HD (aka com.applizards.lafreetj) application 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Groovemusic Project Groovemusic19/9/201417/6/2026
The GrooveMusic (aka com.mobincube.android.sc_2HKFF) application 2.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Musicjustnow 10000 Kindle Books Downloads18/9/201417/6/2026
The 10000 Kindle Books Downloads (aka com.ww10000KindleBooksLatestnBestSellers) application 0.312 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Vevo-watch HD Music Videos9/9/201417/6/2026
The Vevo - Watch HD Music Videos (aka com.vevo) application 2.0.27 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (9.3)5.7%💥 ExploitMusanim Music Animation Machine Midi Player20/1/201116/6/2026
Music Animation Machine MIDI Player 2006aug19 Release 035 and possibly other versions allows user-assisted remote attackers to cause a denial of service (crash) and possibly have other unspecified impact via a long line in a MIDI (.mid) file.
ModificadaAlta (9.3)16%💥 ExploitMusanim Music Animation Machine Midi Player20/1/201116/6/2026
Stack-based buffer overflow in Music Animation Machine MIDI Player 2006aug19 Release 035 and possibly other versions allows user-assisted remote attackers to execute arbitrary code via a long line in a .mamx file.
ModificadaMedia (6.8)4.8%💥 ExploitDanieljamesscott COM Music25/7/201016/6/2026
Directory traversal vulnerability in the Music Manager component for Joomla! allows remote attackers to read arbitrary files and possibly have unspecified other impact via a .. (dot dot) in the cid parameter to album.html.
ModificadaAlta (7.5)1.3%💥 ExploitMusicboxv2 Musicbox23/4/201016/6/2026
SQL injection vulnerability in genre_artists.php in MusicBox 3.3 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (9.3)4.8%💥 ExploitEvils-world Ew-musicplayer29/3/201016/6/2026
Stack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long string in a malformed playlist (.m3u) file. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)1.0%💥 ExploitMasa2el Music City23/3/201016/6/2026
SQL injection vulnerability in index.php in MASA2EL Music City 1.0 and 1.1 allows remote attackers to execute arbitrary SQL commands via the id parameter in a singer action.
ModificadaAlta (7.5)0.90%💥 ExploitItamar Elharar COM Musicgallery7/12/200916/6/2026
SQL injection vulnerability in the Itamar Elharar MusicGallery (com_musicgallery) component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in an itempage action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third…
ModificadaAlta (9.3)5.8%💥 ExploitAssistanttools Music TAG Editor27/10/200916/6/2026
Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)0.99%💥 ExploitBpowerhouse Bpmusic30/9/200916/6/2026
SQL injection vulnerability in music.php in BPowerHouse BPMusic 1.0 allows remote attackers to execute arbitrary SQL commands via the music_id parameter.
ModificadaAlta (9.3)6.1%💥 ExploitOtbcode Easy Music Player25/9/200916/6/2026
Stack-based buffer overflow in Easy Music Player 1.0.0.2 allows remote attackers to execute arbitrary code via a crafted .wav file.
ModificadaMedia (6.8)0.87%💥 ExploitSappy.dk Impleo Music Collection22/6/200916/6/2026
SQL injection vulnerability in admin/login.php in Impleo Music Collection 2.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaMedia (4.3)1.3%💥 ExploitSappy.dk Impleo Music Collection22/6/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Impleo Music Collection 2.0 allows remote attackers to inject arbitrary web script or HTML via the sort parameter.
ModificadaAlta (7.5)0.97%💥 ExploitJoomla COM MusicaMambo-foundation COM Musica21/2/200916/6/2026
SQL injection vulnerability in the com_musica module in Joomla! and Mambo allows remote attackers to execute arbitrary SQL commands via the id parameter to index.php.
ModificadaAlta (7.5)2.5%💥 ExploitJesse-web Jmweb MP3 Music Audio Search AND Download Script9/10/200816/6/2026
Multiple directory traversal vulnerabilities in JMweb MP3 Music Audio Search and Download Script allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the src parameter to (1) listen.php and (2) download.php.
ModificadaAlta (7.5)1.0%💥 ExploitNersoft Live Music Plus28/7/200816/6/2026
SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter in a Singer action.
ModificadaMedia (4.3)1.1%—Maianscriptworld Maian Music14/5/200816/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Maian Music 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter in a search action to index.php, and the (2) msg_script parameter to admin/inc/footer.php.
ModificadaAlta (7.5)1.1%—Maianscriptworld Maian Music14/5/200816/6/2026
SQL injection vulnerability in index.php in Maian Music 1.1 allows remote attackers to execute arbitrary SQL commands via the album parameter in an album action.
ModificadaAlta (7.5)0.98%💥 ExploitMusicbox9/5/200816/6/2026
SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary SQL commands via the artistId parameter.
ModificadaMedia (4.3)8.1%💥 ExploitYahoo Music Jukebox6/2/200816/6/2026
Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddBitmap method.
ModificadaMedia (4.3)9.2%💥 ExploitYahoo Music Jukebox6/2/200816/6/2026
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows remote attackers to execute arbitrary code via a long argument to the AddImage method.
ModificadaMedia (4.3)7.6%💥 ExploitYahoo Music Jukebox6/2/200816/6/2026
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddButton method, a different vulnerability than CVE-2008-0623.
Orbitaley — Vulnerabilidades