Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.25% | — | Foliovision FV Flowplayer Video PlayerAI | 24/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.43.7212. | |
| Aplazada | Media (5.4) | 0.35% | — | Softlabbd Radio PlayerAI | 17/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | |
| Aplazada | Media (5.4) | 0.21% | — | Codepeople CP Media PlayerAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CodePeople CP Media Player.This issue affects CP Media Player: from n/a through 1.1.3. | |
| Modificada | Alta (7.5) | 0.55% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 10/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10.1. | |
| Analizada | Media (4.7) | 0.50% | — | Prestoplayer Presto Player | 10/4/2024 | 17/6/2026 | The Ultimate Video Player For WordPress WordPress plugin before 2.2.3 does not have proper capability check when updating its settings via a REST route, allowing Contributor and above users to update them. Furthermore, due to the lack of escaping in one of the settings, this also allows them to perform Stored XSS… | |
| Modificada | Media (5.4) | 0.34% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 31/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1. | |
| Modificada | Alta (7.6) | 0.48% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 29/3/2024 | 17/6/2026 | Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.1. | |
| Aplazada | Media (5.4) | 0.20% | — | Cincopa Post Video PlayersAI | 27/3/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Cincopa Post Video Players.This issue affects Post Video Players: from n/a through 1.159. | |
| Modificada | Media (5.4) | 0.34% | — | Softlabbd Radio Player | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in SoftLab Radio Player allows Stored XSS.This issue affects Radio Player: from n/a through 2.0.73. | |
| Aplazada | Media (6.5) | 0.33% | — | Podlove WEB PlayerAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podlove Podlove Web Player allows Stored XSS.This issue affects Podlove Web Player: from n/a through 5.7.1. | |
| Aplazada | Media (6.5) | 0.32% | — | Tipsandtricks-hq Compact WP Audio PlayerAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Compact WP Audio Player allows Stored XSS.This issue affects Compact WP Audio Player: from n/a through 1.9.9. | |
| Aplazada | Alta (7.1) | 0.39% | — | Foliovision FV Flowplayer Video PlayerAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.41.7212. | |
| Aplazada | Media (6.5) | 0.48% | — | Softlabbd Radio PlayerAI | 26/3/2024 | 17/6/2026 | Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | |
| Aplazada | Media (6.5) | 0.34% | — | Foliovision FV Flowplayer Video PlayerAI | 19/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Foliovision: Making the web work for you FV Flowplayer Video Player allows Stored XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.41.7212. | |
| Modificada | Media (5.4) | 0.33% | — | Noorsplugin Easy Video Player | 1/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in naa986 Easy Video Player allows Stored XSS.This issue affects Easy Video Player: from n/a through 1.2.2.10. | |
| Modificada | Crítica (9.8) | 11% | 💥 Exploit | Bplugins Html5 Video Player | 30/1/2024 | 17/6/2026 | The 'HTML5 Video Player' WordPress Plugin, version < 2.5.25 is affected by an unauthenticated SQL injection vulnerability in the 'id' parameter in the 'get_view' function. | |
| Modificada | Alta (7.2) | 0.62% | — | Svnlabs Html5 MP3 Player With Folder Feedburner Playlist Free | 8/1/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist Free: from n/a through 2.8.0. | |
| Modificada | Alta (7.2) | 0.62% | — | Svnlabs Html5 Soundcloud Player With Playlist Free | 8/1/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 SoundCloud Player with Playlist Free.This issue affects HTML5 SoundCloud Player with Playlist Free: from n/a through 2.8.0. | |
| Modificada | Alta (8.8) | 0.62% | — | Svnlabs Html5 MP3 Player With Playlist Free | 8/1/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through 3.0.0. | |
| Modificada | Media (5.4) | 0.53% | — | Bplugins Html5 Video Player | 1/1/2024 | 17/6/2026 | The Html5 Video Player WordPress plugin before 2.5.19 does not sanitise and escape some of its player settings, which combined with missing capability checks around the plugin could allow any authenticated users, such as low as subscribers to perform Stored Cross-Site Scripting attacks against high privilege users… | |
| Modificada | Media (6.1) | 0.40% | — | Hdwplayer HDW Player | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mr. Hdwplayer HDW Player Plugin (Video Player & Video Gallery) allows Reflected XSS.This issue affects HDW Player Plugin (Video Player & Video Gallery): from n/a through 5.0. | |
| Modificada | Alta (7.8) | 0.31% | — | Baidu Ttplayer | 7/12/2023 | 17/6/2026 | DLL hijacking vulnerability in TTplayer version 7.0.2, allows local attackers to escalate privileges and execute arbitrary code via urlmon.dll. | |
| Modificada | Alta (7.8) | 0.32% | — | Sohu Video Player | 30/11/2023 | 17/6/2026 | An Untrusted search path vulnerability in Sohu Video Player 7.0.15.0 allows local users to gain escalated privileges through the version.dll file in the current working directory. | |
| Modificada | Media (4.8) | 0.39% | — | Web-dorado Spidervplayer | 30/11/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WebDorado SpiderVPlayer allows Stored XSS.This issue affects SpiderVPlayer: from n/a through 1.5.22. | |
| Modificada | Alta (7.8) | 0.28% | — | Videolan VLC Media Player | 22/11/2023 | 17/6/2026 | A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM. |