Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
2395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.91% | — | Videolan VLC Media Player | 7/11/2023 | 17/6/2026 | Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length. | |
| Modificada | Crítica (9.8) | 1.1% | — | Videolan VLC Media Player | 7/11/2023 | 17/6/2026 | Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption. | |
| Modificada | Media (6.1) | 0.33% | — | Web-dorado Spidervplayer | 18/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in WebDorado SpiderVPlayer plugin <= 1.5.22 versions. | |
| Modificada | Media (5.4) | 0.31% | — | Getbutterfly Youtube Playlist Player | 18/10/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Ciprian Popescu YouTube Playlist Player plugin <= 4.6.7 versions. | |
| Modificada | Alta (8.8) | 0.44% | — | Mekshq Meks Audio PlayerMekshq Meks Easy ADS WidgetMekshq Meks Easy MapsMekshq Meks Easy Photo Feed Widget+6 | 3/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Meks Video Importer, Meks Time Ago, Meks ThemeForest Smart Widget, Meks Smart Author Widget, Meks Audio Player, Meks Easy Maps, Meks Easy Photo Feed Widget, Meks Simple Flickr Widget, Meks Easy Ads Widget, Meks Smart Social Widget plugins leading to dismiss or the… | |
| Modificada | Media (5.4) | 0.36% | — | Essentialplugin Audio Player With Playlist Ultimate | 3/9/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in WP OnlineSupport, Essential Plugin Audio Player with Playlist Ultimate plugin <= 1.2.2 versions. | |
| Modificada | Media (6.1) | 0.56% | — | Foliovision FV Flowplayer Video Player | 25/8/2023 | 17/6/2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘_fv_player_user_video’ parameter saved via the 'save' function hooked via init, and the plugin is also vulnerable to Arbitrary Usermeta Update via the 'save' function in versions up to, and including, 7.5.37.7212… | |
| Modificada | Media (6.1) | 0.40% | — | Foliovision FV Flowplayer Video Player | 18/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.32.7212 versions. | |
| Modificada | Media (6.1) | 0.38% | — | Radioforge Radio Forge Muses Player With Skins | 27/7/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Radio Forge Muses Player with Skins plugin <= 2.5 versions. | |
| Modificada | Media (5.5) | 0.43% | — | Tsingsee Easyplayerpro | 5/6/2023 | 17/6/2026 | A buffer overflow in EasyPlayerPro-Win v3.2.19.0106 to v3.6.19.0823 allows attackers to cause a Denial of Service (DoS) via a crafted XML file. | |
| Modificada | Alta (7.5) | 1.1% | — | Harbingergroup Office Player | 5/6/2023 | 17/6/2026 | OfflinePlayerService.exe in Harbinger Offline Player 4.0.6.0.2 allows directory traversal as LocalSystem via ..\ in a URL. | |
| Modificada | Alta (8.8) | 0.27% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Cross Site Request Forgery (CSRF). | |
| Modificada | Media (5.4) | 0.36% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level. | |
| Modificada | Crítica (9.1) | 0.53% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za. | |
| Modificada | Crítica (9.8) | 0.68% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions. | |
| Modificada | Media (5.4) | 0.34% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 suffers from Multiple Stored Cross-Site Scripting (XSS) vulnerabilities via Shop Beat Control Panel found at www.shopbeat.co.za controlpanel.shopbeat.co.za. | |
| Modificada | Media (5.3) | 0.75% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. Information Exposure Through Directory Listing vulnerability in "studio" software of Shop Beat. This issue affects: Shop Beat studio studio versions prior to 3.2.57 on arm. | |
| Modificada | Alta (8.8) | 0.26% | — | Getbutterfly Youtube Playlist Player | 28/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Ciprian Popescu YouTube Playlist Player plugin <= 4.6.4 versions. | |
| Modificada | Crítica (9.8) | 1.3% | — | Shanling Eddict PlayerShanling Mtouch OS | 25/4/2023 | 17/6/2026 | A vulnerability in the Wi-Fi file transfer module of Shanling M5S Portable Music Player with Shanling MTouch OS v4.3 and Shanling M2X Portable Music Player with Shanling MTouch OS v3.3 allows attackers to arbitrarily read, delete, or modify any critical system files via directory traversal. | |
| Modificada | Crítica (9.8) | 0.71% | — | Contus HD FLV Player | 9/4/2023 | 16/6/2026 | A vulnerability was found in HD FLV PLayer Plugin up to 1.7 on WordPress. It has been rated as critical. Affected by this issue is the function hd_add_media/hd_update_media of the file functions.php. The manipulation of the argument name leads to sql injection. The attack may be launched remotely. Upgrading to version… | |
| Modificada | Media (4.8) | 0.37% | — | Streamweasels Twitch Player | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in StreamWeasels Twitch Player plugin <= 2.1.0 versions. | |
| Modificada | Alta (7.8) | 0.37% | — | Pandora Kmplayer | 30/3/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in KMPlayer 4.2.2.73. This issue affects some unknown processing in the library SHFOLDER.dll. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. The… | |
| Modificada | Crítica (9.8) | 0.87% | — | Simple Music Player Project Simple Music Player | 18/3/2023 | 17/6/2026 | A vulnerability classified as critical has been found in SourceCodester Simple Music Player 1.0. Affected is an unknown function of the file save_music.php. The manipulation of the argument filename leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (5.4) | 0.74% | — | Wpaudio MP3 Player Project Wpaudio MP3 Player | 6/3/2023 | 17/6/2026 | The WPaudio MP3 Player WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (6.1) | 0.51% | — | Learnetic Icplayer | 6/3/2023 | 17/6/2026 | A vulnerability was found in icplayer up to 0.818. It has been rated as problematic. Affected by this issue is some unknown functionality of the file addons/Commons/src/tts-utils.js. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 0.819 is able to address this… |