Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.51% | — | Learnetic Icplayer | 6/3/2023 | 17/6/2026 | A vulnerability was found in icplayer up to 0.819. It has been declared as problematic. Affected by this vulnerability is the function AddonText_Selection_create of the file addons/Text_Selection/src/presenter.js. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to version… | |
| Modificada | Alta (7.3) | 0.11% | — | Google Youtube Android Player API | 1/3/2023 | 17/6/2026 | The YouTube Embedded 1.2 SDK binds to a service within the YouTube Main App. After binding, a remote context is created with the flags Context.CONTEXT_INCLUDE_CODE | Context.CONTEXT_IGNORE_SECURITY. This allows the client app to remotely load code from YouTube Main App by retrieving the Main App’s ClassLoader. A… | |
| Analizada | Alta (7.5) | 1.2% | — | Musicpd Music Player Daemon | 26/2/2023 | 17/6/2026 | In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer. | |
| Modificada | Alta (8.8) | 0.27% | — | Foliovision FV Flowplayer Video Player | 14/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in FolioVision FV Flowplayer Video Player plugin <= 7.5.30.7212 versions. | |
| Modificada | Media (5.4) | 0.57% | — | Bplugins Html5 Audio Player | 6/2/2023 | 17/6/2026 | The Html5 Audio Player WordPress plugin before 2.1.12 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.47% | — | Tipsandtricks-hq Compact WP Audio Player | 23/1/2023 | 17/6/2026 | The Compact WP Audio Player WordPress plugin before 1.9.8 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such… | |
| Modificada | Alta (7.5) | 0.93% | — | Musicpd Music Player Daemon | 10/1/2023 | 17/6/2026 | An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input. | |
| Modificada | Media (5.4) | 0.57% | — | Open Media Player | 27/12/2022 | 17/6/2026 | A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation of the argument ttml_url leads to cross site scripting. The attack can be initiated remotely.… | |
| Modificada | Media (5.4) | 0.48% | — | Wphowto Videojs Html5 Player | 19/12/2022 | 17/6/2026 | The Videojs HTML5 Player WordPress plugin before 1.1.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.48% | — | Wphowto Flowplayer Video Player | 19/12/2022 | 17/6/2026 | The Flowplayer Video Player WordPress plugin before 1.0.5 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.51% | — | Noorsplugin Easy Video Player | 19/12/2022 | 17/6/2026 | The Easy Video Player WordPress plugin before 1.2.2.3 does not sanitize and escapes some parameters, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks. | |
| Modificada | Alta (7.8) | 0.28% | — | Altair Hyperview Player | 13/12/2022 | 17/6/2026 | Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to improper validation of array index vulnerability during processing of H3D files. A DWORD value from a PoC file is extracted and used as an index to write to a buffer, leading to memory corruption. | |
| Modificada | Alta (7.8) | 0.31% | — | Altair Hyperview Player | 13/12/2022 | 17/6/2026 | Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to increment a counter leading to memory corruption. | |
| Modificada | Alta (7.8) | 0.29% | — | Altair Hyperview Player | 13/12/2022 | 17/6/2026 | Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to the use of uninitialized memory vulnerability during parsing of H3D files. A DWORD is extracted from an uninitialized buffer and, after sign extension, is used as an index into a stack variable to increment a counter leading to memory corruption. | |
| Modificada | Alta (7.8) | 0.29% | — | Altair Hyperview Player | 13/12/2022 | 17/6/2026 | Altair HyperView Player versions 2021.1.0.27 and prior perform operations on a memory buffer but can read from or write to a memory location outside of the intended boundary of the buffer. This hits initially as a read access violation, leading to a memory corruption situation. | |
| Modificada | Alta (7.8) | 0.68% | — | Videolan VLC Media PlayerDebian Linux | 6/12/2022 | 17/6/2026 | An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions. | |
| Modificada | Alta (7.5) | 0.73% | — | Kakaocorp Potplayer | 1/12/2022 | 17/6/2026 | A vulnerability classified as problematic has been found in Kakao PotPlayer. This affects an unknown part of the component MID File Handler. The manipulation leads to denial of service. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The associated… | |
| Modificada | Crítica (9.8) | 1.8% | — | Russound Xsourceplayer 777d Firmware | 29/11/2022 | 17/6/2026 | Russound XSourcePlayer 777D v06.08.03 was discovered to contain a remote code execution vulnerability via the scriptRunner.cgi component. | |
| Modificada | Alta (7.8) | 0.21% | — | Etm-s Ondiskplayeragent | 25/11/2022 | 17/6/2026 | Remote code execution vulnerability due to insufficient verification of URLs, etc. in OndiskPlayerAgent. A remote attacker could exploit the vulnerability to cause remote code execution by causing an arbitrary user to download and execute malicious code. | |
| Modificada | Media (5.5) | 0.34% | — | Mplayerhq MencoderMplayerhq MplayerDebian Linux | 15/9/2022 | 17/6/2026 | Certain The MPlayer Project products are vulnerable to Out-of-bounds Read via function read_meta_record() of mplayer/libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. | |
| Modificada | Media (5.5) | 0.34% | — | Mplayerhq MencoderDebian Linux | 15/9/2022 | 17/6/2026 | The MPlayer Project mencoder SVN-r38374-13.0.1 is vulnerable to Divide By Zero via the function config () of llibmpcodecs/vf_scale.c. | |
| Modificada | Media (5.5) | 0.38% | — | Mplayerhq Mplayer | 15/9/2022 | 17/6/2026 | Mplayer SVN-r38374-13.0.1 is vulnerable to Memory Leak via vf.c and vf_vo.c. | |
| Modificada | Media (5.5) | 0.30% | — | Mplayerhq MencoderMplayerhq MplayerDebian Linux | 15/9/2022 | 17/6/2026 | Certain The MPlayer Project products are vulnerable to Buffer Overflow via read_avi_header() of libmpdemux/aviheader.c . This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. | |
| Modificada | Media (5.5) | 0.34% | — | Mplayerhq MencoderMplayerhq MplayerDebian Linux | 15/9/2022 | 17/6/2026 | Certain The MPlayer Project products are vulnerable to Divide By Zero via the function demux_avi_read_packet of libmpdemux/demux_avi.c. This affects mplyer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. | |
| Modificada | Media (5.5) | 0.36% | — | Mplayerhq MencoderMplayerhq MplayerDebian Linux | 15/9/2022 | 17/6/2026 | Certain The MPlayer Project products are vulnerable to Buffer Overflow via the function mp_unescape03() of libmpdemux/mpeg_hdr.c. This affects mencoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1. |