Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.36% | — | Mplayerhq MencoderMplayerhq MplayerDebian Linux | 15/9/2022 | 17/6/2026 | Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.c which affects mencoder and mplayer. This affects mecoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1. | |
| Modificada | Alta (7.8) | 0.35% | — | Mplayerhq MencoderMplayerhq Mplayer | 15/9/2022 | 17/6/2026 | Certain The MPlayer Project products are vulnerable to Buffer Overflow via function play() of libaf/af.c:639. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. | |
| Modificada | Media (5.5) | 0.34% | — | Mplayerhq MplayerDebian Linux | 15/9/2022 | 17/6/2026 | The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function free_mp_image() of libmpcodecs/mp_image.c. | |
| Modificada | Media (5.5) | 0.34% | — | Mplayerhq MencoderMplayerhq MplayerDebian Linux | 15/9/2022 | 17/6/2026 | Certain The MPlayer Project products are vulnerable to Divide By Zero via function demux_open_avi() of libmpdemux/demux_avi.c which affects mencoder. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. | |
| Modificada | Media (5.5) | 0.36% | — | Mplayerhq MencoderMplayerhq MplayerDebian Linux | 15/9/2022 | 17/6/2026 | Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. | |
| Modificada | Media (5.5) | 0.31% | — | Mplayerhq MencoderMplayerhq Mplayer | 15/9/2022 | 17/6/2026 | Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. | |
| Modificada | Media (5.5) | 0.36% | — | Mplayerhq MencoderMplayerhq MplayerDebian Linux | 15/9/2022 | 17/6/2026 | Certain The MPlayer Project products are vulnerable to Buffer Overflow via function gen_sh_video () of mplayer/libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. | |
| Modificada | Media (5.5) | 0.31% | — | Mplayerhq MencoderMplayerhq Mplayer | 15/9/2022 | 17/6/2026 | Certain The MPlayer Project products are vulnerable to Buffer Overflow via function asf_init_audio_stream() of libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1. | |
| Modificada | Alta (8.8) | 0.46% | — | Mp3-jplayer Project Mp3-jplayer | 1/9/2022 | 17/6/2026 | Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Simon Ward MP3 jPlayer plugin <= 2.7.3 at WordPress. | |
| Modificada | Alta (7.5) | 1.3% | — | Mb.miniaudioplayer Project Mb.miniaudioplayer | 28/7/2022 | 17/6/2026 | WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide attacks directed at a target site from… | |
| Modificada | Media (5.5) | 0.94% | — | Mplayerhq Mplayer | 14/7/2022 | 17/6/2026 | The MPlayer Project v1.5 was discovered to contain a heap use-after-free resulting in a double free in the preinit function at libvo/vo_v4l2.c. This vulnerability can lead to a Denial of Service (DoS) via a crafted file. The device=strdup statement is not executed on every call. Note: This has been disputed by third… | |
| Modificada | Crítica (9.8) | 2.1% | — | Daum Potplayer | 15/6/2022 | 17/6/2026 | An exploitable out-of-bounds write vulnerability in PotPlayer 1.7.21523 build 210729 may lead to code execution, information disclosure, and denial of service. | |
| Modificada | Alta (8.8) | 1.6% | — | Realnetworks Realplayer | 5/6/2022 | 17/6/2026 | In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file) in a RAM file. | |
| Modificada | Crítica (9.6) | 2.8% | — | Realnetworks Realplayer | 3/6/2022 | 17/6/2026 | In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject script code to arbitrary domains. It is also possible to reference arbitrary local files. | |
| Modificada | Crítica (9.8) | 4.5% | — | Realnetworks Realplayer | 3/6/2022 | 17/6/2026 | In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution. This occurs because it is possible to plant executables in the startup folder (DLL planting could also occur). | |
| Modificada | Crítica (9.8) | 3.3% | — | Realnetworks Realplayer | 3/6/2022 | 17/6/2026 | In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet Explorer core). This leads to arbitrary code execution. | |
| Modificada | Media (4.3) | 0.54% | — | Python Tkvideoplayer | 6/5/2022 | 17/6/2026 | TkVideoplayer is a simple library to play video files in tkinter. Uncontrolled memory consumption in versions of TKVideoplayer prior to 2.0.0 can theoretically lead to performance degradation. There are no known workarounds. This issue has been patched and users are advised to upgrade to version 2.0.0 or later. | |
| Modificada | Media (5.4) | 0.57% | — | Foliovision FV Flowplayer Video Player | 4/4/2022 | 17/6/2026 | Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter. | |
| Modificada | Alta (7.2) | 0.83% | — | Foliovision FV Flowplayer Video Player | 18/3/2022 | 17/6/2026 | Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727). | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Dvdfab 12 PlayerDvdfab Playerfab | 11/3/2022 | 17/6/2026 | An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to http://<IP_ADDRESS>:32080/download/<URL_ENCODED_PATH>. | |
| Modificada | Media (6.7) | 0.73% | — | Vmware Cloud FoundationVmware FusionVmware Workstation PlayerVmware Workstation PRO+1 | 16/2/2022 | 17/6/2026 | VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host. | |
| Modificada | Crítica (9.8) | 0.34% | — | Samsung Video Player | 11/2/2022 | 17/6/2026 | Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission. | |
| Modificada | Alta (7.8) | 0.26% | — | MSI APP Player | 4/2/2022 | 17/6/2026 | Micro-Star International (MSI) App Player <= 4.280.1.6309 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the NTIOLib_X64.sys and BstkDrv_msi2.sys drivers components. All the vulnerabilities are triggered by sending specific IOCTL requests. | |
| Modificada | Alta (7.8) | 1.2% | — | Clementine-player Clementine | 15/12/2021 | 17/6/2026 | Clementine Music Player through 1.3.1 (when a GLib 2.0.0 DLL is used) is vulnerable to a Read Access Violation on Block Data Move, affecting the MP3 file parsing functionality at memcpy+0x265. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled by… | |
| Modificada | Alta (7.8) | 1.2% | — | Clementine-player Clementine | 15/12/2021 | 17/6/2026 | Clementine Music Player through 1.3.1 is vulnerable to a User Mode Write Access Violation, affecting the MP3 file parsing functionality at clementine+0x3aa207. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled by Clementine. Attackers could exploit… |