Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

2395 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.36%—Mplayerhq MencoderMplayerhq MplayerDebian Linux15/9/202217/6/2026
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mp_getbits() of libmpdemux/mpeg_hdr.c which affects mencoder and mplayer. This affects mecoder SVN-r38374-13.0.1 and mplayer SVN-r38374-13.0.1.
ModificadaAlta (7.8)0.35%—Mplayerhq MencoderMplayerhq Mplayer15/9/202217/6/2026
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function play() of libaf/af.c:639. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
ModificadaMedia (5.5)0.34%—Mplayerhq MplayerDebian Linux15/9/202217/6/2026
The MPlayer Project mplayer SVN-r38374-13.0.1 is vulnerable to memory corruption via function free_mp_image() of libmpcodecs/mp_image.c.
ModificadaMedia (5.5)0.34%—Mplayerhq MencoderMplayerhq MplayerDebian Linux15/9/202217/6/2026
Certain The MPlayer Project products are vulnerable to Divide By Zero via function demux_open_avi() of libmpdemux/demux_avi.c which affects mencoder. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
ModificadaMedia (5.5)0.36%—Mplayerhq MencoderMplayerhq MplayerDebian Linux15/9/202217/6/2026
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
ModificadaMedia (5.5)0.31%—Mplayerhq MencoderMplayerhq Mplayer15/9/202217/6/2026
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function mov_build_index() of libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
ModificadaMedia (5.5)0.36%—Mplayerhq MencoderMplayerhq MplayerDebian Linux15/9/202217/6/2026
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function gen_sh_video () of mplayer/libmpdemux/demux_mov.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
ModificadaMedia (5.5)0.31%—Mplayerhq MencoderMplayerhq Mplayer15/9/202217/6/2026
Certain The MPlayer Project products are vulnerable to Buffer Overflow via function asf_init_audio_stream() of libmpdemux/asfheader.c. This affects mplayer SVN-r38374-13.0.1 and mencoder SVN-r38374-13.0.1.
ModificadaAlta (8.8)0.46%—Mp3-jplayer Project Mp3-jplayer1/9/202217/6/2026
Multiple Cross-Site Request Forgery (CSRF) vulnerabilities in Simon Ward MP3 jPlayer plugin <= 2.7.3 at WordPress.
ModificadaAlta (7.5)1.3%—Mb.miniaudioplayer Project Mb.miniaudioplayer28/7/202217/6/2026
WordPress Plugin mb.miniAudioPlayer-an HTML5 audio player for your mp3 files is prone to multiple vulnerabilities, including open proxy and security bypass vulnerabilities because it fails to properly verify user-supplied input. An attacker may leverage these issues to hide attacks directed at a target site from…
ModificadaMedia (5.5)0.94%—Mplayerhq Mplayer14/7/202217/6/2026
The MPlayer Project v1.5 was discovered to contain a heap use-after-free resulting in a double free in the preinit function at libvo/vo_v4l2.c. This vulnerability can lead to a Denial of Service (DoS) via a crafted file. The device=strdup statement is not executed on every call. Note: This has been disputed by third…
ModificadaCrítica (9.8)2.1%—Daum Potplayer15/6/202217/6/2026
An exploitable out-of-bounds write vulnerability in PotPlayer 1.7.21523 build 210729 may lead to code execution, information disclosure, and denial of service.
ModificadaAlta (8.8)1.6%—Realnetworks Realplayer5/6/202217/6/2026
In Real Player through 20.1.0.312, attackers can execute arbitrary code by placing a UNC share pathname (for a DLL file) in a RAM file.
ModificadaCrítica (9.6)2.8%—Realnetworks Realplayer3/6/202217/6/2026
In Real Player 20.0.8.310, there is a DCP:// URI Remote Arbitrary Code Execution Vulnerability. This is an internal URL Protocol used by Real Player to reference a file that contains an URL. It is possible to inject script code to arbitrary domains. It is also possible to reference arbitrary local files.
ModificadaCrítica (9.8)4.5%—Realnetworks Realplayer3/6/202217/6/2026
In Real Player 20.0.7.309 and 20.0.8.310, external::Import() allows download of arbitrary file types and Directory Traversal, leading to Remote Code Execution. This occurs because it is possible to plant executables in the startup folder (DLL planting could also occur).
ModificadaCrítica (9.8)3.3%—Realnetworks Realplayer3/6/202217/6/2026
In Real Player 20.0.8.310, the G2 Control allows injection of unsafe javascript: URIs in local HTTP error pages (displayed by Internet Explorer core). This leads to arbitrary code execution.
ModificadaMedia (4.3)0.54%—Python Tkvideoplayer6/5/202217/6/2026
TkVideoplayer is a simple library to play video files in tkinter. Uncontrolled memory consumption in versions of TKVideoplayer prior to 2.0.0 can theoretically lead to performance degradation. There are no known workarounds. This issue has been patched and users are advised to upgrade to version 2.0.0 or later.
ModificadaMedia (5.4)0.57%—Foliovision FV Flowplayer Video Player4/4/202217/6/2026
Authenticated Persistent Cross-Site Scripting (XSS) vulnerability in FV Flowplayer Video Player (WordPress plugin) versions <= 7.5.18.727 via &fv_wp_flowplayer_field_splash parameter.
ModificadaAlta (7.2)0.83%—Foliovision FV Flowplayer Video Player18/3/202217/6/2026
Authenticated (author or higher user role) SQL Injection (SQLi) vulnerability discovered in FV Flowplayer Video Player WordPress plugin (versions <= 7.5.15.727).
ModificadaAlta (7.5)13%💥 ExploitDvdfab 12 PlayerDvdfab Playerfab11/3/202217/6/2026
An absolute path traversal vulnerability allows a remote attacker to download any file on the Windows file system for which the user account running DVDFab 12 Player (recently renamed PlayerFab) has read-access, by means of an HTTP GET request to http://<IP_ADDRESS>:32080/download/<URL_ENCODED_PATH>.
ModificadaMedia (6.7)0.73%—Vmware Cloud FoundationVmware FusionVmware Workstation PlayerVmware Workstation PRO+116/2/202217/6/2026
VMware ESXi, Workstation, and Fusion contain a use-after-free vulnerability in the XHCI USB controller. A malicious actor with local administrative privileges on a virtual machine may exploit this issue to execute code as the virtual machine's VMX process running on the host.
ModificadaCrítica (9.8)0.34%—Samsung Video Player11/2/202217/6/2026
Improper privilege management vulnerability in Samsung Video Player prior to version 7.3.15.30 allows attackers to execute video files without permission.
ModificadaAlta (7.8)0.26%—MSI APP Player4/2/202217/6/2026
Micro-Star International (MSI) App Player <= 4.280.1.6309 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the NTIOLib_X64.sys and BstkDrv_msi2.sys drivers components. All the vulnerabilities are triggered by sending specific IOCTL requests.
ModificadaAlta (7.8)1.2%—Clementine-player Clementine15/12/202117/6/2026
Clementine Music Player through 1.3.1 (when a GLib 2.0.0 DLL is used) is vulnerable to a Read Access Violation on Block Data Move, affecting the MP3 file parsing functionality at memcpy+0x265. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled by…
ModificadaAlta (7.8)1.2%—Clementine-player Clementine15/12/202117/6/2026
Clementine Music Player through 1.3.1 is vulnerable to a User Mode Write Access Violation, affecting the MP3 file parsing functionality at clementine+0x3aa207. The vulnerability is triggered when the user opens a crafted MP3 file or loads a remote stream URL that is mishandled by Clementine. Attackers could exploit…