Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
2395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.64% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 1/11/2021 | 17/6/2026 | The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.62% | — | Video Player FOR Youtube Project Video Player FOR Youtube | 25/10/2021 | 17/6/2026 | The Video Player for YouTube WordPress plugin before 1.4 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode | |
| Modificada | Media (6.5) | 0.57% | — | Tipsandtricks-hq Compact WP Audio Player | 18/10/2021 | 17/6/2026 | The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack. | |
| Modificada | Media (5.4) | 0.65% | — | Tipsandtricks-hq Compact WP Audio Player | 18/10/2021 | 17/6/2026 | The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks. | |
| Modificada | Media (5.4) | 0.58% | — | Bplugins Streamcast Radio Player | 18/10/2021 | 17/6/2026 | The StreamCast – Radio Player for WordPress plugin before 2.1.1 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode | |
| Modificada | Media (5.4) | 0.65% | — | Bplugins Html5 Audio Player | 18/10/2021 | 17/6/2026 | The Html5 Audio Player – Audio Player for WordPress plugin before 2.1.3 does not sanitise or validate the parameters from its shortcode, allowing users with a role as low as contributor to set Cross-Site Scripting payload in them which will be triggered in the page/s with the embed malicious shortcode | |
| Modificada | Media (6.1) | 2.2% | 💥 Exploit | Foliovision FV Flowplayer Video Player | 6/10/2021 | 17/6/2026 | The FV Flowplayer Video Player WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the player_id parameter found in the ~/view/stats.php file which allows attackers to inject arbitrary web scripts, in versions 7.5.0.727 - 7.5.2.727. | |
| Modificada | Media (6.1) | 0.84% | — | Alfred-spotify-mini-player Alfred Spotify Mini Player | 1/10/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in callback.php in Spotify-for-Alfred 0.13.9 and below allows remote attackers to inject arbitrary web script or HTML via the error parameter. | |
| Modificada | Media (6.1) | 0.94% | — | Multiplayer-plugin Project Multiplayer-plugin | 16/8/2021 | 17/6/2026 | The Multiplayer Games WordPress plugin is vulnerable to Reflected Cross-Site Scripting due to the use of $_SERVER['PHP_SELF'] in the ~/multiplayergames.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 3.7. | |
| Modificada | Alta (7.5) | 1.8% | 💥 PoC | Videolan VLC Media Player | 26/7/2021 | 17/6/2026 | A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application. | |
| Modificada | Alta (7.1) | 0.74% | — | Videolan VLC Media Player | 26/7/2021 | 17/6/2026 | A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. | |
| Modificada | Alta (7.1) | 0.74% | — | Videolan VLC Media Player | 26/7/2021 | 17/6/2026 | A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. | |
| Modificada | Alta (7.1) | 1.5% | 💥 PoC | Videolan VLC Media Player | 26/7/2021 | 17/6/2026 | A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. | |
| Modificada | Alta (7.8) | 0.33% | — | Cisco Webex Meetings DesktopCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player+1 | 4/6/2021 | 17/6/2026 | A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL injection attack on an affected device. To exploit this vulnerability, the… | |
| Modificada | Media (6.1) | 0.58% | — | Cisco Webex Player | 4/6/2021 | 17/6/2026 | A vulnerability in Cisco Webex Player for Windows and MacOS could allow an attacker to cause the affected software to terminate or to gain access to memory state information that is related to the vulnerable application. The vulnerability is due to insufficient validation of values in Webex recording files that are… | |
| Modificada | Alta (7.8) | 1.0% | — | Cisco Webex Player | 4/6/2021 | 17/6/2026 | A vulnerability in Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. This vulnerability is due to insufficient validation of values in Webex recording files that are in Webex Recording Format (WRF). An attacker could exploit this vulnerability by sending… | |
| Modificada | Alta (7.8) | 1.0% | — | Cisco Webex Meetings ServerCisco Webex Player | 4/6/2021 | 17/6/2026 | A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. This vulnerability is due to insufficient validation of values in Webex recording files that are in either Advanced… | |
| Modificada | Alta (7.8) | 1.1% | — | Cisco Webex Meetings DesktopCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player+1 | 4/6/2021 | 17/6/2026 | A vulnerability in Cisco Webex Network Recording Player for Windows and MacOS and Cisco Webex Player for Windows and MacOS could allow an attacker to execute arbitrary code on an affected system. The vulnerability is due to insufficient validation of values within Webex recording files formatted as either Advanced… | |
| Modificada | Media (5.4) | 0.62% | — | Neox Hana FLV Player | 24/5/2021 | 17/6/2026 | The Hana Flv Player WordPress plugin through 3.1.3 is vulnerable to an Authenticated Stored Cross-Site Scripting (XSS) vulnerability within the 'Default Skin' field. | |
| Modificada | Alta (8.6) | 1.1% | — | Cdnetworks Aquanplayer | 22/4/2021 | 17/6/2026 | There is a directory traversing vulnerability in the download page url of AquaNPlayer 2.0.0.92. The IP of the download page url is localhost and an attacker can traverse directories using "dot dot" sequences(../../) to view host file on the system. This vulnerability can cause information leakage. | |
| Modificada | Media (5.4) | 0.92% | — | Foliovision FV Flowplayer Video Player | 15/1/2021 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in models/list-table.php in the FV Flowplayer Video Player plugin before 7.4.37.727 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the fv_wp_fvvideoplayer_src JSON field in the data parameter. | |
| Modificada | Alta (7.8) | 1.5% | — | Videolan VLC Media PlayerDebian Linux | 8/1/2021 | 9/7/2026 | A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file. | |
| Modificada | Alta (7.1) | 1.2% | — | Audi MMI Multiplayer | 11/11/2020 | 17/6/2026 | On Audi A7 MMI 2014 vehicles, the Bluetooth stack in Audi A7 MMI Multiplayer with version (N+R_CN_AU_P0395) mishandles %x and %s format string specifiers in a device name. This may lead to memory content leaks and potentially crash the services. | |
| Modificada | Alta (7.7) | 0.83% | — | Vmware EsxiVmware Cloud FoundationVmware WorkstationVmware Workstation Player+1 | 20/10/2020 | 17/6/2026 | VMware ESXi (7.0 before ESXi_7.0.1-0.0.16850804, 6.7 before ESXi670-202008101-SG, 6.5 before ESXi650-202007101-SG), Workstation (15.x), Fusion (11.x before 11.5.6) contain an out-of-bounds write vulnerability due to a time-of-check time-of-use issue in ACPI device. A malicious actor with administrative access to a… | |
| Modificada | Alta (8.8) | 4.3% | — | Adobe Flash Player | 14/10/2020 | 17/6/2026 | Adobe Flash Player version 32.0.0.433 (and earlier) are affected by an exploitable NULL pointer dereference vulnerability that could result in a crash and arbitrary code execution. Exploitation of this issue requires an attacker to insert malicious strings in an HTTP response that is by default delivered over TLS/SSL. |