Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
2395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.32% | — | Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO | 16/9/2020 | 17/6/2026 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an information disclosure vulnerability due to an integer overflow issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to leak memory from TPView process… | |
| Modificada | Baja (3.3) | 0.29% | — | Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO | 16/9/2020 | 17/6/2026 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain a denial of service vulnerability due to an out-of-bounds write issue in Cortado ThinPrint component. A malicious actor with normal access to a virtual machine may be able to exploit this issue to create a partial denial-of-service… | |
| Modificada | Media (6.1) | 0.30% | — | Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO | 16/9/2020 | 17/6/2026 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (JPEG2000 parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to… | |
| Modificada | Media (6.1) | 0.30% | — | Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO | 16/9/2020 | 17/6/2026 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMR STRETCHDIBITS parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service… | |
| Modificada | Media (6.1) | 0.30% | — | Vmware Horizon ClientVmware Workstation PlayerVmware Workstation PRO | 16/9/2020 | 17/6/2026 | VMware Workstation (15.x) and Horizon Client for Windows (5.x before 5.4.4) contain an out-of-bounds read vulnerability in Cortado ThinPrint component (EMF Parser). A malicious actor with normal access to a virtual machine may be able to exploit these issues to create a partial denial-of-service condition or to leak… | |
| Modificada | Alta (8.8) | 2.0% | — | Mxplayer MX Player | 8/7/2020 | 17/6/2026 | MX Player Android App versions prior to v1.24.5, are vulnerable to a directory traversal vulnerability when user is using the MX Transfer feature in "Receive" mode. An attacker can exploit this by connecting to the MX Transfer session as a "sender" and sending a MessageType of "FILE_LIST" with a "name" field… | |
| Modificada | Crítica (9.8) | 7.6% | — | Adobe Flash Player Desktop RuntimeAdobe Flash Player | 12/6/2020 | 17/6/2026 | Adobe Flash Player Desktop Runtime 32.0.0.371 and earlier, Adobe Flash Player for Google Chrome 32.0.0.371 and earlier, and Adobe Flash Player for Microsoft Edge and Internet Explorer 32.0.0.330 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 2.4% | — | Videolan VLC Media PlayerDebian Linux | 8/6/2020 | 17/6/2026 | A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file. | |
| Modificada | Baja (3.3) | 0.66% | — | Cisco Webex Network Recording PlayerCisco Webex Player | 3/6/2020 | 17/6/2026 | A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain… | |
| Modificada | Baja (3.3) | 1.4% | — | Cisco Webex PlayerCisco Webex Network Recording Player | 3/6/2020 | 17/6/2026 | A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain… | |
| Modificada | Baja (3.3) | 0.66% | — | Cisco Webex Network Recording PlayerCisco Webex Player | 3/6/2020 | 17/6/2026 | A vulnerability in Cisco Webex Network Recording Player and Cisco Webex Player for Microsoft Windows could allow an attacker to cause a process crash resulting in a Denial of service (DoS) condition for the player application on an affected system. The vulnerability exists due to insufficient validation of certain… | |
| Modificada | Alta (7.8) | 2.0% | — | Videolan VLC Media Player | 15/5/2020 | 17/6/2026 | An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product. | |
| Modificada | Alta (8.8) | 1.2% | — | Imgtech Zoneplayer | 7/5/2020 | 17/6/2026 | IMGTech Co,Ltd ZInsX.ocx ActiveX Control in Zoneplayer 2.0.1.3, version 2.0.1.4 and prior versions on Windows. File Donwload vulnerability in ZInsX.ocx of IMGTech Co,Ltd Zoneplayer allows attacker to cause arbitrary code execution. | |
| Modificada | Alta (7.8) | 2.2% | — | Abbs Software Audio Media Player Project Abbs Software Audio Media Player | 29/4/2020 | 17/6/2026 | ABBS Software Audio Media Player version 3.1 suffers from an instance of CWE-121: Stack-based Buffer Overflow. | |
| Modificada | Alta (7.8) | 2.0% | — | Cisco Webex Network Recording PlayerCisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings Server | 15/4/2020 | 17/6/2026 | A vulnerability in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exists due to insufficient validation of certain elements with a Webex recording stored in either the… | |
| Modificada | Crítica (9.8) | 4.0% | 💥 PoC | Whmcssmarters WEB TV Player | 5/3/2020 | 17/6/2026 | IPTV Smarters WEB TV PLAYER through 2020-02-22 allows attackers to execute OS commands by uploading a script. | |
| Modificada | Alta (7.8) | 1.9% | — | Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player | 4/3/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored… | |
| Modificada | Alta (7.8) | 2.4% | — | Cisco Webex MeetingsCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player | 4/3/2020 | 17/6/2026 | Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities are due to insufficient validation of certain elements within a Webex recording that is stored… | |
| Modificada | Media (6.1) | 2.6% | 💥 Exploit | Longtailvideo JW Player | 20/2/2020 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) logo.link, or (3) aboutlink parameter, or a nested URI scheme name for (4) javascript, (5) asfunction, or (6) vbscript. | |
| Modificada | Alta (8.8) | 10% | — | Adobe Flash PlayerRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 13/2/2020 | 17/6/2026 | Adobe Flash Player versions 32.0.0.321 and earlier, 32.0.0.314 and earlier, 32.0.0.321 and earlier, and 32.0.0.255 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 1.6% | — | Umplayer Project Umplayer | 12/2/2020 | 16/6/2026 | A Code Execution Vulnerability exists in UMPlayer 0.98 in wintab32.dll due to insufficient path restrictions when loading external libraries. which could let a malicious user execute arbitrary code. | |
| Modificada | Alta (7.8) | 1.4% | — | Daum Potplayer | 11/2/2020 | 16/6/2026 | Potplayer prior to 1.5.39659: DLL Loading Arbitrary Code Execution Vulnerability | |
| Modificada | Crítica (9.8) | 7.7% | — | Samsung Prismview Player 11Samsung Prismview System 9 | 10/2/2020 | 17/6/2026 | The HTTP API in Prismview System 9 11.10.17.00 and Prismview Player 11 13.09.1100 allows remote code execution by uploading RebootSystem.lnk and requesting /REBOOTSYSTEM or /RESTARTVNC. (Authentication is required but an XML file containing credentials can be downloaded.) | |
| Modificada | Crítica (9.6) | 8.8% | 💥 Exploit | Flowplayer Flash | 8/2/2020 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) extension for TYPO3 and Mahara, allows remote attackers to inject arbitrary web script or HTML via the plugin configuration directive in a reference to an external domain plugin. | |
| Modificada | Media (5.3) | 1.1% | — | Videolan VLC Media Player | 6/2/2020 | 16/6/2026 | The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating. |