Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.30% | — | Sick Media Server | 12/6/2025 | 17/6/2026 | The HttpOnlyflag of the session cookie \"@@\" is set to false. Since this flag helps preventing access to cookies via client-side scripts, setting the flag to false can lead to a higher possibility of Cross-Side-Scripting attacks which target the stored cookies. | |
| Analizada | Media (6.5) | 0.37% | — | Avaya Media ServerSick Baggage AnalyticsSick Field AnalyticsSick Logistic Diagnostic Analytics+2 | 12/6/2025 | 17/6/2026 | The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame, making it susceptible to brute-force attacks. | |
| Analizada | Alta (7.5) | 0.31% | — | Sick Media Server | 12/6/2025 | 17/6/2026 | All communication with the REST API is unencrypted (HTTP), allowing an attacker to intercept traffic between an actor and the webserver. This leads to the possibility of information gathering and downloading media files. | |
| Analizada | Crítica (9.8) | 0.55% | — | Sick Media Server | 12/6/2025 | 17/6/2026 | Files in the source code contain login credentials for the admin user and the property configuration password, allowing an attacker to get full access to the application. | |
| Analizada | Alta (8.6) | 0.40% | — | Sick Media Server | 12/6/2025 | 17/6/2026 | Due to missing authorization of an API endpoint, unauthorized users can send HTTP GET requests to gather sensitive information. An attacker could also send HTTP POST requests to modify the log files’ root path as well as the TCP ports the service is running on, leading to a Denial of Service attack. | |
| Analizada | Alta (7.5) | 0.56% | — | Synology Media Server | 18/12/2024 | 17/6/2026 | Authorization bypass through user-controlled key vulnerability in streaming service in Synology Media Server before 1.4-2680, 2.0.5-3152 and 2.2.0-3325 allows remote attackers to read specific files via unspecified vectors. | |
| Aplazada | Alta (7.5) | 0.54% | — | ANT Media ServerAI | 29/11/2024 | 17/6/2026 | Ant-Media-Serverv2.8.2 is affected by Improper Output Neutralization for Logs. The vulnerability stems from insufficient input sanitization in the logging mechanism. Without proper filtering or validation, user-controllable data, such as identifiers or other sensitive information, can be included in log entries… | |
| Aplazada | Media (6.1) | 0.32% | — | Emby Media ServerAI | 25/6/2024 | 17/6/2026 | Stored Cross Site Scripting vulnerability in Emby Media Server Emby Media Server 4.8.3.0 allows a remote attacker to escalate privileges via the notifications.html component. | |
| Aplazada | Media (5.4) | 0.48% | — | ANT Media Server Community EditionAI | 14/5/2024 | 17/6/2026 | Ant Media Server Community Edition in a default configuration is vulnerable to an improper HTTP header based authorization, leading to a possible use of non-administrative API calls reserved only for authorized users. All versions up to 2.9.0 (tested) and possibly newer ones are believed to be vulnerable as the vendor… | |
| Aplazada | Alta (7.8) | 0.24% | — | ANT Media ServerAI | 22/4/2024 | 17/6/2026 | Ant Media Server is live streaming engine software. A local privilege escalation vulnerability in present in versions 2.6.0 through 2.8.2 allows any unprivileged operating system user account to escalate privileges to the root user account on the system. This vulnerability arises from Ant Media Server running with… | |
| Modificada | Alta (7.5) | 0.71% | — | Ireader Media-server | 5/2/2024 | 17/6/2026 | media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_uac_stop_timer function at /uac/sip-uac-transaction.c. | |
| Modificada | Alta (7.5) | 0.71% | — | Ireader Media-server | 5/2/2024 | 17/6/2026 | media-server v1.0.0 was discovered to contain a Use-After-Free (UAF) vulnerability via the sip_subscribe_remove function at /uac/sip-uac-subscribe.c. | |
| Modificada | Alta (7.8) | 0.16% | — | Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Database ServerCisco Broadworks Execution Server+8 | 3/8/2023 | 17/6/2026 | A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability… | |
| Modificada | Media (6) | 0.20% | — | Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+12 | 12/7/2023 | 17/6/2026 | A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected… | |
| Modificada | Alta (7.5) | 0.78% | — | Media-server Project Media-server | 15/2/2023 | 17/6/2026 | Use After Free (UAF) vulnerability in ireader media-server before commit 3e0f63f1d3553f75c7d4eb32fa7c7a1976a9ff84 in librtmp, allows attackers to cause a denial of service. | |
| Modificada | Alta (7.5) | 15% | 💥 PoC | Plex Media Server | 18/1/2023 | 17/6/2026 | Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service. | |
| Modificada | Alta (7.5) | 0.91% | — | Synology Media Server | 28/7/2022 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor vulnerability in web server in Synology Media Server before 1.8.1-2876 allows remote attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Crítica (9.8) | 1.6% | — | Synology Media Server | 28/7/2022 | 17/6/2026 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7) | 1.2% | 💥 PoC | Plex Media Server | 8/12/2021 | 17/6/2026 | An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allows the attacker to interact with the RPC functionality and execute… | |
| Modificada | Media (5.3) | 1.0% | — | Synology Media Server | 18/6/2021 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in cgi component in Synology Media Server before 1.8.3-2881 allows remote attackers to access intranet resources via unspecified vectors. | |
| Modificada | Crítica (9.8) | 0.99% | — | Synology Media Server | 1/6/2021 | 17/6/2026 | Improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability in cgi component in Synology Media Server before 1.8.1-2876 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.4% | — | Plex Media Server | 15/6/2020 | 17/6/2026 | Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests. | |
| Analizada | Alta (7.2) | 73% | ⚠ Explotación activa💥 Exploit | Plex Media Server | 8/5/2020 | 17/6/2026 | Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code. | |
| Modificada | Alta (7.8) | 0.75% | — | Plex Media Server | 22/4/2020 | 17/6/2026 | Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privileges. | |
| Modificada | Alta (8.8) | 4.7% | — | Plex Media Server | 19/12/2019 | 17/6/2026 | The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user account running the Plex Media Server has permissions. This allows remote code execution via a variety of methods, such as (on a default Ubuntu installation) creating a .ssh… |