Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.63% | — | Musicpd Music Player DaemonAI | 28/5/2026 | 14/7/2026 | Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow and LocalStorage::MapUTF8 within the local storage plugin, where the on-disk path is constructed by joining the storage root with a user-supplied URI as plain strings without canonicalization,… | |
| Aplazada | Alta (8.8) | 0.68% | — | Musicpd Music Player DaemonAI | 28/5/2026 | 14/7/2026 | Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in the PCM decoder plugin. Attackers can issue two MPD commands referencing… | |
| Aplazada | Crítica (9.3) | 0.52% | — | Apple MusicAI | 17/5/2026 | 17/6/2026 | WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint. Attackers can upload files with arbitrary extensions by manipulating the 'name' parameter to execute code from the… | |
| Aplazada | Baja (2) | 0.38% | — | Code-projects Online Music SiteAI | 28/4/2026 | 17/6/2026 | A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. This manipulation of the argument txtimage causes unrestricted upload. Remote exploitation of the attack is possible. The exploit has been published and may be used. | |
| Analizada | Alta (8.6) | 0.21% | — | Magix Music Editor Deluxe | 22/4/2026 | 17/6/2026 | MAGIX Music Editor 3.1 contains a buffer overflow vulnerability in the FreeDB Proxy Options dialog that allows local attackers to execute arbitrary code by exploiting structured exception handling. Attackers can craft a malicious payload, paste it into the Server field via the CD menu's FreeDB Proxy Options, and… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/edit_music.php. | |
| Aplazada | Crítica (9.8) | 0.47% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_genre.php. | |
| Aplazada | Crítica (9.4) | 0.41% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_user.php. | |
| Aplazada | Alta (7.3) | 0.29% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_playlist.php. | |
| Aplazada | Alta (7.3) | 0.29% | — | Sourcecodester Simple Music Cloud Community SystemAI | 16/4/2026 | 17/6/2026 | SourceCodester Simple Music Cloud Community System v1.0 is vulnerable to SQL Injection in the file /music/view_music.php. | |
| Aplazada | Media (5.4) | 0.22% | — | Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI | 8/4/2026 | 24/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Server Side Request Forgery.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.11. | |
| Analizada | Alta (8.6) | 0.19% | — | Kimtore Practical Music Search | 28/3/2026 | 17/6/2026 | PMS 0.42 contains a stack-based buffer overflow vulnerability that allows local unauthenticated attackers to execute arbitrary code by supplying malicious values in the configuration file. Attackers can craft configuration files with oversized input that overflows the stack buffer and execute shell commands via… | |
| Analizada | Alta (7.5) | 0.49% | — | Borewit Music-metadata | 18/3/2026 | 17/6/2026 | music-metadata is a metadata parser for audio and video media files. Prior to version 11.12.3, music-metadata's ASF parser (`parseExtensionObject()` in `lib/asf/AsfParser.ts:112-158`) enters an infinite loop when a sub-object inside the ASF Header Extension Object has `objectSize = 0`. Version 11.12.3 fixes the issue. | |
| Aplazada | Alta (8.7) | 0.64% | — | MusiccoAI | 6/3/2026 | 17/6/2026 | Musicco 2.0.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary directories by manipulating the parent parameter. Attackers can supply directory traversal sequences in the parent parameter of the getAlbum endpoint to access sensitive system directories and download… | |
| Aplazada | Alta (7.1) | 0.26% | — | Themegoods MusicoAI | 5/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThemeGoods Musico musico allows Reflected XSS.This issue affects Musico: from n/a through < 3.4.5. | |
| Analizada | Alta (8.8) | 0.78% | — | Music-assistant Music Assistant Server | 20/2/2026 | 17/6/2026 | Music Assistant is an open-source media library manager that integrates streaming services with connected speakers. Versions 2.6.3 and below allow unauthenticated network-adjacent attackers to execute arbitrary code on affected installations. The music/playlists/update API allows users to bypass the .m3u extension… | |
| Analizada | Baja (1.9) | 0.21% | — | Fabian Online Music Site | 9/2/2026 | 17/6/2026 | A weakness has been identified in code-projects for Plugin 1.0. This affects an unknown part of the file /Administrator/PHP/AdminAddAlbum.php. This manipulation of the argument txtalbum causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been made available to the public and… | |
| Analizada | Baja (2) | 0.30% | — | Fabian Online Music Site | 9/2/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminAddAlbum.php. The manipulation of the argument txtimage results in unrestricted upload. The attack may be performed from remote. The exploit has been… | |
| Analizada | Media (5.5) | 0.34% | — | Fabian Online Music Site | 9/2/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /Administrator/PHP/AdminEditCategory.php. The manipulation of the argument ID leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly… | |
| Analizada | Media (5.5) | 0.34% | — | Fabian Online Music Site | 9/2/2026 | 17/6/2026 | A vulnerability was determined in code-projects Online Music Site 1.0. Affected is an unknown function of the file /Administrator/PHP/AdminDeleteCategory.php. Executing a manipulation of the argument ID can lead to sql injection. The attack can be executed remotely. The exploit has been publicly disclosed and may be… | |
| Analizada | Media (5.5) | 0.47% | — | Fabian Online Music Site | 8/2/2026 | 17/6/2026 | A weakness has been identified in code-projects Online Music Site 1.0. Impacted is an unknown function of the file /Administrator/PHP/AdminUpdateCategory.php. This manipulation of the argument txtimage causes unrestricted upload. The attack is possible to be carried out remotely. The exploit has been made available to… | |
| Analizada | Media (5.5) | 0.38% | — | Fabian Online Music Site | 8/2/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Administrator/PHP/AdminUpdateCategory.php. The manipulation of the argument txtcat results in sql injection. The attack can be executed remotely. The exploit has been released to the… | |
| Analizada | Media (5.5) | 0.47% | — | Fabian Online Music Site | 28/1/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Administrator/PHP/AdminReply.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may… | |
| Analizada | Media (5.5) | 0.47% | — | Fabian Online Music Site | 28/1/2026 | 17/6/2026 | A weakness has been identified in code-projects Online Music Site 1.0. This affects an unknown function of the file /Administrator/PHP/AdminEditUser.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been made available to the public and… | |
| Analizada | Baja (2) | 0.41% | — | Fabian Online Music Site | 28/1/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminAddCategory.php. The manipulation results in sql injection. The attack may be performed from remote. The exploit has been released to the public and may be used… |