Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 2.1% | — | Plex Media Server | 18/11/2019 | 17/6/2026 | Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token is mishandled and can be retrieved from Tautulli. NOTE: Initially, this id was associated with Plex Media Server 1.18.2.2029-36236cc4c as the affected product and version. Further… | |
| Modificada | Crítica (9.8) | 2.4% | — | Live555 Media ServerDebian Linux | 14/1/2019 | 17/6/2026 | A Denial of Service issue was discovered in the LIVE555 Streaming Media libraries as used in Live555 Media Server 0.93. It can cause an RTSPServer crash in handleHTTPCmd_TunnelingPOST, when RTSP-over-HTTP tunneling is supported, via x-sessioncookie HTTP headers in a GET request and a POST request within the same TCP… | |
| Modificada | Alta (7.8) | 0.30% | — | Intel Media Server Studio | 14/11/2018 | 17/6/2026 | Improper directory permissions in the installer for the Intel Media Server Studio may allow unprivileged users to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (6.5) | 1.7% | — | Cisco Video Surveillance Media Server | 8/11/2018 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Video Surveillance Media Server could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of the web-based management interface of an affected system. The vulnerability is due to insufficient validation of user-supplied input by… | |
| Modificada | Crítica (9.8) | 9.7% | 💥 PoC | Live555 Media ServerDebian Linux | 19/10/2018 | 17/6/2026 | An exploitable code execution vulnerability exists in the HTTP packet-parsing functionality of the LIVE555 RTSP server library version 0.92. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 32% | 💥 Exploit | Plex Media Server | 13/8/2018 | 17/6/2026 | In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running… | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Spirton Universal Media Server | 3/8/2018 | 17/6/2026 | In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running… | |
| Modificada | Crítica (9.8) | 1.3% | — | Synology Media Server | 10/5/2018 | 17/6/2026 | SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter. | |
| Modificada | Media (5.4) | 2.0% | 💥 Exploit | Logitech Media Server | 10/11/2017 | 17/6/2026 | Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Radio" functionality. This vulnerability allows attackers to inject malicious JavaScript payloads, which become permanently stored on the server and execute when a user plays the compromised radio stream. Exploitation of… | |
| Modificada | Media (5.4) | 2.2% | 💥 Exploit | Logitech Media Server | 10/11/2017 | 17/6/2026 | Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. This vulnerability allows remote attackers to inject and permanently store malicious JavaScript payloads, which are executed when users access the affected functionality. Exploitation of this… | |
| Modificada | Media (6.1) | 1.5% | 💥 Exploit | Logitech Media Server | 23/10/2017 | 17/6/2026 | DOM Based Cross Site Scripting (XSS) exists in Logitech Media Server 7.7.1, 7.7.2, 7.7.3, 7.7.5, 7.7.6, 7.9.0, and 7.9.1 via a crafted URI. | |
| Modificada | Crítica (9.8) | 2.7% | — | Red5 Media Server | 8/6/2017 | 17/6/2026 | The AMF unmarshallers in Red5 Media Server before 1.0.8 do not restrict the classes for which it performs deserialization, which allows remote attackers to execute arbitrary code via crafted serialized Java data. | |
| Modificada | Alta (7.5) | 7.2% | 💥 Exploit | Evostream Media Server | 10/3/2017 | 17/6/2026 | A Buffer Overflow was discovered in EvoStream Media Server 1.7.1. A crafted HTTP request with a malicious header will cause a crash. An example attack methodology may include a long message-body in a GET request. | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | Plex Media Server | 7/12/2014 | 17/6/2026 | Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted X-Plex-Url headers to system/proxy, which are inconsistently processed by the request handler in the backend web server. | |
| Modificada | Media (5) | 9.5% | 💥 Exploit | Plex Media Server | 2/12/2014 | 17/6/2026 | Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the URI to (1) manage/ or (2) web/ or remote authenticated users to read arbitrary files via a .. (dot dot) in the URI to resources/. | |
| Modificada | Media (5) | 11% | 💥 Exploit | Fireflymediaserver Firefly Media Server | 18/1/2013 | 16/6/2026 | Firefly Media Server 1.0.0.1359 allows remote attackers to cause a denial of service (NULL pointer dereference) via a (1) crafted Connection HTTP header; a return carriage control character in the (2) Accept Language header, (3) User-agent header, (4) Host header, or (5) protocol version; or a (6) crafted HTTP… | |
| Modificada | Media (5) | 8.5% | 💥 Exploit | Adobe Flash Media Server | 11/8/2011 | 16/6/2026 | Adobe Flash Media Server (FMS) before 3.5.7, and 4.x before 4.0.3, allows attackers to cause a denial of service (memory corruption) via unspecified vectors. | |
| Modificada | Media (5) | 2.2% | — | Adobe Flash Media Server | 16/5/2011 | 16/6/2026 | Adobe Flash Media Server (FMS) before 3.5.6, and 4.x before 4.0.2, allows remote attackers to cause a denial of service (XML data corruption) via unspecified vectors. | |
| Modificada | Alta (10) | 5.9% | — | Adobe Flash Media Server | 10/11/2010 | 16/6/2026 | Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to execute arbitrary code via unspecified vectors, related to a "segmentation fault vulnerability." | |
| Modificada | Media (5) | 3.7% | — | Adobe Flash Media Server | 10/11/2010 | 16/6/2026 | Unspecified vulnerability in the edge process in Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to cause a denial of service via unknown vectors. | |
| Modificada | Media (5) | 3.7% | — | Adobe Flash Media Server | 10/11/2010 | 16/6/2026 | Memory leak in Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to cause a denial of service (memory consumption) via unspecified vectors. | |
| Modificada | Media (5) | 2.5% | — | Adobe Flash Media ServerAdobe Flash Media Server 2 | 11/8/2010 | 16/6/2026 | Adobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to cause a denial of service via unspecified vectors, related to an "input validation issue." | |
| Modificada | Media (5) | 2.5% | — | Adobe Flash Media ServerAdobe Flash Media Server 2 | 11/8/2010 | 16/6/2026 | Unspecified vulnerability in Adobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to cause a denial of service (memory consumption) via unknown vectors. | |
| Modificada | Media (5) | 2.5% | — | Adobe Flash Media ServerAdobe Flash Media Server 2 | 11/8/2010 | 16/6/2026 | Adobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to cause a denial of service via unspecified vectors, related to a "JS method issue." | |
| Modificada | Alta (10) | 4.5% | — | Adobe Flash Media ServerAdobe Flash Media Server 2 | 11/8/2010 | 16/6/2026 | Adobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to execute arbitrary code via unspecified vectors, related to a "JS method vulnerability." |