Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.5) | 0.56% | — | Fabian Online Music Site | 26/1/2026 | 17/6/2026 | A flaw has been found in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /Administrator/PHP/AdminDeleteUser.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. | |
| Aplazada | Crítica (9.8) | 0.45% | — | Themerex Sound Musical Instruments Online StoreAI | 22/1/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in ThemeREX Sound | Musical Instruments Online Store musicplace allows Object Injection.This issue affects Sound | Musical Instruments Online Store: from n/a through <= 1.6.9. | |
| Analizada | Media (5.3) | 0.58% | — | Swingmx Swing Music | 19/1/2026 | 17/6/2026 | Swing Music is a self-hosted music player for local audio files. Prior to version 2.1.4, Swing Music's `list_folders()` function in the `/folder/dir-browser` endpoint is vulnerable to directory traversal attacks. Any authenticated user (including non-admin) can browse arbitrary directories on the server filesystem.… | |
| Analizada | Media (5.5) | 0.37% | — | Fabian Online Music Site | 12/1/2026 | 17/6/2026 | A security flaw has been discovered in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Administrator/PHP/AdminUpdateUser.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.37% | — | Fabian Online Music Site | 12/1/2026 | 17/6/2026 | A vulnerability was identified in code-projects Online Music Site 1.0. The affected element is an unknown function of the file /Administrator/PHP/AdminAddUser.php. The manipulation of the argument txtusername leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and… | |
| Modificada | Media (5.5) | 0.44% | — | Fabian Online Music Site | 6/1/2026 | 17/6/2026 | A flaw has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminViewSongs.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.46% | — | Fabian Online Music Site | 5/1/2026 | 17/6/2026 | A vulnerability was detected in code-projects Online Music Site 1.0. Affected by this issue is some unknown functionality of the file /FrontEnd/Albums.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used. | |
| Modificada | Media (5.5) | 0.44% | — | Fabian Online Music Site | 5/1/2026 | 17/6/2026 | A security vulnerability has been detected in code-projects Online Music Site 1.0. Affected by this vulnerability is an unknown functionality of the file /login.php. Such manipulation of the argument username/password leads to sql injection. The attack may be performed from remote. The exploit has been disclosed… | |
| Modificada | Media (5.5) | 0.43% | — | Fabian Online Music Site | 2/1/2026 | 17/6/2026 | A vulnerability was found in code-projects Online Music Site 1.0. This impacts an unknown function of the file /Frontend/Feedback.php. Performing a manipulation of the argument fname results in sql injection. The attack can be initiated remotely. The exploit has been made public and could be used. | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Online Music Site | 2/1/2026 | 17/6/2026 | A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown function of the file /Frontend/AlbumByCategory.php. Such manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Online Music Site | 2/1/2026 | 17/6/2026 | A flaw has been found in code-projects Online Music Site 1.0. The impacted element is an unknown function of the file /Frontend/ViewSongs.php. This manipulation of the argument ID causes sql injection. It is possible to initiate the attack remotely. The exploit has been published and may be used. | |
| Analizada | Alta (7.5) | 0.41% | 💥 PoC | Inmusicbrands Engine DJ Desktop | 30/12/2025 | 17/6/2026 | inMusic Brands Engine DJ before 4.3.4 suffers from Insecure Permissions due to exposed HTTP service in the Remote Library, which allows attackers to access all files and network paths. | |
| Modificada | Media (4.6) | 0.17% | — | Lyrion Music Server | 8/12/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability exists in the web interface of Lyrion Music Server <= 9.0.3. An authenticated user with access to Settings Player can save arbitrary HTML/JavaScript in the Player name field. That value is stored by the server and later rendered without proper output encoding on the… | |
| Aplazada | Alta (8.8) | 0.43% | — | Nootheme WemusicAI | 6/11/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in NooTheme WeMusic noo-wemusic allows Object Injection.This issue affects WeMusic: from n/a through <= 1.9.1. | |
| Aplazada | Alta (7.1) | 0.22% | — | Nootheme WemusicAI | 6/11/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in NooTheme WeMusic noo-wemusic allows Reflected XSS.This issue affects WeMusic: from n/a through <= 1.9.1. | |
| Aplazada | Media (6.5) | 0.41% | — | ALL IN ONE Music PlayerAI | 30/9/2025 | 17/6/2026 | The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.1 via the 'theme' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of files on the server, which can contain sensitive… | |
| Aplazada | Alta (7.1) | 0.12% | — | Ericzane Floating Window Music PlayerAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ericzane Floating Window Music Player floating-window-music-player allows Stored XSS.This issue affects Floating Window Music Player: from n/a through <= 3.4.2. | |
| Aplazada | Alta (8.4) | 0.42% | 💥 Exploit | Digital Music PADAI | 21/8/2025 | 16/6/2026 | Digital Music Pad v8.2.3.3.4 contains a stack-based buffer overflow vulnerability in its playlist file parser. When opening a .pls file containing an excessively long string in the File1 field, the application fails to properly validate input length, resulting in corruption of the Structured Exception Handler (SEH) on… | |
| Aplazada | Alta (8.7) | 1.2% | — | Sockso Music Host ServerAI | 20/8/2025 | 16/6/2026 | Sockso Music Host Server versions <= 1.5 are vulnerable to a path traversal flaw that allows unauthenticated remote attackers to read arbitrary files from the server’s filesystem. The vulnerability exists in the HTTP interface on port 4444, where the endpoint /file/ fails to properly sanitize user-supplied input.… | |
| Analizada | Media (6.2) | 0.15% | — | Apple Music Classical | 15/8/2025 | 17/6/2026 | This issue was addressed with improved checks. This issue is fixed in Apple Music Classical 2.3 for Android. An app may be able to unexpectedly leak a user's credentials. | |
| Aplazada | Media (4.3) | 0.24% | — | Dariolee Netease MusicAI | 14/8/2025 | 17/6/2026 | Missing Authorization vulnerability in Dariolee Netease Music netease-music allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Netease Music: from n/a through <= 3.2.1. | |
| Aplazada | Media (6.4) | 0.28% | — | Smartwpress Music Player FOR ElementorAI | 3/6/2025 | 17/6/2026 | The Music Player for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘album_buy_url’ parameter in all versions up to, and including, 2.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access… | |
| Analizada | Media (5.4) | 0.31% | — | Opensheetmusicdisplay | 30/5/2025 | 17/6/2026 | The OpenSheetMusicDisplay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘className’ parameter in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above,… | |
| Aplazada | Media (4.8) | 0.20% | — | Funaudiollm InspiremusicAI | 25/5/2025 | 17/6/2026 | A vulnerability was found in FunAudioLLM InspireMusic up to bf32364bcb0d136497ca69f9db622e9216b029dd. It has been classified as critical. Affected is the function load_state_dict of the file inspiremusic/cli/model.py of the component Pickle Data Handler. The manipulation leads to deserialization. An attack has to be… | |
| Aplazada | Alta (8.5) | 0.32% | — | Lambertgroup Sticky Html5 Music PlayerAI | 16/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LambertGroup Sticky HTML5 Music Player lbg-audio3-html5 allows SQL Injection.This issue affects Sticky HTML5 Music Player: from n/a through <= 3.1.6. |