Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
2394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.22% | — | Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI | 8/4/2026 | 24/7/2026 | Server-Side Request Forgery (SSRF) vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Server Side Request Forgery.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.11. | |
| Aplazada | Media (5.4) | 0.23% | — | Ilghera JW Player FOR WordpressAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in ilGhera JW Player for WordPress jw-player-7-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JW Player for WordPress: from n/a through <= 2.3.6. | |
| Aplazada | Media (5.4) | 0.17% | — | AM Lottie PlayerAI | 8/4/2026 | 25/7/2026 | The AM LottiePlayer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via uploaded SVG files in all versions up to, and including, 3.6.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Pendiente de análisis | Crítica (9.1) | 0.46% | — | JXL 9 Inch CAR Android Double DIN PlayerAI | 7/4/2026 | 24/7/2026 | An issue in JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to force the infotainment system into accepting falsified GPS signals as legitimate, resulting in the device reporting an incorrect or static location. | |
| Analizada | Media (5.3) | 0.17% | — | Rareprob Video Player | 31/3/2026 | 24/7/2026 | An arbitrary file overwrite vulnerability in RAREPROB SOLUTIONS PRIVATE LIMITED Video player Play All Videos v1.0.135 allows attackers to overwrite critical internal files via the file import process, leading to arbtrary code execution or information exposure. | |
| Aplazada | Alta (8.6) | 0.15% | — | Dvdxplayer PROAI | 22/3/2026 | 17/6/2026 | DVDXPlayer Pro 5.5 contains a local buffer overflow vulnerability with structured exception handling that allows local attackers to execute arbitrary code by crafting malicious playlist files. Attackers can create a specially crafted .plf file containing shellcode and NOP sleds that overflows a buffer and hijacks the… | |
| Aplazada | Alta (7.1) | 0.12% | — | Joshuae1974 Flash Video PlayerAI | 20/3/2026 | 17/6/2026 | Cross-Site request forgery (CSRF) vulnerability in joshuae1974 Flash Video Player allows Cross Site Request Forgery.This issue affects Flash Video Player: from n/a through 5.0.4. | |
| Aplazada | Alta (7.5) | 0.30% | — | Gerritvanaaken Podlove WEB PlayerAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in gerritvanaaken Podlove Web Player podlove-web-player allows Object Injection.This issue affects Podlove Web Player: from n/a through <= 5.9.1. | |
| Modificada | Crítica (9.6) | 0.33% | — | Killergerbah Asbplayer | 25/2/2026 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in the subtitle loading function of the asbplayer Chrome Extension version 1.14.0 allows attackers to execute arbitrary JavaScript in the context of the active streaming platform via a crafted .srt subtitle file. Because the script executes within the same-site context, it can… | |
| Aplazada | Media (5.3) | 0.26% | — | Sonaar MP3 Audio PlayerAI | 19/2/2026 | 17/6/2026 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions 4.0 to 5.10 via the 'load_track_note_ajax' due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to view the… | |
| Aplazada | Media (5) | 0.19% | — | Sonaar MP3 Audio PlayerAI | 14/2/2026 | 17/6/2026 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Server-Side Request Forgery in versions 5.3 to 5.10 via the 'load_lyrics_ajax_callback' function. This makes it possible for authenticated attackers, with author level access and above, to make web requests to… | |
| Aplazada | Alta (8.5) | 0.15% | — | Bluestacks APP PlayerAI | 6/2/2026 | 17/6/2026 | BlueStacks App Player 2.4.44.62.57 contains an unquoted service path vulnerability in the BstHdLogRotatorSvc service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Bluestacks\HD-LogRotatorService.exe to inject malicious executables… | |
| Aplazada | Alta (8.4) | 0.80% | — | Quick PlayerAI | 30/1/2026 | 17/6/2026 | Quick Player 1.3 contains a buffer overflow vulnerability that allows attackers to execute arbitrary code by crafting a malicious .m3l file with carefully constructed payload. Attackers can trigger the vulnerability by loading a specially crafted file through the application's file loading mechanism, potentially… | |
| Aplazada | Media (5.4) | 0.19% | — | Softlabbd Radio PlayerAI | 23/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in princeahmed Radio Player radio-player allows Server Side Request Forgery.This issue affects Radio Player: from n/a through <= 2.0.91. | |
| Aplazada | Alta (7.1) | 0.21% | — | Lambertgroup Universal Video PlayerAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player universal-video-player allows Reflected XSS.This issue affects Universal Video Player: from n/a through <= 3.8.4. | |
| Aplazada | Alta (7.1) | 0.21% | — | Lambertgroup Universal Video PlayerAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup Universal Video Player universal-video-player allows Reflected XSS.This issue affects Universal Video Player: from n/a through <= 3.8.4. | |
| Aplazada | Alta (7.1) | 0.30% | — | Lambertgroup Html5 Video Player With Playlist AND Multiple SkinsAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5 Video Player with Playlist & Multiple Skins lbg-vp2-html5-rightside allows Reflected XSS.This issue affects HTML5 Video Player with Playlist & Multiple Skins: from n/a through <= 5.3.5. | |
| Aplazada | Alta (7.1) | 0.21% | — | Lambertgroup Html5 Video PlayerAI | 22/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LambertGroup HTML5 Video Player lbg-vp2-html5-bottom allows Reflected XSS.This issue affects HTML5 Video Player: from n/a through <= 5.3.5. | |
| Aplazada | Media (4.8) | 0.41% | — | Videolan VLC Media PlayerAI | 16/1/2026 | 17/6/2026 | mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server. | |
| Aplazada | Media (6.4) | 0.27% | — | Cool YT PlayerAI | 7/1/2026 | 17/6/2026 | The Cool YT Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'videoid' parameter in all versions up to, and including, 1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Aplazada | Alta (8.5) | 0.26% | — | TDM Digital Signage PC PlayerAI | 6/1/2026 | 17/6/2026 | TDM Digital Signage PC Player 4.1.0.4 contains an elevation of privileges vulnerability that allows authenticated users to modify executable files. Attackers can leverage the 'Modify' permissions for authenticated users to replace executable files with malicious binaries and gain elevated system access. | |
| Aplazada | Alta (8.7) | 0.39% | — | Adtec Digital Signedje Digital Signage PlayerAI | 6/1/2026 | 17/6/2026 | Adtec Digital SignEdje Digital Signage Player v2.08.28 contains multiple hardcoded default credentials that allow unauthenticated remote access to web, telnet, and SSH interfaces. Attackers can exploit these credentials to gain root-level access and execute system commands across multiple Adtec Digital product… | |
| Aplazada | Alta (8.7) | 1.4% | — | Cayin Signage Media PlayerAI | 6/1/2026 | 17/6/2026 | Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root. | |
| Aplazada | Media (4.3) | 0.21% | — | Nicashmu Post Video PlayersAI | 31/12/2025 | 23/9/2026 | Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in nicashmu Post Video Players video-playlist-and-gallery-plugin allows Retrieve Embedded Sensitive Data.This issue affects Post Video Players: from n/a through <= 1.163. | |
| Aplazada | Media (5.9) | 0.21% | — | Nicashmu Post Video PlayersAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in nicashmu Post Video Players video-playlist-and-gallery-plugin allows Stored XSS.This issue affects Post Video Players: from n/a through <= 1.163. |