Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 87 respecto a la semana anterior
Críticas / altas1458▲ 97 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.33% | — | Codepeople Music Player FOR WoocommerceAI | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in codepeople Music Player for WooCommerce music-player-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Music Player for WooCommerce: from n/a through <= 1.5.1. | |
| Analizada | Media (5.3) | 0.55% | — | Oretnom23 Music Class Enrollment System | 14/4/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Music Class Enrollment System 1.0. Affected is an unknown function of the file /manage_class.php. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Aplazada | Media (4.3) | 0.40% | — | Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.9.4. | |
| Aplazada | Media (6.5) | 0.40% | — | Smartwpress Musicians Pack FOR ElementorAI | 4/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in smartwpress Musician's Pack For Elementor music-pack-for-elementor allows DOM-Based XSS.This issue affects Musician's Pack For Elementor: from n/a through <= 1.8.7. | |
| Analizada | Media (5.1) | 0.69% | — | Tencentmusic Supersonic | 3/4/2025 | 17/6/2026 | A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Database Connection Handler. The manipulation leads to code injection. The attack may… | |
| Aplazada | Media (5.3) | 0.37% | — | Music Press PROAI | 24/3/2025 | 17/6/2026 | Missing Authorization vulnerability in tuyennv Music Press Pro music-press-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Music Press Pro: from n/a through <= 1.4.6. | |
| Aplazada | Alta (7.5) | 0.51% | — | Partitionnumerique Music Sheet ViewerAI | 7/2/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in efreja Music Sheet Viewer music-sheet-viewer allows Path Traversal.This issue affects Music Sheet Viewer: from n/a through <= 4.1. | |
| Aplazada | Media (6.5) | 0.23% | — | Tuyennv Music Press PROAI | 4/2/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in tuyennv Music Press Pro music-press-pro allows Stored XSS.This issue affects Music Press Pro: from n/a through <= 1.4.6. | |
| Analizada | Media (6.1) | 0.58% | 💥 Exploit | Webdesignby Musicbox | 4/2/2025 | 17/6/2026 | The Musicbox WordPress plugin through 2.0.3 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Alta (7.5) | 0.54% | — | Partitionnumerique Music Sheet Viewer | 30/1/2025 | 17/6/2026 | The Music Sheet Viewer plugin for WordPress is vulnerable to Arbitrary File Read in all versions up to, and including, 4.1 via the read_score_file() function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.… | |
| Analizada | Media (5.4) | 0.22% | — | Partitionnumerique Music Sheet Viewer | 30/1/2025 | 17/6/2026 | The Music Sheet Viewer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pn_msv' shortcode in all versions up to, and including, 4.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.5) | 0.32% | — | Kugou Technology CO LTD Kugou MusicAI | 27/1/2025 | 17/6/2026 | An issue in KuGou Technology CO. LTD KuGou Music iOS v20.0.0 allows attackers to access sensitive user information via supplying a crafted link. | |
| Aplazada | Alta (7.1) | 0.26% | — | Codepeople Music StoreAI | 27/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in codepeople Music Store music-store allows Reflected XSS.This issue affects Music Store: from n/a through <= 1.1.19. | |
| Modificada | Media (4.3) | 0.21% | — | Apple Music | 15/1/2025 | 17/6/2026 | The issue was addressed with improved input sanitization. This issue is fixed in Apple Music 1.5.0.152 for Windows. Processing maliciously crafted web content may disclose internal states of the app. | |
| Aplazada | Alta (7.6) | 0.58% | — | Hiren.sabd WP Music PlayerAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in hiren.sabd WP Music Player wp-music-player allows SQL Injection.This issue affects WP Music Player: from n/a through <= 1.3. | |
| Aplazada | Alta (8.8) | 0.53% | — | Croma MusicAI | 7/1/2025 | 17/6/2026 | The Croma Music plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the 'ironMusic_ajax' function in all versions up to, and including, 3.6. This makes it possible for authenticated attackers, with Subscriber-level access… | |
| Modificada | Alta (8.8) | 0.33% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 2/1/2025 | 17/6/2026 | Missing Authorization vulnerability in sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through <= 5.8. | |
| Aplazada | Alta (7.3) | 0.28% | — | Huawei Home Music SystemAI | 28/12/2024 | 17/6/2026 | Some Huawei home music system products have a path traversal vulnerability. Successful exploitation of this vulnerability may cause unauthorized file deletion or file permission change.(Vulnerability ID:HWPSIRT-2023-53450) This vulnerability has been assigned a (CVE)ID:CVE-2023-7263 | |
| Aplazada | Alta (8) | 0.30% | — | Huawei Home Music SystemAI | 26/12/2024 | 17/6/2026 | Huawei Home Music System has a path traversal vulnerability. Successful exploitation of this vulnerability may cause the music host file to be deleted or the file permission to be changed.(Vulnerability ID:HWPSIRT-2023-60613) | |
| Analizada | Alta (8.8) | 0.43% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Sonaar Music MP3 Audio Player for Music, Radio & Podcast by Sonaar allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 4.10. | |
| Aplazada | Alta (7.1) | 0.17% | — | Rockemmusic Favicon MY BlogAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in rockemmusic Favicon My Blog favicon-my-blog allows Stored XSS.This issue affects Favicon My Blog: from n/a through <= 1.0.2. | |
| Analizada | Media (5.4) | 0.34% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 19/11/2024 | 17/6/2026 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.8 due to insufficient input sanitization and output escaping on user supplied attributes. This… | |
| Analizada | Media (4.3) | 0.33% | — | Smartwpress Music Player FOR Elementor | 15/11/2024 | 17/6/2026 | The Music Player for Elementor – Audio Player & Podcast Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the import_mpfe_template() function in all versions up to, and including, 2.4.1. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (5.3) | 0.53% | — | Oretnom23 Simple Music Cloud Community System | 10/11/2024 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Simple Music Cloud Community System 1.0. This vulnerability affects unknown code of the file /music/ajax.php?action=signup. The manipulation of the argument pp leads to unrestricted upload. The attack can be initiated remotely. The exploit has been… | |
| Analizada | Crítica (9.8) | 0.56% | — | Lopalopa Music Management System | 25/9/2024 | 17/6/2026 | An Incorrect Access Control vulnerability was found in /music/ajax.php?action=delete_playlist in Kashipara Music Management System v1.0. This vulnerability allows an unauthenticated attacker to delete the valid music playlist entries. |