Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
2394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.33% | — | Streamweasels Twitch PlayerAI | 24/12/2025 | 17/6/2026 | Missing Authorization vulnerability in JayBee Twitch Player ttv-easy-embed-player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Twitch Player: from n/a through <= 2.1.3. | |
| Aplazada | Alta (7.2) | 0.24% | — | Bplugins Html5 Audio PlayerAI | 19/12/2025 | 17/6/2026 | The HTML5 Audio Player – The Ultimate No-Code Podcast, MP3 & Audio Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions from 2.4.0 up to, and including, 2.5.1 via the getIcyMetadata() function. This makes it possible for unauthenticated attackers to make web requests to arbitrary… | |
| Aplazada | Crítica (9.3) | 0.35% | — | Mmetrodw TplayerAI | 18/12/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in mmetrodw tPlayer tplayer-html5-audio-player-with-playlist allows SQL Injection.This issue affects tPlayer: from n/a through <= 1.2.1.6. | |
| Analizada | Alta (7.5) | 0.45% | — | Gomlab GOM Player | 15/12/2025 | 17/6/2026 | GOM Player 2.3.90.5360 contains a remote code execution vulnerability in its Internet Explorer component that allows attackers to execute arbitrary code through DNS spoofing. Attackers can redirect victims using a malicious URL shortcut and WebDAV technique to run a reverse shell with SMB server interaction. | |
| Analizada | Media (6.7) | 0.48% | — | Gomlab GOM Player | 15/12/2025 | 17/6/2026 | GOM Player 2.3.90.5360 contains a buffer overflow vulnerability in the equalizer preset name input field that allows attackers to crash the application. Attackers can overwrite the preset name with 260 'A' characters to trigger a buffer overflow and cause application instability. | |
| Aplazada | Alta (8.8) | 0.80% | — | Player LeaderboardAI | 12/12/2025 | 30/9/2026 | The Player Leaderboard plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 1.0.2 via the 'player_leaderboard' shortcode. This is due to the plugin using an unsanitized user-supplied value from the shortcode's 'mode' attribute in a call to include() without proper path… | |
| Modificada | Alta (7.5) | 0.31% | — | Jxlindia JXL 9 Inch CAR Android Double DIN Player Firmware | 10/12/2025 | 5/7/2026 | An issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted Link Manager Protocol (LMP) packet. | |
| Aplazada | Alta (8.7) | 0.35% | — | Request Serious Play Media PlayerAI | 5/12/2025 | 17/6/2026 | ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files from local resources. | |
| Modificada | Alta (7.6) | 0.29% | — | Jxlindia JXL 9 Inch CAR Android Double DIN Player Firmware | 4/12/2025 | 5/7/2026 | An issue in the Bluetooth Human Interface Device (HID) of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to inject arbitrary keystrokes via a spoofed Bluetooth HID device. | |
| Analizada | Baja (1.9) | 0.34% | — | Rareprob HD Video Player ALL Formats | 2/12/2025 | 17/6/2026 | A security vulnerability has been detected in Rareprob HD Video Player All Formats App 12.1.372 on Android. Impacted is an unknown function of the component com.rocks.music.videoplayer. The manipulation leads to path traversal. The attack needs to be performed locally. The exploit has been disclosed publicly and may… | |
| Aplazada | Baja (2.1) | 0.25% | — | Lkinderbueno Streamity Xtream Iptv PlayerAI | 24/11/2025 | 17/6/2026 | A vulnerability was found in lKinderBueno Streamity Xtream IPTV Player up to 2.8. The impacted element is an unknown function of the file public/proxy.php. Performing manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. Upgrading… | |
| Aplazada | Crítica (9.8) | 0.57% | — | WaveplayerAI | 19/11/2025 | 17/6/2026 | The WavePlayer WordPress plugin before 3.8.0 does not have authorization in an AJAX action as well as does not validate the file to be copied locally, allowing unauthenticated users to upload arbitrary file on the server and lead to RCE | |
| Aplazada | Media (6.4) | 0.23% | — | PlayerzbrAI | 22/10/2025 | 17/6/2026 | The Playerzbr plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'urlmeta' post meta field in all versions up to, and including, 1.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject… | |
| Aplazada | Media (6.5) | 0.41% | — | ALL IN ONE Music PlayerAI | 30/9/2025 | 17/6/2026 | The All in One Music Player plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.3.1 via the 'theme' parameter. This makes it possible for authenticated attackers, with Contributor-level access and above, to read the contents of files on the server, which can contain sensitive… | |
| Aplazada | Media (6.5) | 0.21% | — | PlayerjsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PlayerJS PlayerJS playerjs allows DOM-Based XSS.This issue affects PlayerJS: from n/a through <= 2.24. | |
| Aplazada | Media (6.4) | 0.25% | — | Media Player Addons FOR ElementorAI | 17/9/2025 | 25/9/2026 | The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitle_ssize', 'track_title', and 'track_artist_name' parameters in version 1.0.5. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible… | |
| Aplazada | Alta (7.2) | 0.25% | — | Fwdesign Ultimate Video PlayerAI | 9/9/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in FWDesign Ultimate Video Player fwduvp allows Server Side Request Forgery.This issue affects Ultimate Video Player: from n/a through <= 10.1. | |
| Aplazada | Alta (7.1) | 0.12% | — | Ericzane Floating Window Music PlayerAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ericzane Floating Window Music Player floating-window-music-player allows Stored XSS.This issue affects Floating Window Music Player: from n/a through <= 3.4.2. | |
| Aplazada | Crítica (10) | 0.76% | — | Bsplayer BS PlayerAI | 30/8/2025 | 16/6/2026 | BS.Player version 2.57 (build 1051) contains a vulnerability in its playlist import functionality. When processing .m3u files, the application fails to properly validate the length of playlist entries, resulting in a buffer overflow condition. This flaw occurs during parsing of long URLs embedded in the playlist,… | |
| Aplazada | Alta (7.1) | 0.23% | — | Yahoo WebplayerAI | 28/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in 8bitkid Yahoo! WebPlayer yahoo-media-player allows Reflected XSS.This issue affects Yahoo! WebPlayer: from n/a through <= 2.0.6. | |
| Aplazada | Alta (8.4) | 0.34% | — | Steinberg Mymp3playerAI | 21/8/2025 | 16/6/2026 | Steinberg MyMP3Player version 3.0 (build 3.0.0.67) is vulnerable to a stack-based buffer overflow when parsing .m3u playlist files. The application fails to properly validate the length of input data within the playlist, allowing a specially crafted file to overwrite critical memory structures and execute arbitrary… | |
| Aplazada | Alta (8.4) | 0.35% | — | MJM Core PlayerAI | 20/8/2025 | 16/6/2026 | MJM Core Player (likely now referred to as MJM Player) 2011 is vulnerable to a stack-based buffer overflow when parsing specially crafted .s3m music files. The vulnerability arises from improper bounds checking in the file parser, allowing an attacker to overwrite memory on the stack and execute arbitrary code.… | |
| Aplazada | Alta (8.4) | 0.35% | — | MJM QuickplayerAI | 20/8/2025 | 16/6/2026 | MJM QuickPlayer (also known as MJM Player) version 2010 contains a stack-based buffer overflow vulnerability triggered by opening a malicious .s3m music file. The flaw occurs due to improper bounds checking in the file parser, allowing an attacker to overwrite memory and execute arbitrary code. Exploitation is… | |
| Aplazada | Alta (8.6) | 0.80% | — | SplayerAI | 20/8/2025 | 16/6/2026 | SPlayer version 3.7 and earlier is vulnerable to a stack-based buffer overflow when processing HTTP responses containing an overly long Content-Type header. The vulnerability occurs due to improper bounds checking on the header value, allowing an attacker to overwrite the Structured Exception Handler (SEH) and execute… | |
| Aplazada | Alta (8.4) | 0.34% | — | Xion Audio PlayerAI | 20/8/2025 | 16/6/2026 | Xion Audio Player versions 1.0.126 and prior are vulnerable to a Unicode-based stack buffer overflow triggered by opening a specially crafted .m3u playlist file. The file contains an overly long string that overwrites the Structured Exception Handler (SEH) chain, allowing an attacker to hijack execution flow and run… |