Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

282 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.62%—Apple Music27/2/202317/6/2026
A logic issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sensitive data.
ModificadaAlta (7.5)0.55%—Apple Music27/2/202317/6/2026
This issue was addressed with improved state management. This issue is fixed in Apple Music 3.9.10 for Android. An app may be able to access user-sensitive data.
ModificadaMedia (5.9)0.47%—Apple Music27/2/202317/6/2026
This issue was addressed by using HTTPS when sending information over the network. This issue is fixed in Apple Music 3.5.0 for Android. An attacker in a privileged network position can track a user's activity.
ModificadaCrítica (9.8)0.46%—Music Gallery Site Project Music Gallery Site27/2/202317/6/2026
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been classified as critical. Affected is an unknown function of the file /admin/?page=user/manage. The manipulation of the argument id leads to sql injection. It is possible to launch the attack remotely. The identifier of this vulnerability is…
ModificadaCrítica (9.8)0.46%—Music Gallery Site Project Music Gallery Site27/2/202317/6/2026
A vulnerability was found in SourceCodester Music Gallery Site 1.0 and classified as critical. This issue affects some unknown processing of the file view_category.php. The manipulation of the argument id leads to sql injection. The attack may be initiated remotely. The associated identifier of this vulnerability is…
AnalizadaAlta (7.5)1.2%—Musicpd Music Player Daemon26/2/202317/6/2026
In MPD before 0.23.8, as used on Automotive Grade Linux and other platforms, the PipeWire output plugin mishandles a Drain call in certain situations involving truncated files. Eventually there is an assertion failure in libmpdclient because libqtappfw passes in a NULL pointer.
ModificadaCrítica (9.8)4.7%💥 ExploitMusic Gallery Site Project Music Gallery Site22/2/202317/6/2026
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been rated as critical. This issue affects some unknown processing of the file Users.php of the component POST Request Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been…
ModificadaAlta (8.8)1.7%💥 ExploitMusic Gallery Site Project Music Gallery Site22/2/202317/6/2026
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been declared as critical. This vulnerability affects unknown code of the file Master.php of the component GET Request Handler. The manipulation of the argument id leads to sql injection. The attack can be initiated remotely. The exploit has…
ModificadaCrítica (9.8)1.9%💥 ExploitMusic Gallery Site Project Music Gallery Site22/2/202317/6/2026
A vulnerability was found in SourceCodester Music Gallery Site 1.0. It has been classified as critical. This affects an unknown part of the file view_music_details.php of the component GET Request Handler. The manipulation of the argument id leads to sql injection. It is possible to initiate the attack remotely. The…
ModificadaCrítica (9.8)1.8%💥 ExploitMusic Gallery Site Project Music Gallery Site21/2/202317/6/2026
A vulnerability classified as critical has been found in SourceCodester Music Gallery Site 1.0. This affects an unknown part of the file music_list.php of the component GET Request Handler. The manipulation of the argument cid leads to sql injection. It is possible to initiate the attack remotely. The exploit has been…
ModificadaAlta (7.5)0.93%—Musicpd Music Player Daemon10/1/202317/6/2026
An issue in MPD (Music Player Daemon) v0.23.10 allows attackers to cause a Denial of Service (DoS) via a crafted input.
ModificadaAlta (7.2)0.94%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/del.
ModificadaAlta (7.2)0.94%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/singer/hy.
ModificadaAlta (7.2)0.94%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/level_del.
ModificadaAlta (7.2)0.94%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/singer/admin/lists/zhuan.
ModificadaAlta (8.8)0.95%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/User/level_sort.
ModificadaAlta (7.2)0.94%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/js_del.
ModificadaAlta (7.2)0.94%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Label/page_del.
ModificadaAlta (7.2)0.94%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/vod/admin/topic/del.
ModificadaAlta (7.2)0.94%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/Links/del.
ModificadaAlta (7.2)0.94%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/user/zu_del.
ModificadaAlta (7.2)0.94%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan.
ModificadaAlta (7.2)0.94%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/del.
ModificadaAlta (8.8)0.95%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/lists/zhuan.
ModificadaAlta (8.8)0.95%—Chshcms Cscms Music Portal System26/5/202217/6/2026
CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via /admin.php/pic/admin/pic/hy. This vulnerability is exploited via restoring deleted photos.
Orbitaley — Vulnerabilidades