Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/lists/zhuan. | |
| Modificada | Alta (7.2) | 0.83% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/topic/save. | |
| Modificada | Alta (8.8) | 0.95% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/pl_save. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/hy. | |
| Modificada | Alta (7.2) | 0.83% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/news/admin/news/save. | |
| Modificada | Alta (7.2) | 0.94% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a blind SQL injection vulnerability via the id parameter at /admin.php/pic/admin/type/save. | |
| Modificada | Crítica (9.8) | 12% | — | Chshcms Cscms Music Portal System | 26/5/2022 | 17/6/2026 | CSCMS Music Portal System v4.2 was discovered to contain a SQL injection vulnerability via the id parameter at /admin.php/pic/admin/pic/del. | |
| Modificada | Alta (8.8) | 2.7% | — | Musical World Project Musical World | 8/4/2022 | 17/6/2026 | Musical World v1 was discovered to contain an arbitrary file upload vulnerability via uploaded_songs.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file. | |
| Modificada | Crítica (9.8) | 1.6% | — | Oretnom23 Simple Music Cloud Community System | 21/1/2022 | 17/6/2026 | An SQL Injection vulnerability exists in Sourcecodester Simple Music Clour Community System 1.0 via the email parameter in /music/ajax.php. | |
| Modificada | Media (4.8) | 0.64% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 1/11/2021 | 17/6/2026 | The MP3 Audio Player for Music, Radio & Podcast by Sonaar WordPress plugin before 2.4.2 does not properly sanitize or escape data in some of its Playlist settings, allowing high privilege users to perform Cross-Site Scripting attacks | |
| Modificada | Alta (7.8) | 0.32% | — | Sony Audio USB DriverSony HAP Music Transfer | 26/8/2021 | 17/6/2026 | Untrusted search path vulnerability in the installer of Sony Audio USB Driver V1.10 and prior and the installer of HAP Music Transfer Ver.1.3.0 and prior allows an attacker to gain privileges and execute arbitrary code via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (8.8) | 18% | — | Qnap Music Station | 13/5/2021 | 17/6/2026 | An improper access control vulnerability has been reported to affect earlier versions of Music Station. If exploited, this vulnerability allows attackers to compromise the security of the software by gaining privileges, reading sensitive information, executing commands, evading detection, etc. This issue affects: QNAP… | |
| Modificada | Media (6.1) | 0.99% | — | Qnap Music Station | 10/12/2020 | 17/6/2026 | This cross-site scripting vulnerability in Music Station allows remote attackers to inject malicious code. QANP have already fixed this vulnerability in the following versions of Music Station. QuTS hero h4.5.1: Music Station 5.3.13 and later QTS 4.5.1: Music Station 5.3.12 and later QTS 4.4.3: Music Station 5.3.12… | |
| Modificada | Alta (7.5) | 1.3% | — | Qnap Music Station | 2/11/2020 | 17/6/2026 | If exploited, this SQL injection vulnerability could allow remote attackers to obtain application information. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11. | |
| Modificada | Media (6.1) | 0.77% | — | Qnap Music Station | 2/11/2020 | 17/6/2026 | If exploited, this cross-site scripting vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11. | |
| Modificada | Crítica (9.8) | 2.1% | — | Qnap Music Station | 2/11/2020 | 17/6/2026 | If exploited, this command injection vulnerability could allow remote attackers to execute arbitrary commands. This issue affects: QNAP Systems Inc. Music Station versions prior to 5.1.13; versions prior to 5.2.9; versions prior to 5.3.11. | |
| Modificada | Media (5.5) | 0.76% | — | Apple Music | 27/10/2020 | 17/6/2026 | This issue was addressed with improved checks to prevent unauthorized actions. This issue is fixed in Apple Music 3.4.0 for Android. A malicious application may be able to leak a user's credentials. | |
| Modificada | Media (4.8) | 1.5% | — | Qnap Music Station | 5/12/2019 | 17/6/2026 | This cross-site scripting (XSS) vulnerability in Music Station allows remote attackers to inject and execute scripts on the administrator’s management console. To fix this vulnerability, QNAP recommend updating Music Station to their latest versions. | |
| Modificada | Crítica (9.8) | 2.3% | — | Qnap Music Station | 4/12/2019 | 17/6/2026 | This command injection vulnerability in Music Station allows attackers to execute commands on the affected device. To fix the vulnerability, QNAP recommend updating Music Station to their latest versions. | |
| Modificada | Media (6.1) | 1.6% | — | Codepeople Music Store | 17/9/2019 | 17/6/2026 | The music-store plugin before 1.0.43 for WordPress has XSS via the wp-admin/admin.php?page=music-store-menu-reports from_year parameter. | |
| Modificada | Alta (7.8) | 0.22% | — | Qualcomm Snapdragon Auto FirmwareQualcomm Snapdragon Consumer Internet OF Things FirmwareQualcomm Snapdragon Industrial Internet OF Things FirmwareQualcomm Snapdragon Internet OF Things Firmware+37 | 25/2/2019 | 17/6/2026 | Improper validation of array index can lead to unauthorized access while processing debugFS in Snapdragon Auto, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in version MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W,… | |
| Modificada | Media (5.5) | 0.20% | — | Qualcomm Snapdragon Auto FirmwareQualcomm Snapdragon Connectivity FirmwareQualcomm Snapdragon Consumer Internet OF Things FirmwareQualcomm Snapdragon Industrial Internet OF Things Firmware+32 | 25/2/2019 | 17/6/2026 | Arbitrary write issue can occur when user provides kernel address in compat mode in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Voice & Music, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9640, MDM9650, MSM8909W, MSM8996AU,… | |
| Modificada | Alta (8.1) | 1.5% | 💥 PoC | Musicloud Project Musicloud | 17/2/2019 | 17/6/2026 | A file-read vulnerability was identified in the Wi-Fi transfer feature of Musicloud 1.6. By default, the application runs a transfer service on port 8080, accessible by everyone on the same Wi-Fi network. An attacker can send the POST parameters downfiles and cur-folder (with a crafted ../ payload) to the… | |
| Modificada | Alta (7.5) | 1.5% | — | Sony Music Center FOR PC | 15/11/2018 | 17/6/2026 | An unvalidated software update vulnerability in Music Center for PC version 1.0.02 and earlier could allow a man-in-the-middle attacker to tamper with an update file and inject executable files. | |
| Modificada | Crítica (9.8) | 3.3% | 💥 Exploit | Joomlathat Music Collection | 28/9/2018 | 17/6/2026 | SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter. |