Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

282 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.7%—Qnap Music Station14/9/201817/6/2026
Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run arbitrary commands in the compromised application.
ModificadaMedia (5.9)0.91%—Subsonic Music Streamer11/9/201817/6/2026
The Subsonic Music Streamer application 4.4 for Android has Improper Certificate Validation of the Subsonic server certificate, which might allow man-in-the-middle attackers to obtain interaction data.
ModificadaAlta (7.4)0.63%—Linecorp Line Music7/9/201817/6/2026
The LINE MUSIC for Android version 3.1.0 to versions prior to 3.6.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)0.99%—Tiktok Musical.ly15/8/201817/6/2026
Musical.ly Inc., musical.ly - your video social network, 6.1.6, 2017-10-03, iOS application uses a hard-coded key for encryption. Data stored using this key can be decrypted by anyone able to access this key.
ModificadaAlta (8.8)2.5%—Amazon Music2/3/201817/6/2026
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Amazon Music Player 6.1.5.1213. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI…
ModificadaCrítica (9.8)2.7%💥 ExploitJoommasters JMS Music2/2/201817/6/2026
SQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.
ModificadaMedia (6.1)0.78%—Webartisan Soundy Background Music22/1/201817/6/2026
The Soundy Background Music plugin 3.9 and below for WordPress has Cross-Site Scripting via soundy-background-music\templates\front-end.php (war_soundy_preview parameter).
ModificadaAlta (7.8)1.9%—Sony Music Center22/12/201717/6/2026
Untrusted search path vulnerability in Music Center for PC version 1.0.01 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (6.5)1.5%—Game-music-emu Project Game-music-emu6/12/201717/6/2026
The Mem_File_Reader::read_avail function in Data_Reader.cpp in the Game_Music_Emu library (aka game-music-emu) 0.6.1 does not ensure a non-negative size, which allows remote attackers to cause a denial of service (application crash) via a crafted file.
ModificadaAlta (7.8)1.0%—Sony Music Center1/12/201717/6/2026
Untrusted search path vulnerability in Music Center for PC version 1.0.00 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaCrítica (9.8)1.7%—Qnap Music Station6/10/201717/6/2026
QNAP discovered a number of command injection vulnerabilities found in Music Station versions 4.8.6 (for QTS 4.2.x), 5.0.7 (for QTS 4.3.x), and earlier. If exploited, these vulnerabilities may allow a remote attacker to run arbitrary commands on the NAS.
ModificadaAlta (7)0.71%—Earcms EAR Music30/7/201717/6/2026
In Earcms Ear Music through 4.1 build 20170710, remote authenticated users can execute arbitrary PHP code by changing the allowable music-upload extensions to include .php in addition to .mp3 and .m4a in admin.php?iframe=config_upload, and then using user.php/music/add/ to upload the code.
ModificadaCrítica (9.8)4.4%—Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+36/6/201717/6/2026
game-music-emu before 0.6.1 mishandles unspecified integer values.
ModificadaMedia (5.5)0.53%—Game-music-emu Project Game-music-emuFedoraproject FedoraOpensuse LeapOpensuse Project Leap+36/6/201717/6/2026
game-music-emu before 0.6.1 allows local users to cause a denial of service (divide by zero and process crash).
ModificadaAlta (7.8)2.3%—Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+512/4/201717/6/2026
game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.
ModificadaAlta (7.8)2.3%—Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+512/4/201717/6/2026
game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.
ModificadaAlta (7.8)1.9%—Opensuse LeapOpensuseOpensuse Project LeapSuse Linux Enterprise+512/4/201717/6/2026
Stack-based buffer overflow in game-music-emu before 0.6.1.
ModificadaMedia (4.8)0.23%—Apple Music7/4/201717/6/2026
The Apple Music (aka com.apple.android.music) application before 2.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.85%—Fomori Cherrymusic27/3/201717/6/2026
Cross-site scripting (XSS) vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to inject arbitrary web script or HTML via the playlistname field when creating a new playlist.
ModificadaMedia (4.3)6.7%💥 ExploitFomori Cherrymusic27/3/201717/6/2026
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary files via the "value" parameter to "download."
ModificadaMedia (6.8)1.5%—Newphoria Corporation Megaphone Music20/9/201517/6/2026
The Newphoria MEGAPHONE MUSIC application before 1.1 for Android and before 1.1 for iOS allows attackers to bypass a URL whitelist protection mechanism and obtain API access via unspecified vectors.
ModificadaMedia (5.4)0.27%—Imapp Realtime Music Rank20/10/201417/6/2026
The Realtime Music Rank (aka com.blogspot.imapp.immusicrank2) application 5.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Nobexrc Musica DE Barrios Sonideros19/10/201417/6/2026
The musica de barrios sonideros (aka com.nobexinc.wls_93155702.rc) application 3.3.10 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Webizz Apostilas Musicais11/10/201417/6/2026
The Apostilas musicais (aka com.apostilas) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Amazighmusic Project Amazighmusic23/9/201417/6/2026
The Amazighmusic (aka nl.appsandroo.Amazighmusic) application 1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Orbitaley — Vulnerabilidades