Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
2395 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8) | 0.61% | — | Videolan VLC Media PlayerAI | 25/9/2024 | 17/6/2026 | VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's… | |
| Modificada | Media (5.4) | 0.35% | — | Softlabbd Radio Player | 25/9/2024 | 17/6/2026 | The Radio Player – Live Shoutcast, Icecast and Any Audio Stream Player for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'align' attribute within the 'wp:radio-player' Gutenberg block in all versions up to, and including, 2.0.78 due to insufficient input sanitization and output… | |
| Aplazada | Crítica (9.8) | 0.43% | — | Afmobi BoomplayerAI | 14/9/2024 | 17/6/2026 | Improper permission configurationDomain configuration vulnerability of the mobile application (com.afmobi.boomplayer) can lead to account takeover risks. | |
| Analizada | Media (5.3) | 0.39% | — | Bplugins Html5 Video Player | 11/9/2024 | 17/6/2026 | The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on multiple functions called via the 'h5vp_ajax_handler' ajax action in all versions up to, and including, 2.5.32. This makes it possible for unauthenticated… | |
| Analizada | Media (4.3) | 0.31% | — | Bplugins Html5 Video Player | 11/9/2024 | 17/6/2026 | The HTML5 Video Player – mp4 Video Player Plugin and Block plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'save_password' function in all versions up to, and including, 2.5.34. This makes it possible for authenticated attackers, with Subscriber-level… | |
| Modificada | Alta (8.1) | 19% | 💥 PoC | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 29/8/2024 | 17/6/2026 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the removeTempFiles() function and insufficient path validation on the 'file' parameter in all versions up to, and including, 5.7.0.1.… | |
| Analizada | Media (5.3) | 0.41% | — | Softlabbd Radio Player | 17/8/2024 | 17/6/2026 | The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_settings function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update plugin settings. | |
| Analizada | Media (5.3) | 0.41% | — | Softlabbd Radio Player | 17/8/2024 | 17/6/2026 | The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the update_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to update player instances. | |
| Analizada | Media (5.3) | 0.51% | — | Softlabbd Radio Player | 17/8/2024 | 17/6/2026 | The Radio Player plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the delete_player function in versions up to, and including, 2.0.73. This makes it possible for unauthenticated attackers to delete player instances. | |
| Analizada | Media (5.5) | 0.16% | — | Pandora Kmplayer | 5/8/2024 | 17/6/2026 | A segmentation fault in KMPlayer v4.2.2.65 allows attackers to cause a Denial of Service (DoS) via a crafted AVI file. | |
| Modificada | Media (5.4) | 0.26% | — | Bplugins Html5 Audio Player | 22/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bPlugins Html5 Audio Player allows Stored XSS.This issue affects Html5 Audio Player: from n/a through 2.2.23. | |
| Modificada | Media (5.4) | 0.32% | — | Bradmax Player | 20/7/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in bradmax Bradmax Player allows Stored XSS.This issue affects Bradmax Player: from n/a through 1.1.27. | |
| Modificada | Alta (8.8) | 0.51% | — | Foliovision FV Flowplayer Video Player | 19/7/2024 | 17/6/2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to time-based SQL Injection via the ‘exclude’ parameter in all versions up to, and including, 7.5.46.7212 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible… | |
| Modificada | Media (5.4) | 0.33% | — | Sonaar MP3 Audio Player FOR Music, Radio & Podcast | 10/7/2024 | 17/6/2026 | The MP3 Audio Player – Music Player, Podcast Player & Radio by Sonaar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'id' attribute within the plugin's sonaar_audioplayer shortcode in all versions up to, and including, 5.5 due to insufficient input sanitization and output escaping on user… | |
| Analizada | Media (6.5) | 2.6% | 💥 Exploit | Bplugins Html5 Video Player | 20/6/2024 | 17/6/2026 | The HTML5 Video Player WordPress plugin before 2.5.27 does not sanitize and escape a parameter from a REST route before using it in a SQL statement, allowing unauthenticated users to perform SQL injection attacks | |
| Modificada | Media (5.3) | 0.34% | — | Softlabbd Radio Player | 11/6/2024 | 17/6/2026 | Missing Authorization vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | |
| Aplazada | Media (5.3) | 0.36% | — | Podlove WEB PlayerAI | 8/6/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Podlove Podlove Web Player.This issue affects Podlove Web Player: from n/a through 5.7.3. | |
| Aplazada | Media (6.8) | 0.26% | — | Ariane Allegro Scenario PlayerAICisco DUOAI | 6/6/2024 | 17/6/2026 | Ariane Allegro Scenario Player through 2024-03-05, when Ariane Duo kiosk mode is used, allows physically proximate attackers to obtain sensitive information (such as hotel invoice content with PII), and potentially create unauthorized room keys, by entering a guest-search quote character and then accessing the… | |
| Aplazada | Alta (7.1) | 0.27% | — | Foliovision FV Flowplayer Video PlayerAI | 3/6/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Foliovision FV Flowplayer Video Player allows Reflected XSS.This issue affects FV Flowplayer Video Player: from n/a through 7.5.45.7212. | |
| Aplazada | Media (6.4) | 0.34% | — | Wphowto Videojs Html5 PlayerAI | 24/5/2024 | 17/6/2026 | The Videojs HTML5 Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's videojs_video shortcode in all versions up to, and including, 1.1.11 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.4) | 0.46% | — | Bplugins Html5 Audio PlayerAI | 14/5/2024 | 17/6/2026 | The HTML5 Audio Player- Best WordPress Audio Player Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's widgets in all versions up to, and including, 2.2.19 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.43% | — | Ilghera JW Player FOR WordpressAI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from n/a through 2.3.3. | |
| Aplazada | Alta (8.3) | 0.44% | — | ZD Youtube FLV PlayerAI | 30/4/2024 | 17/6/2026 | The ZD YouTube FLV Player plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2.6 via the $_GET['image'] parameter. This makes it possible for unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used… | |
| Aplazada | Media (5.4) | 0.32% | — | Softlabbd Radio PlayerAI | 25/4/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in SoftLab Radio Player.This issue affects Radio Player: from n/a through 2.0.73. | |
| Aplazada | Media (4.1) | 0.34% | — | Foliovision FV Flowplayer Video PlayerAI | 24/4/2024 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Foliovision FV Flowplayer Video Player.This issue affects FV Flowplayer Video Player: from n/a through 7.5.44.7212. |