Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2835▲ 112 respecto a la semana anterior
Críticas / altas1495▲ 318 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (2) | 0.69% | — | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A vulnerability was identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This vulnerability affects unknown code of the file /htdocs/userScripts.php. The manipulation of the argument Custom script leads to cross site scripting. The attack is possible to be carried out remotely. The exploit is publicly available and… | |
| Analizada | Baja (2) | 0.30% | — | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A vulnerability was determined in MiczFlor RPi-Jukebox-RFID up to 2.8.0. This affects an unknown part of the file /htdocs/cardRegisterNew.php. Executing manipulation can lead to cross site scripting. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. The vendor was… | |
| Analizada | Baja (2) | 0.30% | — | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A vulnerability was found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file /htdocs/manageFilesFolders.php. Performing manipulation results in cross site scripting. Remote exploitation of the attack is possible. The exploit has been made public and could be… | |
| Analizada | Baja (2) | 0.30% | — | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A vulnerability has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdocs/cardEdit.php. Such manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Baja (2) | 0.29% | — | Sourcefabric Rpi-jukebox-rfid | 13/9/2025 | 17/6/2026 | A flaw has been found in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/inc.setWlanIpMail.php. This manipulation of the argument Email address causes cross site scripting. The attack may be initiated remotely. The exploit has been published and may be used. The vendor was… | |
| Analizada | Baja (2.1) | 9.4% | — | Sourcefabric Rpi-jukebox-rfid | 12/9/2025 | 17/6/2026 | A security vulnerability has been detected in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this issue is some unknown functionality of the file /htdocs/api/playlist/playsinglefile.php. The manipulation of the argument File leads to os command injection. The attack may be initiated remotely. The exploit has been… | |
| Modificada | Baja (2.1) | 10% | — | Sourcefabric Rpi-jukebox-rfid | 12/9/2025 | 17/6/2026 | A weakness has been identified in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected by this vulnerability is an unknown functionality of the file /htdocs/api/playlist/shuffle.php. Executing manipulation of the argument playlist can lead to os command injection. The attack can be launched remotely. The exploit has been… | |
| Analizada | Baja (2.1) | 7.1% | — | Sourcefabric Rpi-jukebox-rfid | 12/9/2025 | 17/6/2026 | A security flaw has been discovered in MiczFlor RPi-Jukebox-RFID up to 2.8.0. Affected is an unknown function of the file /htdocs/api/playlist/single.php. Performing manipulation of the argument playlist results in os command injection. The attack can be initiated remotely. The exploit has been released to the public… | |
| Modificada | Crítica (9.8) | 2.7% | — | Sourcefabric Rpi-jukebox-rfid | 30/8/2022 | 17/6/2026 | RPi-Jukebox-RFID v2.3.0 was discovered to contain a command injection vulnerability via the component /htdocs/utils/Files.php. This vulnerability is exploited via a crafted payload injected into the file name of an uploaded file. | |
| Modificada | Media (6.9) | 0.36% | — | Audiotool Ease Jukebox | 6/9/2012 | 16/6/2026 | Untrusted search path vulnerability in Ease Jukebox 1.40 allows local users to gain privileges via a Trojan horse wmaudsdk.dll file in the current working directory, as demonstrated by a directory that contains a .mp3 or .wav file. NOTE: the provenance of this information is unknown; the details are obtained solely… | |
| Modificada | Media (5) | 14% | — | Jooforge COM Jukebox | 12/4/2010 | 16/6/2026 | Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 31% | — | Sorcerersoftware Multimedia Jukebox | 30/7/2009 | 16/6/2026 | Heap-based buffer overflow in Sorcerer Software MultiMedia Jukebox 4.0 Build 020124 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted (1) .m3u or possibly (2) .pst file. | |
| Modificada | Media (4.3) | 1.5% | — | Jinzora Media Jukebox | 21/2/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Jinzora Media Jukebox 2.7.5 allow remote attackers to inject arbitrary web script or HTML via the (1) frontend, (2) set_frontend, (3) jz_path, (4) theme, and (5) set_theme parameters to (a) index.php; the frontend, theme, and (6) language parameters to (b)… | |
| Modificada | Media (4.3) | 9.2% | — | Yahoo Music Jukebox | 6/2/2008 | 16/6/2026 | Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows remote attackers to execute arbitrary code via a long argument to the AddImage method. | |
| Modificada | Media (4.3) | 8.1% | — | Yahoo Music Jukebox | 6/2/2008 | 16/6/2026 | Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddBitmap method. | |
| Modificada | Media (4.3) | 7.6% | — | Yahoo Music Jukebox | 6/2/2008 | 16/6/2026 | Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to execute arbitrary code via a long argument to the AddButton method, a different vulnerability than CVE-2008-0623. | |
| Modificada | Media (4.3) | 2.0% | — | Netjukebox | 22/6/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in netjukebox 4.01b allow remote attackers to inject arbitrary web script or HTML via the (1) album_id, (2) order, (3) sort, (4) filter, and (5) genre_id parameters to (a) index.php; and the (6) url parameter to (b) ridirect.php. NOTE: the attack also reveals the… | |
| Modificada | Media (6.8) | 1.1% | — | Musicmatch Jukebox | 2/5/2005 | 16/6/2026 | Musicmatch Jukebox 10.00.2047 and earlier adds the musicmatch.com domain to the Trusted Sites zone in Internet Explorer, which allows systems in the domain to conduct unauthorized activities, as demonstrated using cross-site scripting (XSS) attacks. | |
| Modificada | Baja (2.1) | 0.31% | — | Musicmatch Jukebox | 2/5/2005 | 16/6/2026 | Musicmatch 10.00.2047 and earlier store log files in the Program Files directory instead of the user profile, which may allow local users to obtain sensitive information. | |
| Modificada | Media (5) | 1.1% | — | Musicmatch Jukebox | 2/5/2005 | 16/6/2026 | DiagCollectionControl.dll in Musicmatch 10.00.2047 and earlier allows remote attackers to overwrite arbitrary files via the bstrSavePath argument. | |
| Modificada | Media (4.6) | 0.34% | — | Musicmatch Jukebox | 2/5/2005 | 16/6/2026 | Unquoted Windows search path vulnerability in Musicmatch Jukebox 10.00.2047 and earlier allows local users to gain privileges via a malicious C:\program.exe file, which is run by MMFWLaunch.exe when it attempts to execute launch.exe. | |
| Modificada | Alta (7.5) | 2.0% | — | Realnetworks Realjukebox 2Realnetworks Realjukebox 2 PlusRealnetworks Realone Player | 4/10/2002 | 16/6/2026 | RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary script in the Local computer zone by inserting the script into the skin.ini file of an RJS archive, then referencing skin.ini from a web page after it has been extracted, which is parsed as HTML by… | |
| Modificada | Alta (7.5) | 8.1% | — | Realnetworks Realjukebox 2Realnetworks Realjukebox 2 PlusRealnetworks Realone Player | 4/10/2002 | 16/6/2026 | Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to execute arbitrary code via an RFS skin file whose skin.ini contains a long value in a CONTROLnImage argument, such as CONTROL1Image. |