Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | Longtailvideo JW PlayerAI | 30/9/2026 | 30/9/2026 | Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions. | |
| Aplazada | Media (5.4) | 0.23% | — | Ilghera JW Player FOR WordpressAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in ilGhera JW Player for WordPress jw-player-7-for-wp allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects JW Player for WordPress: from n/a through <= 2.3.6. | |
| Aplazada | Alta (7.1) | 0.29% | — | Ilghera Related-videos-for-jw-playerAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ilGhera Related Videos for JW Player related-videos-for-jw-player allows Reflected XSS.This issue affects Related Videos for JW Player: from n/a through <= 1.2.0. | |
| Aplazada | Media (6.5) | 0.43% | — | Ilghera JW Player FOR WordpressAI | 3/5/2024 | 17/6/2026 | Missing Authorization vulnerability in ilGhera JW Player for WordPress.This issue affects JW Player for WordPress: from n/a through 2.3.3. | |
| Modificada | Media (6.1) | 2.6% | — | Longtailvideo JW Player | 20/2/2020 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers to inject arbitrary web script or HTML via the (1) link, (2) logo.link, or (3) aboutlink parameter, or a nested URI scheme name for (4) javascript, (5) asfunction, or (6) vbscript. | |
| Modificada | Media (6.8) | 2.9% | — | Longtailvideo JW Player FOR Flash & Html5 Video Plugin | 25/6/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the JW Player plugin before 2.1.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that remove players via a delete action to wp-admin/admin.php. | |
| Modificada | Media (4.3) | 4.4% | — | Longtailvideo JW Player | 21/5/2012 | 16/6/2026 | player.swf in LongTail JW Player 5.9 allows remote attackers to conduct cross-site scripting (XSS) attacks to inject arbitrary web script or HTML via multiple "javascript:" sequences in the debug parameter. |