Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
222 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.5) | 0.17% | — | Videolan VLC Media PlayerAI | 29/9/2026 | 30/9/2026 | VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua… | |
| Aplazada | Crítica (9.8) | 0.69% | — | Actions Semiconductor CO LTD Tool - Media Player UtilitiesAI | 9/9/2026 | 10/9/2026 | An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components | |
| Aplazada | Media (5.3) | 0.24% | — | Videolan VLC Media PlayerAI | 9/9/2026 | 14/9/2026 | Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build… | |
| Aplazada | Alta (7.3) | 0.12% | — | Videolan VLC Media PlayerAI | 9/9/2026 | 18/9/2026 | VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process. | |
| Aplazada | Alta (7.1) | 0.25% | — | CP Media PlayerAI | 27/8/2026 | 28/8/2026 | Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions. | |
| Aplazada | Media (4.8) | 0.41% | — | Videolan VLC Media PlayerAI | 16/1/2026 | 17/6/2026 | mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server. | |
| Aplazada | Alta (8.7) | 1.4% | — | Cayin Signage Media PlayerAI | 6/1/2026 | 17/6/2026 | Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root. | |
| Aplazada | Alta (8.7) | 0.35% | — | Request Serious Play Media PlayerAI | 5/12/2025 | 17/6/2026 | ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files from local resources. | |
| Aplazada | Media (6.4) | 0.25% | — | Media Player Addons FOR ElementorAI | 17/9/2025 | 25/9/2026 | The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitle_ssize', 'track_title', and 'track_artist_name' parameters in version 1.0.5. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible… | |
| Aplazada | Alta (8) | 0.61% | — | Videolan VLC Media PlayerAI | 25/9/2024 | 17/6/2026 | VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's… | |
| Aplazada | Media (5.4) | 0.21% | — | Codepeople CP Media PlayerAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in CodePeople CP Media Player.This issue affects CP Media Player: from n/a through 1.1.3. | |
| Modificada | Alta (7.8) | 0.28% | — | Videolan VLC Media Player | 22/11/2023 | 17/6/2026 | A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM. | |
| Modificada | Alta (7.5) | 0.91% | — | Videolan VLC Media Player | 7/11/2023 | 17/6/2026 | Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length. | |
| Modificada | Crítica (9.8) | 1.1% | — | Videolan VLC Media Player | 7/11/2023 | 17/6/2026 | Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption. | |
| Modificada | Alta (8.8) | 0.27% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Cross Site Request Forgery (CSRF). | |
| Modificada | Media (5.4) | 0.36% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level. | |
| Modificada | Crítica (9.1) | 0.53% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za. | |
| Modificada | Crítica (9.8) | 0.68% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions. | |
| Modificada | Media (5.4) | 0.34% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 suffers from Multiple Stored Cross-Site Scripting (XSS) vulnerabilities via Shop Beat Control Panel found at www.shopbeat.co.za controlpanel.shopbeat.co.za. | |
| Modificada | Media (5.3) | 0.75% | — | Shopbeat Shop Beat Media Player | 30/5/2023 | 17/6/2026 | Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. Information Exposure Through Directory Listing vulnerability in "studio" software of Shop Beat. This issue affects: Shop Beat studio studio versions prior to 3.2.57 on arm. | |
| Modificada | Media (5.4) | 0.55% | — | Open Media Player | 27/12/2022 | 17/6/2026 | A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation of the argument ttml_url leads to cross site scripting. The attack can be initiated remotely.… | |
| Modificada | Alta (7.8) | 0.68% | — | Videolan VLC Media PlayerDebian Linux | 6/12/2022 | 17/6/2026 | An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions. | |
| Modificada | Alta (7.5) | 1.8% | — | Videolan VLC Media Player | 26/7/2021 | 17/6/2026 | A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application. | |
| Modificada | Alta (7.1) | 0.74% | — | Videolan VLC Media Player | 26/7/2021 | 17/6/2026 | A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. | |
| Modificada | Alta (7.1) | 0.74% | — | Videolan VLC Media Player | 26/7/2021 | 17/6/2026 | A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. |