Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

222 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.5)0.17%—Videolan VLC Media PlayerAI29/9/202630/9/2026
VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua…
AplazadaCrítica (9.8)0.69%—Actions Semiconductor CO LTD Tool - Media Player UtilitiesAI9/9/202610/9/2026
An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components
AplazadaMedia (5.3)0.24%—Videolan VLC Media PlayerAI9/9/202614/9/2026
Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build…
AplazadaAlta (7.3)0.12%—Videolan VLC Media PlayerAI9/9/202618/9/2026
VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.
AplazadaAlta (7.1)0.25%—CP Media PlayerAI27/8/202628/8/2026
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
AplazadaMedia (4.8)0.41%—Videolan VLC Media PlayerAI16/1/202617/6/2026
mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server.
AplazadaAlta (8.7)1.4%—Cayin Signage Media PlayerAI6/1/202617/6/2026
Cayin Signage Media Player 3.0 contains an authenticated remote command injection vulnerability in system.cgi and wizard_system.cgi pages. Attackers can exploit the 'NTP_Server_IP' parameter with default credentials to execute arbitrary shell commands as root.
AplazadaAlta (8.7)0.35%—Request Serious Play Media PlayerAI5/12/202517/6/2026
ReQuest Serious Play Media Player 3.0 contains an unauthenticated file disclosure vulnerability when input passed through the 'file' parameter in and script is not properly verified before being used to read web log files. Attackers can exploit this to disclose contents of files from local resources.
AplazadaMedia (6.4)0.25%—Media Player Addons FOR ElementorAI17/9/202525/9/2026
The Media Player Addons for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'subtitle_ssize', 'track_title', and 'track_artist_name' parameters in version 1.0.5. This is due to insufficient input sanitization and output escaping on user-supplied attributes. This makes it possible…
AplazadaAlta (8)0.61%—Videolan VLC Media PlayerAI25/9/202417/6/2026
VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's…
AplazadaMedia (5.4)0.21%—Codepeople CP Media PlayerAI15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in CodePeople CP Media Player.This issue affects CP Media Player: from n/a through 1.1.3.
ModificadaAlta (7.8)0.28%—Videolan VLC Media Player22/11/202317/6/2026
A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM.
ModificadaAlta (7.5)0.91%—Videolan VLC Media Player7/11/202317/6/2026
Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length.
ModificadaCrítica (9.8)1.1%—Videolan VLC Media Player7/11/202317/6/2026
Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption.
ModificadaAlta (8.8)0.27%—Shopbeat Shop Beat Media Player30/5/202317/6/2026
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Cross Site Request Forgery (CSRF).
ModificadaMedia (5.4)0.36%—Shopbeat Shop Beat Media Player30/5/202317/6/2026
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Bypass 2FA via APIs. For Controlpanel Lite. "After login we are directly able to use the bearer token or jsession ID to access the apis instead of entering the 2FA code. Thus, leading to bypass of 2FA on API level.
ModificadaCrítica (9.1)0.53%—Shopbeat Shop Beat Media Player30/5/202317/6/2026
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to IDOR via controlpanel.shopbeat.co.za.
ModificadaCrítica (9.8)0.68%—Shopbeat Shop Beat Media Player30/5/202317/6/2026
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Insecure Permissions.
ModificadaMedia (5.4)0.34%—Shopbeat Shop Beat Media Player30/5/202317/6/2026
Shop Beat Solutions (Pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 suffers from Multiple Stored Cross-Site Scripting (XSS) vulnerabilities via Shop Beat Control Panel found at www.shopbeat.co.za controlpanel.shopbeat.co.za.
ModificadaMedia (5.3)0.75%—Shopbeat Shop Beat Media Player30/5/202317/6/2026
Shop Beat Solutions (pty) LTD Shop Beat Media Player 2.5.95 up to 3.2.57 is vulnerable to Directory Traversal via server.shopbeat.co.za. Information Exposure Through Directory Listing vulnerability in "studio" software of Shop Beat. This issue affects: Shop Beat studio studio versions prior to 3.2.57 on arm.
ModificadaMedia (5.4)0.55%—Open Media Player27/12/202217/6/2026
A vulnerability was found in IET-OU Open Media Player up to 1.5.0. It has been declared as problematic. This vulnerability affects the function webvtt of the file application/controllers/timedtext.php. The manipulation of the argument ttml_url leads to cross site scripting. The attack can be initiated remotely.…
ModificadaAlta (7.8)0.68%—Videolan VLC Media PlayerDebian Linux6/12/202217/6/2026
An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions.
ModificadaAlta (7.5)1.8%—Videolan VLC Media Player26/7/202117/6/2026
A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application.
ModificadaAlta (7.1)0.74%—Videolan VLC Media Player26/7/202117/6/2026
A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.
ModificadaAlta (7.1)0.74%—Videolan VLC Media Player26/7/202117/6/2026
A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file.