Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.40% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 allows an admin user to write arbitrary files that may be executed on load. The preference TranscoderH264Options is appended verbatim to x264's option string on every transcode. At startup, all .so files are run without signature, execute bit, or symbol checks. | |
| Analizada | Media (5.3) | 0.22% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 allows an authenticated user to request arbitrary internal or external addresses via the '/video/:/transcode/universal' path parameter. | |
| Analizada | Media (6.9) | 0.23% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 does not correctly neutralize URL values included in 'searchOne,' allowing an attacker to call other plugins' functions and supply their own parameters. | |
| Analizada | Media (5.3) | 0.22% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 allows SSRF via '/player/timeline'. An attacker using any X-Plex-Token value can include a full URL in the 'protocol' parameter and force the Plex server to POST to the attacker's chosen destination. | |
| Analizada | Alta (7.1) | 0.52% | — | Plex Media Server | 23/9/2026 | 29/9/2026 | Plex Media Server before 1.43.3.10861 builds a file path from the url parameter without checking it for ../ sequences, allowing path traversal via '/system/agents/media/get'. A remote attacker with a valid session token could read any file that the target user can access. This access includes the PlexOnlineToken,… | |
| Aplazada | Baja (2.1) | 0.42% | — | AV Stumpfl Pixera TWO Media ServerAI | 3/5/2026 | 17/6/2026 | A vulnerability has been found in AV Stumpfl Pixera Two Media Server up to 25.1 R2. The affected element is an unknown function of the component Service Port 1338. Such manipulation leads to path traversal. The exploit has been disclosed to the public and may be used. Upgrading to version 25.2 R3 is sufficient to fix… | |
| Analizada | Media (4.3) | 0.30% | — | Plex Media Server | 2/1/2026 | 30/9/2026 | In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a shared_servers endpoint. | |
| Analizada | Media (4.3) | 0.30% | — | Plex Media Server | 2/1/2026 | 30/9/2026 | In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml. | |
| Analizada | Alta (7.1) | 0.28% | — | Plex Media Server | 2/1/2026 | 30/9/2026 | In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account. | |
| Analizada | Alta (7.1) | 0.25% | — | Plex Media Server | 2/1/2026 | 30/9/2026 | Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token. | |
| Analizada | Alta (8.7) | 0.73% | — | Eibiz I-media Server Digital Signage | 10/12/2025 | 17/6/2026 | EIBIZ i-Media Server Digital Signage 3.8.0 contains an unauthenticated configuration disclosure vulnerability that allows remote attackers to access sensitive configuration files via direct object reference. Attackers can retrieve the SiteConfig.properties file through an HTTP GET request, exposing administrative… | |
| Analizada | Crítica (9.3) | 0.80% | — | Eibiz I-media Server Digital Signage | 10/12/2025 | 17/6/2026 | Eibiz i-Media Server Digital Signage 3.8.0 contains an authentication bypass vulnerability that allows unauthenticated attackers to create admin users through AMF-encoded object manipulation. Attackers can send crafted serialized objects to the /messagebroker/amf endpoint to create administrative users without… | |
| Analizada | Alta (8.7) | 1.6% | — | Eibiz I-media Server Digital Signage | 10/12/2025 | 17/6/2026 | Eibiz i-Media Server Digital Signage 3.8.0 contains a directory traversal vulnerability that allows unauthenticated remote attackers to access files outside the server's root directory. Attackers can exploit the 'oldfile' GET parameter to view sensitive configuration files like web.xml and system files such as win.ini. | |
| Analizada | Crítica (9.3) | 1.1% | — | Eibiz I-media Server Digital Signage | 10/12/2025 | 17/6/2026 | Eibiz i-Media Server Digital Signage 3.8.0 contains an unauthenticated privilege escalation vulnerability in the updateUser object that allows attackers to modify user roles. Attackers can exploit the /messagebroker/amf endpoint to elevate privileges and take over user accounts by manipulating role settings without… | |
| Aplazada | Crítica (9.3) | 0.72% | — | Request Serious Play F3 Media ServerAI | 5/12/2025 | 17/6/2026 | ReQuest Serious Play F3 Media Server 7.0.3 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands as the web server user. Attackers can upload PHP executable files via the Quick File Uploader page, resulting in remote code execution on the server. | |
| Aplazada | Alta (8.7) | 0.37% | — | Request Serious Play F3 Media ServerAI | 5/12/2025 | 17/6/2026 | ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 allows unauthenticated attackers to disclose the webserver's Python debug log file containing system information, credentials, paths, processes and command arguments running on the device.… | |
| Aplazada | Alta (8.7) | 0.46% | — | Request Serious Play F3 Media ServerAI | 14/11/2025 | 17/6/2026 | ReQuest Serious Play F3 Media Server versions 7.0.3.4968 (Pro), 7.0.2.4954, 6.5.2.4954, 6.4.2.4681, 6.3.2.4203, and 2.0.1.823 contain a remote denial-of-service vulnerability. The device can be shut down or rebooted by an unauthenticated attacker through a single crafted HTTP GET request, allowing remote interruption… | |
| Aplazada | Alta (8.5) | 0.56% | — | Plex Media ServerAI | 21/8/2025 | 17/6/2026 | Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other servers accessible by that server owner). | |
| Aplazada | Crítica (9.3) | 4.4% | — | Serviio Media ServerAI | 10/7/2025 | 17/6/2026 | An unauthenticated command injection vulnerability exists in Serviio Media Server versions 1.4 through 1.8 on Windows, in the /rest/action API endpoint exposed by the console component (default port 23423). The checkStreamUrl method accepts a VIDEO parameter that is passed unsanitized to a call to cmd.exe, enabling… | |
| Analizada | Alta (7.5) | 0.38% | — | Sick Media Server | 12/6/2025 | 17/6/2026 | The Media Server’s authorization tokens have a poor quality of randomness. An attacker may be able to guess the token of an active user by computing plausible tokens. | |
| Analizada | Alta (7.5) | 0.30% | — | Sick Media Server | 12/6/2025 | 17/6/2026 | The application uses a weak password hash function, allowing an attacker to crack the weak password hash to gain access to an FTP user account. | |
| Analizada | Crítica (9.8) | 0.52% | — | Sick Media Server | 12/6/2025 | 17/6/2026 | The FTP server’s login mechanism does not restrict authentication attempts, allowing an attacker to brute-force user passwords and potentially compromising the FTP server. | |
| Analizada | Alta (7.5) | 0.32% | — | Sick Media Server | 12/6/2025 | 17/6/2026 | The server supports authentication methods in which credentials are sent in plaintext over unencrypted channels. If an attacker were to intercept traffic between a client and this server, the credentials would be exposed. | |
| Analizada | Media (6.1) | 0.31% | — | Sick Baggage AnalyticsSick Field AnalyticsSick Logistic Diagnostic AnalyticsSick Media Server+2 | 12/6/2025 | 17/6/2026 | The application fails to implement several security headers. These headers help increase the overall security level of the web application by e.g., preventing the application to be displayed in an iFrame (Clickjacking attacks) or not executing injected malicious JavaScript code (XSS attacks). | |
| Analizada | Media (6.1) | 0.33% | — | Sick Field AnalyticsSick Media Server | 12/6/2025 | 17/6/2026 | The web application is vulnerable to clickjacking attacks. The site can be embedded into another frame, allowing an attacker to trick a user into clicking on something different from what the user perceives. This could potentially reveal confidential information or allow others to take control of their computer while… |