Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2857▼ 164 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
282 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.5) | 0.16% | — | Sonaar MP3 Audio Player FOR Music Radio PodcastAI | 5/10/2026 | 5/10/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sonaar MP3 Audio Player for Music, Radio & Podcast by Sonaar mp3-music-player-by-sonaar allows Stored XSS.This issue affects MP3 Audio Player for Music, Radio & Podcast by Sonaar: from n/a through 5.14.2. | |
| Aplazada | Alta (7.2) | 0.37% | — | Music Player FOR WoocommerceAI | 30/9/2026 | 30/9/2026 | Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions. | |
| Aplazada | Baja (1.9) | 0.17% | — | Flb-music-playerAI | 28/9/2026 | 28/9/2026 | A vulnerability has been found in FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1. This impacts the function path.join of the file /src/main/core/createParsedTrack.ts. The manipulation leads to path traversal. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The… | |
| Aplazada | Alta (8.6) | 0.45% | — | Codepeople Music StoreAI | 5/9/2026 | 8/9/2026 | The Music Store WordPress plugin before 1.4.5 does not sanitise and escape user input before using it in a SQL statement, leading to a SQL injection exploitable by unauthenticated users. | |
| Aplazada | Alta (7.1) | 0.25% | — | Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI | 2/9/2026 | 2/9/2026 | Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Music Player FOR WoocommerceAI | 27/8/2026 | 28/8/2026 | Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions. | |
| Aplazada | Alta (7.5) | 0.54% | — | Swingmx Swing MusicAI | 11/8/2026 | 28/8/2026 | A missing authentication vulnerability in Swing Music 3.0.0 allows unauthenticated remote attackers to create arbitrary user accounts via the POST /auth/profile/create endpoint. The endpoint is allowlisted from JWT verification, permitting unauthenticated account creation. An attacker can register an account and use… | |
| Aplazada | Media (5.3) | 0.29% | — | Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions. | |
| Aplazada | Baja (2.1) | 0.47% | — | Code-projects Online Music SiteAI | 29/6/2026 | 29/6/2026 | A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Frontend/Feedback.php of the component POST Request Handler. The manipulation of the argument fname/femail/faddress/fmessage results in cross site scripting. The attack may be launched remotely. The… | |
| Aplazada | Media (5.5) | 0.29% | — | Code-projects Online Music SiteAI | 8/6/2026 | 23/7/2026 | A vulnerability was determined in code-projects Online Music Site 1.0. This issue affects some unknown processing of the file /Frontend/Search.php. This manipulation of the argument Category causes sql injection. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be… | |
| Aplazada | Media (5.5) | 0.27% | — | Code-projects Online Music SiteAI | 8/6/2026 | 23/7/2026 | A vulnerability was found in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminDeleteAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit has been made public and could be used. | |
| Aplazada | Media (5.1) | 0.18% | — | Sonaar MusicAI | 8/6/2026 | 23/7/2026 | WordPress Sonaar Music Plugin 4.7 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the comment functionality. Attackers can submit JavaScript payloads in the comment parameter to wp-comments-post.php which are stored and executed in the… | |
| Aplazada | Media (5.1) | 0.26% | — | Lyrion Music ServerAI | 5/6/2026 | 17/6/2026 | Lyrion Music Server 9.2.0 contains a reflected cross-site scripting vulnerability in advanced search parameters that fail to properly sanitize user input before displaying it in search forms. Attackers can inject malicious scripts through unfiltered search parameters to execute arbitrary JavaScript in users' browsers… | |
| Aplazada | Alta (8.7) | 0.93% | — | Lyrion Music ServerAI | 5/6/2026 | 17/6/2026 | Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting directory traversal in the web server context. Attackers can manipulate file path parameters to access sensitive files outside the intended directory structure. | |
| Aplazada | Media (6.9) | 0.50% | — | Lyrion Music ServerAI | 5/6/2026 | 17/6/2026 | Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no restriction to the configured media… | |
| Aplazada | Media (5.1) | 0.32% | — | Lyrion Music ServerAI | 5/6/2026 | 17/6/2026 | Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through media file metadata tags like GENRE, ARTIST, and ALBUM. Attackers can craft files with XSS payloads in metadata tags that execute in the web interface when users view track… | |
| Aplazada | Media (5.1) | 0.31% | — | Lyrion Music ServerAI | 5/6/2026 | 17/6/2026 | Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer that allows attackers to inject malicious scripts by exploiting unescaped template variables. Attackers can inject XSS payloads through search, lines, and path query parameters or by crafting values that… | |
| Aplazada | Media (5.1) | 0.54% | — | Lyrion Music ServerAI | 5/6/2026 | 17/6/2026 | Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log endpoint that allows attackers to inject arbitrary HTML and JavaScript code through the search parameter. Attackers can craft malicious URLs with JavaScript payloads in the search parameter to execute… | |
| Aplazada | Media (5.3) | 0.21% | — | ZUZ MusicAI | 4/6/2026 | 22/7/2026 | Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submitting crafted contact form data. Attackers can inject script code through the name, subject, and message parameters in POST requests to /gmusic/zuzconsole/___contact,… | |
| Aplazada | Media (5.1) | 0.30% | — | Lightweight Music ServerAI | 1/6/2026 | 22/7/2026 | Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted media file into the victim's library,… | |
| Aplazada | Media (5.5) | 0.27% | — | Code-projects Online Music SiteAI | 31/5/2026 | 22/7/2026 | A vulnerability was detected in code-projects Online Music Site 1.0. This vulnerability affects unknown code of the file /Administrator/PHP/AdminEditAlbum.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used. | |
| Aplazada | Baja (2) | 0.21% | — | Code-projects Online Music SiteAI | 31/5/2026 | 22/7/2026 | A vulnerability has been found in code-projects Online Music Site 1.0. This affects an unknown part of the file /Administrator/PHP/AdminUpdateAlbum.php. Such manipulation of the argument ID leads to sql injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. | |
| Aplazada | Alta (8.7) | 0.51% | — | XiaomusicAI | 29/5/2026 | 21/7/2026 | xiaomusic v0.5.7 contains an unauthenticated path traversal vulnerability in the GET /music/{file_path:path} endpoint that allows unauthenticated attackers to read arbitrary files outside the intended music directory by exploiting an incomplete path prefix check. Attackers can request files from sibling directories… | |
| Aplazada | Media (6.9) | 0.44% | — | Musicpd Music Player DaemonAI | 28/5/2026 | 14/7/2026 | Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF bytes in URI fields by supplying a malicious XSPF playlist with XML numeric character references. Attackers can inject… | |
| Aplazada | Media (6.9) | 0.48% | — | LibcurlAIMusicpd Music Player DaemonAI | 28/5/2026 | 14/7/2026 | Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION is set without CURLOPT_REDIR_PROTOCOLS_STR, allowing unauthenticated attackers to bypass the http/https scheme restriction by causing a malicious HTTP server to redirect… |