Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3222▲ 222 respecto a la semana anterior
Críticas / altas1465▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)511▼ 31 respecto a la semana anterior
–

2391 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.54%—Music Player FOR WoocommerceAI30/9/202630/9/2026
Shop manager PHP Object Injection in Music Player for WooCommerce <= 1.9.1 versions.
AplazadaAlta (7.1)0.25%—Longtailvideo JW PlayerAI30/9/202630/9/2026
Unauthenticated Cross Site Scripting (XSS) in JW Player for WordPress <= 2.3.11 versions.
AplazadaMedia (6.8)0.24%—Audio Player BlockAI30/9/202630/9/2026
The Audio Player Block WordPress plugin before 1.6.3 does not validate the scheme of a user-supplied URL before using it as a link target, allowing users with the Contributor role and above to store malicious JavaScript that executes in the session of any user who later triggers the link (such as an administrator or…
Pendiente de análisisAlta (8.5)0.17%—Videolan VLC Media PlayerAI29/9/202630/9/2026
VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua…
AplazadaBaja (1.9)0.17%—Flb-music-playerAI28/9/202628/9/2026
A vulnerability has been found in FLB-Music FLB-Music-Player 1.1.8/1.1.9/1.2.0/1.2.1. This impacts the function path.join of the file /src/main/core/createParsedTrack.ts. The manipulation leads to path traversal. The attack must be carried out locally. The exploit has been disclosed to the public and may be used. The…
AplazadaAlta (8.7)0.56%—Paella PlayerAIOpencastAI17/9/202624/9/2026
Paella Player is a set of libraries to create a multi stream video player. Prior to Paella Player 2.12.11 (as used in Opencast prior to 19.7 and 20.2), there is a potential XSS attack though closed captions cue text. This vulnerability is fixed in 2.12.11.
AplazadaCrítica (9.8)0.69%—Actions Semiconductor CO LTD Tool - Media Player UtilitiesAI9/9/202610/9/2026
An issue in Actions Semiconductor Co. Ltd Tool- Media Player Utilities v.4.46 allows a physically proximate attacker execute arbitrary code via the Production.dll and RdiskUpgrade.exe components
AplazadaMedia (5.3)0.24%—Videolan VLC Media PlayerAI9/9/202614/9/2026
Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build…
AplazadaAlta (7.3)0.12%—Videolan VLC Media PlayerAI9/9/202618/9/2026
VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process.
AplazadaMedia (6.8)0.39%—Video Player FOR YoutubeAI5/9/20268/9/2026
The Video Player for YouTube WordPress plugin before 2.1.0 does not properly sanitise and escape user-supplied input before using it in a SQL statement, allowing users with the Contributor role and above to perform SQL injection attacks and read arbitrary data from the database.
AplazadaAlta (7.1)0.25%—Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI2/9/20262/9/2026
Unauthenticated Cross Site Scripting (XSS) in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.13.1 versions.
AplazadaMedia (6.4)0.19%—Easy Waveform PlayerAI2/9/20263/9/2026
The Easy Waveform Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the shortcode_easywaveformplayer() function in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…
AplazadaMedia (4.9)0.33%—Fluent Player PROAI27/8/202628/8/2026
Editor Broken Access Control in FluentPlayer Pro <= 1.3.2 versions.
AplazadaAlta (7.1)0.25%—Music Player FOR WoocommerceAI27/8/202628/8/2026
Unauthenticated Cross Site Scripting (XSS) in Music Player for WooCommerce <= 1.8.9 versions.
AplazadaAlta (7.1)0.25%—CP Media PlayerAI27/8/202628/8/2026
Unauthenticated Cross Site Scripting (XSS) in CP Media Player <= 1.3.0 versions.
AplazadaCrítica (9.1)0.44%—Zyplayer-docAI26/8/202631/8/2026
Zyplayer-Doc <=1.0.0 is vulnerable to Server-Side Request Forgery (SSRF) via WikiPageWebService.download().
AplazadaMedia (5.3)0.32%—Podcast PlayerAI10/8/202626/8/2026
The Podcast Player WordPress plugin before 8.3.1 does not validate the destination of a server-side request built from user-supplied input, allowing unauthenticated attackers to make the server issue requests to arbitrary hosts and read back responses that parse as RSS/XML.
AplazadaMedia (5.3)0.29%—Sonaar MP3 Audio Player FOR Music Radio AND PodcastAI23/7/202623/7/2026
Unauthenticated Broken Access Control in MP3 Audio Player for Music, Radio & Podcast by Sonaar <= 5.12 versions.
AplazadaMedia (5.3)0.29%—YT PlayerAI23/7/202623/9/2026
Missing Authorization vulnerability in bPlugins YT Player yt-player allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects YT Player: from n/a through 2.1.2.
AplazadaAlta (8.3)0.40%—Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI2/7/20262/7/2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and…
AplazadaAlta (8.3)0.40%—Geovision GeowebplayerAIGeovision Gv-vmsAIGeovision Gv-cloudAI2/7/20262/7/2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and…
AplazadaAlta (8.3)0.40%—Geovision GeowebplayerAIGeovision GV VMSAIGeovision GV CloudAI2/7/20262/7/2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and…
AplazadaAlta (8.3)0.40%—Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI2/7/20262/7/2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and…
AplazadaAlta (8.3)0.40%—Geovision GeowebplayerAIGeovision GV VMSAIGeovision GV CloudAI2/7/20262/7/2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and…
AplazadaAlta (8.3)0.39%—Geovision GeowebplayerAIGeovision GV VMSAIGeovision GV CloudAI2/7/20262/7/2026
GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and…