Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
134 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.5) | 0.17% | — | Videolan VLC Media PlayerAI | 29/9/2026 | 30/9/2026 | VLC media player before 3.0.24 contains a path traversal vulnerability in the skins2 ThemeLoader that fails to validate member names in .vlt skin archives. Attackers can craft malicious skin files with path traversal sequences to write arbitrary files with VLC user privileges, enabling code execution through Lua… | |
| Aplazada | Media (5.3) | 0.24% | — | Videolan VLC Media PlayerAI | 9/9/2026 | 14/9/2026 | Certain VLC media player builds in versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing media from an attacker-controlled network source. Exploitation requires user interaction and may disclose a limited, layout-dependent amount of VLC process memory. Exposure depends on build… | |
| Aplazada | Alta (7.3) | 0.12% | — | Videolan VLC Media PlayerAI | 9/9/2026 | 18/9/2026 | VLC media player versions 3.0.0 through 3.0.23 contain a memory-safety vulnerability reachable when processing crafted media. Exploitation requires user interaction and may result in application termination or code execution with the privileges of the VLC process. | |
| Aplazada | Media (6.3) | 0.51% | — | Videolan VLC FOR AndroidAI | 26/2/2026 | 14/7/2026 | VideoLAN VLC for Android prior to version 3.7.0 contains an authentication bypass in the Remote Access Server feature due to missing or insufficient rate limiting on one-time password (OTP) verification. The Remote Access Server uses a 4-digit OTP and does not enforce effective throttling or lockout within the OTP… | |
| Aplazada | Baja (2.3) | 0.41% | — | Videolan VLC FOR AndroidAI | 26/2/2026 | 14/7/2026 | VideoLAN VLC for Android prior to version 3.7.0 contains a path traversal vulnerability in the Remote Access Server routing for the authenticated endpoint GET /download. The file query parameter is concatenated into a filesystem path under the configured download directory without canonicalization or directory… | |
| Aplazada | Media (4.8) | 0.41% | — | Videolan VLC Media PlayerAI | 16/1/2026 | 17/6/2026 | mmstu.c in VideoLAN VLC media player before 3.0.22 allows an out-of-bounds read and denial of service via a crafted 0x01 response from an MMS server. | |
| Aplazada | Alta (8) | 0.61% | — | Videolan VLC Media PlayerAI | 25/9/2024 | 17/6/2026 | VLC media player 3.0.20 and earlier is vulnerable to denial of service through an integer overflow which could be triggered with a maliciously crafted mms stream (heap based overflow). If successful, a malicious third party could trigger either a crash of VLC or an arbitrary code execution with the target user's… | |
| Modificada | Alta (8.8) | 1.8% | — | Videolan Dav1dApple SafariApple IpadosApple Iphone OS+3 | 19/2/2024 | 17/6/2026 | An integer overflow in dav1d AV1 decoder that can occur when decoding videos with large frame size. This can lead to memory corruption within the AV1 decoder. We recommend upgrading past version 1.4.0 of dav1d. | |
| Modificada | Alta (7.8) | 0.28% | — | Videolan VLC Media Player | 22/11/2023 | 17/6/2026 | A binary hijacking vulnerability exists within the VideoLAN VLC media player before 3.0.19 on Windows. The uninstaller attempts to execute code with elevated privileges out of a standard user writable location. Standard users may use this to gain arbitrary code execution as SYSTEM. | |
| Modificada | Alta (7.5) | 0.91% | — | Videolan VLC Media Player | 7/11/2023 | 17/6/2026 | Videolan VLC prior to version 3.0.20 contains an Integer underflow that leads to an incorrect packet length. | |
| Modificada | Crítica (9.8) | 1.1% | — | Videolan VLC Media Player | 7/11/2023 | 17/6/2026 | Videolan VLC prior to version 3.0.20 contains an incorrect offset read that leads to a Heap-Based Buffer Overflow in function GetPacket() and results in a memory corruption. | |
| Modificada | Media (5.9) | 0.74% | — | Videolan Dav1dFedoraproject Fedora | 10/5/2023 | 17/6/2026 | VideoLAN dav1d before 1.2.0 has a thread_task.c race condition that can lead to an application crash, related to dav1d_decode_frame_exit. | |
| Modificada | Alta (7.8) | 0.68% | — | Videolan VLC Media PlayerDebian Linux | 6/12/2022 | 17/6/2026 | An integer overflow in the VNC module in VideoLAN VLC Media Player through 3.0.17.4 allows attackers, by tricking a user into opening a crafted playlist or connecting to a rogue VNC server, to crash VLC or execute code under some conditions. | |
| Modificada | Alta (7.5) | 1.8% | — | Videolan VLC Media Player | 26/7/2021 | 17/6/2026 | A NULL-pointer dereference in "Open" in avi.c of VideoLAN VLC Media Player 3.0.11 can a denial of service (DOS) in the application. | |
| Modificada | Alta (7.1) | 0.74% | — | Videolan VLC Media Player | 26/7/2021 | 17/6/2026 | A buffer overflow vulnerability in the vlc_input_attachment_New component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. | |
| Modificada | Alta (7.1) | 0.74% | — | Videolan VLC Media Player | 26/7/2021 | 17/6/2026 | A buffer overflow vulnerability in the AVI_ExtractSubtitle component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. | |
| Modificada | Alta (7.1) | 1.5% | — | Videolan VLC Media Player | 26/7/2021 | 17/6/2026 | A buffer overflow vulnerability in the __Parse_indx component of VideoLAN VLC Media Player 3.0.11 allows attackers to cause an out-of-bounds read via a crafted .avi file. | |
| Modificada | Alta (7.8) | 1.5% | — | Videolan VLC Media PlayerDebian Linux | 8/1/2021 | 9/7/2026 | A vulnerability in EbmlTypeDispatcher::send in VideoLAN VLC media player 3.0.11 allows attackers to trigger a heap-based buffer overflow via a crafted .mkv file. | |
| Modificada | Alta (7.8) | 2.4% | — | Videolan VLC Media PlayerDebian Linux | 8/6/2020 | 17/6/2026 | A heap-based buffer overflow in the hxxx_AnnexB_to_xVC function in modules/packetizer/hxxx_nal.c in VideoLAN VLC media player before 3.0.11 for macOS/iOS allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via a crafted H.264 Annex-B video (.avi for example) file. | |
| Modificada | Alta (7.8) | 2.0% | — | Videolan VLC Media Player | 15/5/2020 | 17/6/2026 | An off-by-one error in the DecodeBlock function in codec/sdl_image.c in VideoLAN VLC media player before 3.0.9 allows remote attackers to cause a denial of service (memory corruption) via a crafted image file. NOTE: this may be related to the SDL_Image product. | |
| Modificada | Media (5.3) | 1.1% | — | Videolan VLC Media Player | 6/2/2020 | 16/6/2026 | The web interface in VideoLAN VLC media player before 2.0.7 has no access control which allows remote attackers to view directory listings via the 'dir' command or issue other commands without authenticating. | |
| Modificada | Media (6.1) | 1.6% | — | Videolan VLC Media PlayerOpensuse | 31/1/2020 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the HTTP Interface in VideoLAN VLC Media Player before 2.0.7 allow remote attackers to inject arbitrary web script or HTML via the (1) command parameter to requests/vlm_cmd.xml, (2) dir parameter to requests/browse.xml, or (3) URI in a request, which is returned… | |
| Modificada | Alta (7.8) | 1.5% | — | Videolan VLC Media Player | 24/1/2020 | 17/6/2026 | The rtp_packetize_xiph_config function in modules/stream_out/rtpfmt.c in VideoLAN VLC media player before 2.1.6 uses a stack-allocation approach with a size determined by arbitrary input data, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a… | |
| Modificada | Alta (7.8) | 2.4% | — | Videolan VLC Media Player | 24/1/2020 | 17/6/2026 | Integer overflow in the Encode function in modules/codec/schroedinger.c in VideoLAN VLC media player before 2.1.6 and 2.2.x before 2.2.1 allows remote attackers to conduct buffer overflow attacks and execute arbitrary code via a crafted length value. | |
| Modificada | Alta (7.8) | 2.2% | — | Videolan VLC Media Player | 24/1/2020 | 17/6/2026 | The MP4_ReadBox_String function in modules/demux/mp4/libmp4.c in VideoLAN VLC media player before 2.1.6 allows remote attackers to trigger an unintended zero-size malloc and conduct buffer overflow attacks, and consequently execute arbitrary code, via a box size of 7. |