Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3062▲ 584 respecto a la semana anterior
Críticas / altas1459▲ 293 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.29%—Gerritvanaaken Podlove WEB PlayerAI5/3/202617/6/2026
Deserialization of Untrusted Data vulnerability in gerritvanaaken Podlove Web Player podlove-web-player allows Object Injection.This issue affects Podlove Web Player: from n/a through <= 5.9.1.
AplazadaMedia (5.3)0.36%—Podlove WEB PlayerAI8/6/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Podlove Podlove Web Player.This issue affects Podlove Web Player: from n/a through 5.7.3.
AplazadaMedia (6.5)0.33%—Podlove WEB PlayerAI27/3/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podlove Podlove Web Player allows Stored XSS.This issue affects Podlove Web Player: from n/a through 5.7.1.
ModificadaMedia (6.5)0.88%—Unity WEB Player29/7/201917/6/2026
The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials
ModificadaCrítica (9.8)1.7%—Tibco Spotfire AnalystTibco Spotfire ClientTibco Spotfire ConnectorsTibco Spotfire Deployment KIT+324/7/201817/6/2026
Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in…
ModificadaMedia (5.4)0.61%—Tibco Silver Fabric Enabler FOR Spotfire WEB PlayerTibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Automation Services+624/7/201817/6/2026
Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the…
ModificadaAlta (7.5)3.5%—Tibco Spotfire Deployment KITTibco Spotfire ProfessionalTibco Spotfire WEB PlayerTibco Spotfire Desktop+521/7/201517/6/2026
Multiple unspecified vulnerabilities in TIBCO Spotfire Client and Spotfire Web Player Client in Spotfire Analyst before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Analytics Platform for AWS 6.5 and 7.0.x before 7.0.1; Spotfire Automation Services before 5.5.2, 6.0.x before 6.0.3,…
ModificadaAlta (7.5)3.0%—Divx DirectshowdemuxfilterDivx PlayerDivx WEB Player13/1/201517/6/2026
Multiple integer signedness errors in DirectShowDemuxFilter, as used in Divx Web Player, Divx Player, and other Divx plugins, allow remote attackers to execute arbitrary code via a (1) negative or (2) large value in a Stream Format (STRF) chunk in an AVI file, which triggers a heap-based buffer overflow.
ModificadaMedia (4)0.94%—Tibco Silver Fabric EnablerTibco Spotfire Deployment KITTibco Spotfire WEB Player21/11/201417/6/2026
Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spotfire Web Player before 1.6.1 allows remote authenticated users to obtain sensitive information via unspecified vectors.
ModificadaAlta (7.5)3.1%—Tibco WEB PlayerTibco Automation ServicesTibco Spotfire ServerTibco Spotfire Professional+310/4/201417/6/2026
Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in TIBCO Spotfire Server 3.3.x before 3.3.4, 4.5.x before 4.5.1, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.2; Spotfire Professional 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before…
ModificadaMedia (6.4)1.3%—Tibco Spotfire WEB Player15/3/201316/6/2026
The Engine in TIBCO Spotfire Web Player 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 does not properly implement access control, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors.
ModificadaMedia (4.3)1.1%—Tibco Spotfire WEB Player15/3/201316/6/2026
Cross-site scripting (XSS) vulnerability in the Engine in TIBCO Spotfire Web Player 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)1.6%—Tibco Spotfire Analytics ServerTibco Spotfire ServerTibco WEB Player Automation ServicesTibco Spotfire Professional13/3/201216/6/2026
TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analytics Client Application in Spotfire Analytics Server before 10.1.2; Server before 3.3.3; and Web Player, Automation Services, and Professional before 4.0.2 allow remote attackers to obtain sensitive information via a…
ModificadaMedia (5.8)1.3%—Neoaxis WEB Player20/1/201216/6/2026
Directory traversal vulnerability in the web player in NeoAxis NeoAxis web player 1.4 and earlier allows user-assisted remote attackers to write arbitrary files via a .. (dot dot) in a filename in the neoaxis_web_application_win32.zip ZIP archive.
ModificadaAlta (9.3)5.7%—Divx WEB Player16/4/200916/6/2026
Integer signedness error in DivX Web Player 1.4.2.7, and possibly earlier versions, allows remote attackers to execute arbitrary code via a DivX file containing a crafted Stream Format (STRF) chunk, which triggers a heap-based buffer overflow.
ModificadaAlta (7.8)3.1%—Divx WEB Player7/3/200716/6/2026
A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via large values to DivxWP.Resize, related to resizing images.
ModificadaMedia (6.8)1.1%—Sourceforge Webmplayer2/3/200716/6/2026
Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php.
ModificadaMedia (6.8)2.2%—Webmplayer2/3/200716/6/2026
index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous.
ModificadaAlta (7.5)5.5%—Virtools WEB Player4/10/200516/6/2026
Buffer overflow in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to execute arbitrary code via a long filename.
ModificadaMedia (5)2.1%—Virtools WEB Player4/10/200516/6/2026
Directory traversal vulnerability in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename.