Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
2394 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.40% | — | Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.40% | — | Geovision GeowebplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.39% | — | Geovision GeowebplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeowebplayerAIGeovision Gv-vmsAIGeovision Gv-cloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeowebplayerAIGeovision Gv-vmsAIGeovision Gv-cloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.45% | — | Geovision VMSAIGeovision GV CloudAIGeovision GeowebplayerAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision SoftwareAIGeovision Gv-vmsAIGeovision Gv-cloudAIGeovision GeowebplayerAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeoplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeowebplayerAIGeovision Gv-vmsAIGeovision Gv-cloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.3) | 0.37% | — | Geovision GeowebplayerAIGeovision Gv-vmsAIGeovision Gv-cloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Alta (8.8) | 0.38% | — | Geovision GeowebplayerAIGeovision GV VMSAIGeovision GV CloudAI | 2/7/2026 | 2/7/2026 | GeoWebPlayer (also called "Web Plugin" in the GV-VMS documentation and "WS Player" for VMS-Cloud) is an addon that can be installed with various GeoVision software (GV-VMS, GV-Cloud, ...). It creates a websocket server that expands the capabilities of the various web-interfaces provided by the GeoVision software and… | |
| Aplazada | Media (6.4) | 0.35% | — | Foliovision FV Flowplayer Video PlayerAI | 1/7/2026 | 1/7/2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'video_player' shortcode 'align' attribute in all versions up to, and including, 7.5.51.7212 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Aplazada | Media (6.5) | 0.22% | — | Wphowto Flowplayer Video PlayerAI | 15/6/2026 | 17/6/2026 | Subscriber Cross Site Scripting (XSS) in FV Flowplayer Video Player < 7.5.51.7212 versions. | |
| Aplazada | Media (6.4) | 0.42% | — | Prestoplayer Presto PlayerAI | 12/6/2026 | 28/8/2026 | The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays() function, which copies the link_url… | |
| Aplazada | Alta (7.2) | 0.42% | — | Foliovision FV Flowplayer Video PlayerAI | 9/6/2026 | 23/7/2026 | The FV Flowplayer Video Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the comment text in all versions up to, and including, 7.5.49.7212 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Aplazada | Alta (8.6) | 0.15% | — | AllplayerAI | 4/6/2026 | 22/7/2026 | AllPlayer 7.4 contains a local buffer overflow vulnerability in URL handling that allows attackers to overwrite structured exception handling pointers by supplying an excessively long URL string. Attackers can craft a malicious URL, paste it into the Open URL dialog, and trigger SEH-based code execution to run… | |
| Aplazada | Media (6.9) | 0.44% | — | Musicpd Music Player DaemonAI | 28/5/2026 | 14/7/2026 | Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF bytes in URI fields by supplying a malicious XSPF playlist with XML numeric character references. Attackers can inject… | |
| Aplazada | Media (6.9) | 0.48% | — | LibcurlAIMusicpd Music Player DaemonAI | 28/5/2026 | 14/7/2026 | Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION is set without CURLOPT_REDIR_PROTOCOLS_STR, allowing unauthenticated attackers to bypass the http/https scheme restriction by causing a malicious HTTP server to redirect… | |
| Aplazada | Alta (8.7) | 0.63% | — | Musicpd Music Player DaemonAI | 28/5/2026 | 14/7/2026 | Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow and LocalStorage::MapUTF8 within the local storage plugin, where the on-disk path is constructed by joining the storage root with a user-supplied URI as plain strings without canonicalization,… | |
| Aplazada | Alta (8.8) | 0.68% | — | Musicpd Music Player DaemonAI | 28/5/2026 | 14/7/2026 | Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt stack memory by triggering an off-by-one write in the PCM decoder plugin. Attackers can issue two MPD commands referencing… | |
| Aplazada | Media (4.3) | 0.27% | — | Brainstormforce Presto PlayerAI | 19/5/2026 | 17/6/2026 | Missing Authorization vulnerability in Brainstorm Force Presto Player allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Presto Player: from n/a through 4.1.3. | |
| Aplazada | Alta (8.8) | 0.27% | — | Joomla COM HdwplayerAI | 13/5/2026 | 17/6/2026 | Joomla com_hdwplayer 4.2 contains an SQL injection vulnerability in the search.php file that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hdwplayersearch parameter. Attackers can submit POST requests with crafted SQL payloads in the hdwplayersearch parameter… | |
| Analizada | Alta (8.6) | 0.21% | — | Socusoft Html5 Video Player | 12/4/2026 | 17/6/2026 | HTML5 Video Player 1.2.5 contains a local buffer overflow vulnerability that allows attackers to execute arbitrary code by supplying an oversized key code string. Attackers can craft a malicious payload exceeding 997 bytes and paste it into the KEY CODE field in the Help Register dialog to trigger code execution and… |