Vulnerabilities
Summary — last 7 days
New vulnerabilities2,731▼ 12 vs. last week
Critical / high1,272▼ 242 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
10 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | High (7.1) | 0.23% | — | Dvs11 Random Posts MP3 Player SharebuttonAI | 3/15/2025 | 6/17/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dvs11 Random Posts, Mp3 Player + ShareButton random-posts-mp3-player-sharebutton allows Reflected XSS.This issue affects Random Posts, Mp3 Player + ShareButton: from n/a through <= 1.4.1. | |
| Modified | High (7.2) | 0.62% | — | Svnlabs Html5 MP3 Player With Folder Feedburner Playlist Free | 1/8/2024 | 6/17/2026 | Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist Free: from n/a through 2.8.0. | |
| Modified | High (8.8) | 0.62% | — | Svnlabs Html5 MP3 Player With Playlist Free | 1/8/2024 | 6/17/2026 | Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through 3.0.0. | |
| Modified | Medium (5.4) | 0.74% | — | Wpaudio MP3 Player Project Wpaudio MP3 Player | 3/6/2023 | 6/17/2026 | The WPaudio MP3 Player WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. | |
| Modified | Medium (5) | 2.6% | — | Svnlabs Html5 MP3 Player With Playlist Free | 12/2/2014 | 6/17/2026 | The HTML5 MP3 Player with Playlist Free plugin before 2.7 for WordPress allows remote attackers to obtain the installation path via a request to html5plus/playlist.php. | |
| Modified | Low (2.1) | 0.93% | — | Jordan DE Laune MP3 Player | 6/25/2013 | 6/16/2026 | Cross-site scripting (XSS) vulnerability in the MP3 Player module for Drupal 6.x allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the file name of a MP3 file. | |
| Modified | Medium (4.3) | 1.9% | 💥 Exploit | Tomatosoft Free MP3 Player | 12/30/2011 | 6/16/2026 | TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long string in an MP3 file, possibly a buffer overflow. | |
| Modified | High (7.5) | 1.1% | — | Steve Grundell Frontend MP3 Player | 6/17/2009 | 6/16/2026 | SQL injection vulnerability in the Frontend MP3 Player (fe_mp3player) 0.2.3 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modified | High (9.3) | 5.8% | 💥 Exploit | Sorinara Soritong MP3 Player | 5/15/2009 | 6/16/2026 | Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a crafted .m3u file. | |
| Modified | Medium (4.3) | 0.98% | — | Avnex AV MP3 Player | 9/14/2007 | 6/16/2026 | Avnex AV MP3 Player allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error. |