Vulnerabilities

Summary — last 7 days

New vulnerabilities2,731▼ 12 vs. last week
Critical / high1,272▼ 242 vs. last week
New active exploitation (KEV)6▼ 1 vs. last week
Unscored (no CVSS)230▲ 212 vs. last week
–

10 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredHigh (7.1)0.23%—Dvs11 Random Posts MP3 Player SharebuttonAI3/15/20256/17/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dvs11 Random Posts, Mp3 Player + ShareButton random-posts-mp3-player-sharebutton allows Reflected XSS.This issue affects Random Posts, Mp3 Player + ShareButton: from n/a through <= 1.4.1.
ModifiedHigh (7.2)0.62%—Svnlabs Html5 MP3 Player With Folder Feedburner Playlist Free1/8/20246/17/2026
Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Folder Feedburner Playlist Free.This issue affects HTML5 MP3 Player with Folder Feedburner Playlist Free: from n/a through 2.8.0.
ModifiedHigh (8.8)0.62%—Svnlabs Html5 MP3 Player With Playlist Free1/8/20246/17/2026
Deserialization of Untrusted Data vulnerability in SVNLabs Softwares HTML5 MP3 Player with Playlist Free.This issue affects HTML5 MP3 Player with Playlist Free: from n/a through 3.0.0.
ModifiedMedium (5.4)0.74%—Wpaudio MP3 Player Project Wpaudio MP3 Player3/6/20236/17/2026
The WPaudio MP3 Player WordPress plugin through 4.0.2 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks.
ModifiedMedium (5)2.6%—Svnlabs Html5 MP3 Player With Playlist Free12/2/20146/17/2026
The HTML5 MP3 Player with Playlist Free plugin before 2.7 for WordPress allows remote attackers to obtain the installation path via a request to html5plus/playlist.php.
ModifiedLow (2.1)0.93%—Jordan DE Laune MP3 Player6/25/20136/16/2026
Cross-site scripting (XSS) vulnerability in the MP3 Player module for Drupal 6.x allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the file name of a MP3 file.
ModifiedMedium (4.3)1.9%💥 ExploitTomatosoft Free MP3 Player12/30/20116/16/2026
TomatoSoft Free Mp3 Player 1.0 allows remote attackers to cause a denial of service (application crash) via a long string in an MP3 file, possibly a buffer overflow.
ModifiedHigh (7.5)1.1%—Steve Grundell Frontend MP3 Player6/17/20096/16/2026
SQL injection vulnerability in the Frontend MP3 Player (fe_mp3player) 0.2.3 and earlier extension for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModifiedHigh (9.3)5.8%💥 ExploitSorinara Soritong MP3 Player5/15/20096/16/2026
Stack-based buffer overflow in Sorinara Soritong MP3 Player 1.0 allows remote attackers to execute arbitrary code via a crafted .m3u file.
ModifiedMedium (4.3)0.98%—Avnex AV MP3 Player9/14/20076/16/2026
Avnex AV MP3 Player allows user-assisted remote attackers to cause a denial of service (application crash) via a malformed .au file that triggers a divide-by-zero error.
Orbitaley — Vulnerabilities