Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.29% | — | Gerritvanaaken Podlove WEB PlayerAI | 5/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in gerritvanaaken Podlove Web Player podlove-web-player allows Object Injection.This issue affects Podlove Web Player: from n/a through <= 5.9.1. | |
| Aplazada | Media (5.3) | 0.36% | — | Podlove WEB PlayerAI | 8/6/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Podlove Podlove Web Player.This issue affects Podlove Web Player: from n/a through 5.7.3. | |
| Aplazada | Media (6.5) | 0.33% | — | Podlove WEB PlayerAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Podlove Podlove Web Player allows Stored XSS.This issue affects Podlove Web Player: from n/a through 5.7.1. | |
| Modificada | Media (6.5) | 0.88% | — | Unity WEB Player | 29/7/2019 | 17/6/2026 | The Unity Web Player plugin before 4.6.6f2 and 5.x before 5.0.3f2 allows attackers to read messages or access online services via a victim's credentials | |
| Modificada | Crítica (9.8) | 1.7% | — | Tibco Spotfire AnalystTibco Spotfire ClientTibco Spotfire ConnectorsTibco Spotfire Deployment KIT+3 | 24/7/2018 | 17/6/2026 | Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in… | |
| Modificada | Media (5.4) | 0.61% | — | Tibco Silver Fabric Enabler FOR Spotfire WEB PlayerTibco Spotfire AnalystTibco Spotfire Analytics Platform FOR AWSTibco Spotfire Automation Services+6 | 24/7/2018 | 17/6/2026 | Multiple TIBCO Products are prone to multiple unspecified cross-site scripting vulnerabilities because it fails to properly sanitize user-supplied input. An attacker may leverage these issues to execute arbitrary script code in the browser of an unsuspecting user in the context of the affected site. This can allow the… | |
| Modificada | Alta (7.5) | 3.5% | — | Tibco Spotfire Deployment KITTibco Spotfire ProfessionalTibco Spotfire WEB PlayerTibco Spotfire Desktop+5 | 21/7/2015 | 17/6/2026 | Multiple unspecified vulnerabilities in TIBCO Spotfire Client and Spotfire Web Player Client in Spotfire Analyst before 5.5.2, 6.0.x before 6.0.3, 6.5.x before 6.5.3, and 7.0.x before 7.0.1; Spotfire Analytics Platform for AWS 6.5 and 7.0.x before 7.0.1; Spotfire Automation Services before 5.5.2, 6.0.x before 6.0.3,… | |
| Modificada | Alta (7.5) | 3.0% | — | Divx DirectshowdemuxfilterDivx PlayerDivx WEB Player | 13/1/2015 | 17/6/2026 | Multiple integer signedness errors in DirectShowDemuxFilter, as used in Divx Web Player, Divx Player, and other Divx plugins, allow remote attackers to execute arbitrary code via a (1) negative or (2) large value in a Stream Format (STRF) chunk in an AVI file, which triggers a heap-based buffer overflow. | |
| Modificada | Media (4) | 0.94% | — | Tibco Silver Fabric EnablerTibco Spotfire Deployment KITTibco Spotfire WEB Player | 21/11/2014 | 17/6/2026 | Spotfire Web Player Engine in TIBCO Spotfire Web Player 6.0.x before 6.0.2 and 6.5.x before 6.5.2, Spotfire Deployment Kit 6.0.x before 6.0.2 and 6.5.x before 6.5.2, and Silver Fabric Enabler for Spotfire Web Player before 1.6.1 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.1% | — | Tibco WEB PlayerTibco Automation ServicesTibco Spotfire ServerTibco Spotfire Professional+3 | 10/4/2014 | 17/6/2026 | Unspecified vulnerability in Spotfire Web Player Engine, Spotfire Desktop, and Spotfire Server Authentication Module in TIBCO Spotfire Server 3.3.x before 3.3.4, 4.5.x before 4.5.1, 5.0.x before 5.0.2, 5.5.x before 5.5.1, and 6.x before 6.0.2; Spotfire Professional 4.0.x before 4.0.4, 4.5.x before 4.5.2, 5.0.x before… | |
| Modificada | Media (6.4) | 1.3% | — | Tibco Spotfire WEB Player | 15/3/2013 | 16/6/2026 | The Engine in TIBCO Spotfire Web Player 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 does not properly implement access control, which allows remote attackers to obtain sensitive information or modify data via unspecified vectors. | |
| Modificada | Media (4.3) | 1.1% | — | Tibco Spotfire WEB Player | 15/3/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Engine in TIBCO Spotfire Web Player 3.3.x before 3.3.3, 4.0.x before 4.0.3, 4.5.x before 4.5.1, and 5.0.x before 5.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5) | 1.6% | — | Tibco Spotfire Analytics ServerTibco Spotfire ServerTibco WEB Player Automation ServicesTibco Spotfire Professional | 13/3/2012 | 16/6/2026 | TIBCO Spotfire Web Application, Web Player Application, Automation Services Application, and Analytics Client Application in Spotfire Analytics Server before 10.1.2; Server before 3.3.3; and Web Player, Automation Services, and Professional before 4.0.2 allow remote attackers to obtain sensitive information via a… | |
| Modificada | Media (5.8) | 1.3% | — | Neoaxis WEB Player | 20/1/2012 | 16/6/2026 | Directory traversal vulnerability in the web player in NeoAxis NeoAxis web player 1.4 and earlier allows user-assisted remote attackers to write arbitrary files via a .. (dot dot) in a filename in the neoaxis_web_application_win32.zip ZIP archive. | |
| Modificada | Alta (9.3) | 5.7% | — | Divx WEB Player | 16/4/2009 | 16/6/2026 | Integer signedness error in DivX Web Player 1.4.2.7, and possibly earlier versions, allows remote attackers to execute arbitrary code via a DivX file containing a crafted Stream Format (STRF) chunk, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (7.8) | 3.1% | — | Divx WEB Player | 7/3/2007 | 16/6/2026 | A certain ActiveX control in the DivXBrowserPlugin (npdivx32.dll) in DivX Web Player, as distributed with DivX Player 1.3.0, allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via large values to DivxWP.Resize, related to resizing images. | |
| Modificada | Media (6.8) | 1.1% | — | Sourceforge Webmplayer | 2/3/2007 | 16/6/2026 | Multiple SQL injection vulnerabilities in WebMplayer before 0.6.1-Alpha allow remote attackers to execute arbitrary SQL commands via the (1) strid parameter to index.php and the (2) id[0] or other id array index parameter to filecheck.php. | |
| Modificada | Media (6.8) | 2.2% | — | Webmplayer | 2/3/2007 | 16/6/2026 | index.php in WebMplayer before 0.6.1-Alpha allows remote attackers to execute arbitrary code via shell metacharacters in an exec function call. NOTE: some sources have referred to this as eval injection in the param parameter, but CVE source inspection suggests that this is erroneous. | |
| Modificada | Alta (7.5) | 5.5% | — | Virtools WEB Player | 4/10/2005 | 16/6/2026 | Buffer overflow in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to execute arbitrary code via a long filename. | |
| Modificada | Media (5) | 2.1% | — | Virtools WEB Player | 4/10/2005 | 16/6/2026 | Directory traversal vulnerability in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to overwrite arbitrary files via a .. (dot dot) in a filename. |