İçeriğe atla
Noroxi

Plex kayıtları

plex üreticisine ait 19 yayımlanmış kayıt.

Araştırmacı profili

KEV’e giren
1 · %5,3
Silahlaştırılmış
1 · %5,3
Pre-auth RCE
2
Düzeltme kaydı olan
%0
Yayından KEV’e ortanca
1036 gün

Tüm kayıtlar

19 kayıt
  • Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

    YüksekCVSS 7,2KEVSilahlaştırılmışEPSS %73

    plex · media server8 May 2020

  • CVE-2018-13415
    49Planlayın

    In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE

    KritikCVSS 9,8Kavram kanıtıEPSS %32

    plex · media server13 Ağu 2018

  • CVE-2019-19141
    36İzleyin

    The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user

    YüksekCVSS 8,8İstismar yokEPSS %5

    plex · media server19 Ara 2019

  • CVE-2021-33959
    35İzleyin

    Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.

    YüksekCVSS 7,5Kavram kanıtıEPSS %15

    plex · media server18 Oca 2023

  • CVE-2020-5742
    35İzleyin

    Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.

    YüksekCVSS 8,8İstismar yokEPSS %1

    plex · media server15 Haz 2020

  • CVE-2026-96656
    34İzleyin

    Plex Media Server arbitrary file write

    YüksekCVSS 8,6İstismar yokEPSS %0

    plex · media server6 gün önce

  • CVE-2014-9304
    32İzleyin

    Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary adm

    YüksekCVSS 7,5Kavram kanıtıEPSS %8

    plex · media server7 Ara 2014

  • CVE-2020-5740
    31İzleyin

    Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYS

    YüksekCVSS 7,8İstismar yokEPSS %1

    plex · media server22 Nis 2020

  • CVE-2021-42835
    28İzleyin

    An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee.

    YüksekCVSS 7,0Kavram kanıtıEPSS %1

    plex · media server8 Ara 2021

  • CVE-2026-96651
    28İzleyin

    Plex Media Server path traversal

    YüksekCVSS 7,1İstismar yokEPSS %0

    plex · media server6 gün önce

  • CVE-2025-69415
    28İzleyin

    In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether

    YüksekCVSS 7,1İstismar yokEPSS %0

    plex · media server2 Oca 2026

  • CVE-2025-69414
    28İzleyin

    Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access

    YüksekCVSS 7,1İstismar yokEPSS %0

    plex · media server2 Oca 2026

  • CVE-2018-21031
    27İzleyin

    Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token i

    OrtaCVSS 6,5İstismar yokEPSS %2

    plex · media server18 Kas 2019

  • CVE-2026-96654
    27İzleyin

    Plex Media Server URL injection

    OrtaCVSS 6,9İstismar yokEPSS %0

    plex · media server6 gün önce

  • CVE-2014-9181
    23İzleyin

    Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a ..

    OrtaCVSS 5,0Kavram kanıtıEPSS %9

    plex · media server2 Ara 2014

  • CVE-2026-96652
    21İzleyin

    Plex Media Server SSRF

    OrtaCVSS 5,3İstismar yokEPSS %0

    plex · media server6 gün önce

  • CVE-2026-96655
    21İzleyin

    Plex Media Server arbitrary-host SSRF

    OrtaCVSS 5,3İstismar yokEPSS %0

    plex · media server6 gün önce

  • CVE-2025-69417
    17İzleyin

    In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unr

    OrtaCVSS 4,3İstismar yokEPSS %0

    plex · media server2 Oca 2026

  • CVE-2025-69416
    17İzleyin

    In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unr

    OrtaCVSS 4,3İstismar yokEPSS %0

    plex · media server2 Oca 2026