Plex records
19 published records for vendor plex.
Researcher profile
- Entered KEV
- 1 · 5.3%
- Weaponized
- 1 · 5.3%
- Pre-auth RCE
- 2
- With a fix record
- 0%
- Median publish → KEV
- 1036 days
Recurring classes
- CWE-863 Incorrect Authorization3
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-367 Time-of-check Time-of-use (TOCTOU) Race Condition1
- CWE-427 Uncontrolled Search Path Element1
- CWE-502 Deserialization of Untrusted Data1
The weakness classes this vendor ships most often: where to look.
CWEAll records
19 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
80Now | CVE-2020-5741Weaponized | Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.plex · media server · CWE-502 | High7.2 | KEV | 72.9% | May 8, 2020 |
49Plan | CVE-2018-13415Proof of concept | In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXEplex · media server · CWE-611 | Critical9.8 | — | 31.8% | Aug 13, 2018 |
36Monitor | CVE-2019-19141No exploit | The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user plex · media server · CWE-22 | High8.8 | — | 4.7% | Dec 19, 2019 |
35Monitor | CVE-2021-33959Proof of concept | Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.plex · media server · CWE-346 | High7.5 | — | 15.0% | Jan 18, 2023 |
35Monitor | CVE-2020-5742No exploit | Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.plex · media server | High8.8 | — | 1.4% | Jun 15, 2020 |
34Monitor | CVE-2026-96656No exploit | Plex Media Server arbitrary file writeplex · media server · CWE-73 | High8.6 | — | 0.3% | 6 days ago |
32Monitor | CVE-2014-9304Proof of concept | Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary admplex · media server · CWE-264 | High7.5 | — | 8.1% | Dec 7, 2014 |
31Monitor | CVE-2020-5740No exploit | Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSplex · media server · CWE-427 | High7.8 | — | 0.7% | Apr 22, 2020 |
28Monitor | CVE-2021-42835Proof of concept | An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee.plex · media server · CWE-367 | High7.0 | — | 1.2% | Dec 8, 2021 |
28Monitor | CVE-2026-96651No exploit | Plex Media Server path traversalplex · media server · CWE-22 | High7.1 | — | 0.4% | 6 days ago |
28Monitor | CVE-2025-69415No exploit | In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether plex · media server · CWE-672 | High7.1 | — | 0.3% | Jan 2, 2026 |
28Monitor | CVE-2025-69414No exploit | Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient accessplex · media server · CWE-863 | High7.1 | — | 0.3% | Jan 2, 2026 |
27Monitor | CVE-2018-21031No exploit | Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token iplex · media server · CWE-522 | Medium6.5 | — | 2.1% | Nov 18, 2019 |
27Monitor | CVE-2026-96654No exploit | Plex Media Server URL injectionplex · media server · CWE-84 | Medium6.9 | — | 0.2% | 6 days ago |
23Monitor | CVE-2014-9181Proof of concept | Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a ..plex · media server · CWE-22 | Medium5.0 | — | 9.5% | Dec 2, 2014 |
21Monitor | CVE-2026-96652No exploit | Plex Media Server SSRFplex · media server · CWE-918 | Medium5.3 | — | 0.2% | 6 days ago |
21Monitor | CVE-2026-96655No exploit | Plex Media Server arbitrary-host SSRFplex · media server · CWE-918 | Medium5.3 | — | 0.2% | 6 days ago |
17Monitor | CVE-2025-69417No exploit | In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrplex · media server · CWE-863 | Medium4.3 | — | 0.3% | Jan 2, 2026 |
17Monitor | CVE-2025-69416No exploit | In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrplex · media server · CWE-863 | Medium4.3 | — | 0.3% | Jan 2, 2026 |
- CVE-2020-574180Now
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.
HighCVSS 7.2KEVWeaponizedEPSS 73%plex · media serverMay 8, 2020
- CVE-2018-1341549Plan
In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE
CriticalCVSS 9.8Proof of conceptEPSS 32%plex · media serverAug 13, 2018
- CVE-2019-1914136Monitor
The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user
HighCVSS 8.8No exploitEPSS 5%plex · media serverDec 19, 2019
- CVE-2021-3395935Monitor
Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
HighCVSS 7.5Proof of conceptEPSS 15%plex · media serverJan 18, 2023
- CVE-2020-574235Monitor
Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.
HighCVSS 8.8No exploitEPSS 1%plex · media serverJun 15, 2020
- CVE-2026-9665634Monitor
Plex Media Server arbitrary file write
HighCVSS 8.6No exploitEPSS 0%plex · media server6 days ago
- CVE-2014-930432Monitor
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary adm
HighCVSS 7.5Proof of conceptEPSS 8%plex · media serverDec 7, 2014
- CVE-2020-574031Monitor
Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYS
HighCVSS 7.8No exploitEPSS 1%plex · media serverApr 22, 2020
- CVE-2021-4283528Monitor
An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee.
HighCVSS 7.0Proof of conceptEPSS 1%plex · media serverDec 8, 2021
- CVE-2026-9665128Monitor
Plex Media Server path traversal
HighCVSS 7.1No exploitEPSS 0%plex · media server6 days ago
- CVE-2025-6941528Monitor
In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether
HighCVSS 7.1No exploitEPSS 0%plex · media serverJan 2, 2026
- CVE-2025-6941428Monitor
Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access
HighCVSS 7.1No exploitEPSS 0%plex · media serverJan 2, 2026
- CVE-2018-2103127Monitor
Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token i
MediumCVSS 6.5No exploitEPSS 2%plex · media serverNov 18, 2019
- CVE-2026-9665427Monitor
Plex Media Server URL injection
MediumCVSS 6.9No exploitEPSS 0%plex · media server6 days ago
- CVE-2014-918123Monitor
Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a ..
MediumCVSS 5.0Proof of conceptEPSS 9%plex · media serverDec 2, 2014
- CVE-2026-9665221Monitor
Plex Media Server SSRF
MediumCVSS 5.3No exploitEPSS 0%plex · media server6 days ago
- CVE-2026-9665521Monitor
Plex Media Server arbitrary-host SSRF
MediumCVSS 5.3No exploitEPSS 0%plex · media server6 days ago
- CVE-2025-6941717Monitor
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unr
MediumCVSS 4.3No exploitEPSS 0%plex · media serverJan 2, 2026
- CVE-2025-6941617Monitor
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unr
MediumCVSS 4.3No exploitEPSS 0%plex · media serverJan 2, 2026