Skip to content
Noroxi

Plex records

19 published records for vendor plex.

All records

19 records
  • Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

    HighCVSS 7.2KEVWeaponizedEPSS 73%

    plex · media serverMay 8, 2020

  • In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE

    CriticalCVSS 9.8Proof of conceptEPSS 32%

    plex · media serverAug 13, 2018

  • The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user

    HighCVSS 8.8No exploitEPSS 5%

    plex · media serverDec 19, 2019

  • Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.

    HighCVSS 7.5Proof of conceptEPSS 15%

    plex · media serverJan 18, 2023

  • CVE-2020-5742
    35Monitor

    Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.

    HighCVSS 8.8No exploitEPSS 1%

    plex · media serverJun 15, 2020

  • Plex Media Server arbitrary file write

    HighCVSS 8.6No exploitEPSS 0%

    plex · media server6 days ago

  • CVE-2014-9304
    32Monitor

    Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary adm

    HighCVSS 7.5Proof of conceptEPSS 8%

    plex · media serverDec 7, 2014

  • CVE-2020-5740
    31Monitor

    Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYS

    HighCVSS 7.8No exploitEPSS 1%

    plex · media serverApr 22, 2020

  • An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee.

    HighCVSS 7.0Proof of conceptEPSS 1%

    plex · media serverDec 8, 2021

  • Plex Media Server path traversal

    HighCVSS 7.1No exploitEPSS 0%

    plex · media server6 days ago

  • In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether

    HighCVSS 7.1No exploitEPSS 0%

    plex · media serverJan 2, 2026

  • Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access

    HighCVSS 7.1No exploitEPSS 0%

    plex · media serverJan 2, 2026

  • Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token i

    MediumCVSS 6.5No exploitEPSS 2%

    plex · media serverNov 18, 2019

  • Plex Media Server URL injection

    MediumCVSS 6.9No exploitEPSS 0%

    plex · media server6 days ago

  • CVE-2014-9181
    23Monitor

    Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a ..

    MediumCVSS 5.0Proof of conceptEPSS 9%

    plex · media serverDec 2, 2014

  • Plex Media Server SSRF

    MediumCVSS 5.3No exploitEPSS 0%

    plex · media server6 days ago

  • Plex Media Server arbitrary-host SSRF

    MediumCVSS 5.3No exploitEPSS 0%

    plex · media server6 days ago

  • In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unr

    MediumCVSS 4.3No exploitEPSS 0%

    plex · media serverJan 2, 2026

  • In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unr

    MediumCVSS 4.3No exploitEPSS 0%

    plex · media serverJan 2, 2026