Перейти к содержимому
Noroxi

Записи Plex

19 опубликованных записей вендора plex.

Профиль для исследователя

Попали в KEV
1 · 5,3 %
С эксплойтом
1 · 5,3 %
Pre-auth RCE
2
С записью об исправлении
0 %
Медиана: публикация → KEV
1036 дн.

Все записи

19 записей
  • CVE-2020-5741
    80Срочно

    Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

    ВысокаяCVSS 7,2KEVГотовый эксплойтEPSS 73 %

    plex · media server8 мая 2020 г.

  • CVE-2018-13415
    49В плане

    In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE

    КритическаяCVSS 9,8Proof of conceptEPSS 32 %

    plex · media server13 авг. 2018 г.

  • CVE-2019-19141
    36Наблюдать

    The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user

    ВысокаяCVSS 8,8Эксплойта нетEPSS 5 %

    plex · media server19 дек. 2019 г.

  • CVE-2021-33959
    35Наблюдать

    Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.

    ВысокаяCVSS 7,5Proof of conceptEPSS 15 %

    plex · media server18 янв. 2023 г.

  • CVE-2020-5742
    35Наблюдать

    Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.

    ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %

    plex · media server15 июн. 2020 г.

  • CVE-2026-96656
    34Наблюдать

    Plex Media Server arbitrary file write

    ВысокаяCVSS 8,6Эксплойта нетEPSS 0 %

    plex · media server6 дней назад

  • CVE-2014-9304
    32Наблюдать

    Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary adm

    ВысокаяCVSS 7,5Proof of conceptEPSS 8 %

    plex · media server7 дек. 2014 г.

  • CVE-2020-5740
    31Наблюдать

    Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYS

    ВысокаяCVSS 7,8Эксплойта нетEPSS 1 %

    plex · media server22 апр. 2020 г.

  • CVE-2021-42835
    28Наблюдать

    An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee.

    ВысокаяCVSS 7,0Proof of conceptEPSS 1 %

    plex · media server8 дек. 2021 г.

  • CVE-2026-96651
    28Наблюдать

    Plex Media Server path traversal

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    plex · media server6 дней назад

  • CVE-2025-69415
    28Наблюдать

    In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    plex · media server2 янв. 2026 г.

  • CVE-2025-69414
    28Наблюдать

    Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access

    ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %

    plex · media server2 янв. 2026 г.

  • CVE-2018-21031
    27Наблюдать

    Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token i

    СредняяCVSS 6,5Эксплойта нетEPSS 2 %

    plex · media server18 нояб. 2019 г.

  • CVE-2026-96654
    27Наблюдать

    Plex Media Server URL injection

    СредняяCVSS 6,9Эксплойта нетEPSS 0 %

    plex · media server6 дней назад

  • CVE-2014-9181
    23Наблюдать

    Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a ..

    СредняяCVSS 5,0Proof of conceptEPSS 9 %

    plex · media server2 дек. 2014 г.

  • CVE-2026-96652
    21Наблюдать

    Plex Media Server SSRF

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    plex · media server6 дней назад

  • CVE-2026-96655
    21Наблюдать

    Plex Media Server arbitrary-host SSRF

    СредняяCVSS 5,3Эксплойта нетEPSS 0 %

    plex · media server6 дней назад

  • CVE-2025-69417
    17Наблюдать

    In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unr

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    plex · media server2 янв. 2026 г.

  • CVE-2025-69416
    17Наблюдать

    In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unr

    СредняяCVSS 4,3Эксплойта нетEPSS 0 %

    plex · media server2 янв. 2026 г.