VYPR

Plex Media Server

by Plexinc

CVEs (4)

  • CVE-2018-13415CriAug 13, 2018
    risk 0.69cvss 9.8epss 0.32

    In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same…

  • CVE-2020-5742Jun 15, 2020
    risk 0.00cvss epss 0.01

    Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.

  • CVE-2020-5740Apr 22, 2020
    risk 0.00cvss epss 0.01

    Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privileges.

  • CVE-2019-19141Dec 19, 2019
    risk 0.00cvss epss 0.04

    The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user account running the Plex Media Server has permissions. This allows remote code execution via a variety of methods, such as (on a default…