Vulnerability index

Browse CVEs

19 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.1 CVE-2026-35033 Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain an unauthenticated arbitrary file read vulnerability via ffmpe… Jellyfin 10.11.7+ Fix from $2,3002026-04-14 HIGH 8.8 CVE-2026-35031 Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the subtitle upload endpoint (POST /V… Jellyfin 10.11.7+ Fix from $1,9502026-04-14 HIGH 8.1 CVE-2026-35032 Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a vulnerability chain in the LiveTV M3U tuner endpoint (POST /… Jellyfin 10.11.7+ Fix from $1,9502026-04-14 MEDIUM 6.5 CVE-2026-35034 Jellyfin is an open source self hosted media server. Versions prior to 10.11.7 contain a denial of service vulnerability in the SyncPlay group creati… Jellyfin 10.11.7+ Fix from $1,6002026-04-14 CRITICAL 9.8 CVE-2026-31852 Jellyfin is an open-source media system. The code-quality.yml GitHub Actions workflow in jellyfin/jellyfin-ios is vulnerable to arbitrary code execut… Jellyfin Patch available Fix from $2,3002026-03-11 HIGH 8.8 CVE-2025-31499 Jellyfin is an open source self hosted media server. Versions before 10.10.7 are vulnerable to argument injection in FFmpeg. This can be leveraged to… Jellyfin 10.10.7+ Fix from $1,9502025-04-15 HIGH 7.5 CVE-2025-32012 Jellyfin is an open source self hosted media server. In versions 10.9.0 to before 10.10.7, the /System/Restart endpoint provides administrators the a… Jellyfin 10.10.7+ Fix from $1,9502025-04-15 MEDIUM 5.4 CVE-2024-43801 Jellyfin is an open source self hosted media server. The Jellyfin user profile image upload accepts SVG files, allowing for a stored XSS attack again… Jellyfin after 10.9.10 Fix from $1,6002024-09-02 HIGH 7.2 CVE-2023-48702 Jellyfin is a system for managing and streaming media. Prior to version 10.8.13, the `/System/MediaEncoder/Path` endpoint executes an arbitrary file … Jellyfin 10.8.13+ Fix from $1,9502023-12-13 HIGH 8.8 CVE-2023-49096 Jellyfin is a Free Software Media System for managing and streaming media. In affected versions there is an argument injection in the VideosControlle… Jellyfin 10.8.13+ Fix from $1,9502023-12-06 HIGH 8.1 CVE-2023-30626 Jellyfin is a free-software media system. Versions starting with 10.8.0 and prior to 10.8.10 and prior have a directory traversal vulnerability insid… Jellyfin 10.8.10+ Fix from $1,9502023-04-24 MEDIUM 5.4 CVE-2023-30627 jellyfin-web is the web client for Jellyfin, a free-software media system. Starting in version 10.1.0 and prior to version 10.8.10, a stored cross-si… Jellyfin 10.8.10+ Fix from $1,6002023-04-24 HIGH 7.5 CVE-2023-27161 Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. This vulnerability allows atta… Jellyfin after 10.7.7 Fix from $1,9502023-03-10 MEDIUM 5.4 CVE-2023-23635 In Jellyfin 10.8.x through 10.8.3, the name of a collection is vulnerable to stored XSS. This allows an attacker to steal access tokens from the loca… Jellyfin after 10.8.3 Fix from $1,6002023-02-03 MEDIUM 5.4 CVE-2023-23636 In Jellyfin 10.8.x through 10.8.3, the name of a playlist is vulnerable to stored XSS. This allows an attacker to steal access tokens from the localS… Jellyfin after 10.8.3 Fix from $1,6002023-02-03 HIGH 8.8 CVE-2022-35909 In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality. Jellyfin 10.8+ Fix from $1,9502022-08-19 MEDIUM 5.4 CVE-2022-35910 In Jellyfin before 10.8, stored XSS allows theft of an admin access token. Jellyfin 10.8+ Fix from $1,6002022-08-19 MEDIUM 5.8 CVE-2021-29490EPSS 70% Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. Verions prior to 10.7.3 v… Jellyfin 10.7.3+ Fix from $1,6002021-05-06 MEDIUM 6.5 CVE-2021-21402EPSS 80% Jellyfin is a Free Software Media System. In Jellyfin before version 10.7.1, with certain endpoints, well crafted requests will allow arbitrary file … Jellyfin 10.7.1+ Fix from $1,6002021-03-23