Vulnerability index

Browse CVEs

12 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Media Server HIGH 7.1
CVE-2025-69414

Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.

Fix: after 1.42.2.10156
Fix from $1,950 2026-01-02
Media Server HIGH 7.1
CVE-2025-69415

In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the devic…

Fix: after 1.42.2.10156
Fix from $1,950 2026-01-02
Media Server HIGH 7.5
CVE-2021-33959EPSS 15%

Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.

Fix: after 1.21
Fix from $1,950 2023-01-18
Media Server HIGH 7.0
CVE-2021-42835

An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user acco…

Fix: 1.25.0.5282+
Fix from $1,950 2021-12-08
Media Server HIGH 8.8
CVE-2020-5742

Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.

Fix: 2020-06-15+
Fix from $1,950 2020-06-15
Media Server HIGH 7.2
CVE-2020-5741 KEVEPSS 73%

Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.

Fix: 1.19.3+
Fix from $1,950 2020-05-08
Media Server HIGH 7.8
CVE-2020-5740

Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privi…

Fix: 1.19.1.2701+
Fix from $1,950 2020-04-22
Media Server HIGH 8.8
CVE-2019-19141

The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user account r…

Fix: after 1.18.2.2029
Fix from $1,950 2019-12-19
Media Server MEDIUM 6.5
CVE-2018-21031

Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token is mishand…

No fix yet
Fix from $1,600 2019-11-18
Media Server CRITICAL 9.8
CVE-2018-13415EPSS 32%

In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack.…

No fix yet
Fix from $2,300 2018-08-13
Media Server HIGH 7.5
CVE-2014-9304EPSS 8%

Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrati…

Fix: after 0.9.9.2
Fix from $1,950 2014-12-07
Media Server MEDIUM 5.0
CVE-2014-9181EPSS 9%

Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in…

Fix: after 0.9.9.2
Fix from $1,600 2014-12-02