Vulnerabilities > Jellyfin > Jellyfin > 10.3.2
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2023-12-13 | CVE-2023-48702 | Unspecified vulnerability in Jellyfin Jellyfin is a system for managing and streaming media. | 7.2 |
2023-12-06 | CVE-2023-49096 | Unspecified vulnerability in Jellyfin Jellyfin is a Free Software Media System for managing and streaming media. | 8.8 |
2023-04-24 | CVE-2023-30627 | Unspecified vulnerability in Jellyfin jellyfin-web is the web client for Jellyfin, a free-software media system. | 5.4 |
2023-03-10 | CVE-2023-27161 | Server-Side Request Forgery (SSRF) vulnerability in Jellyfin Jellyfin up to v10.7.7 was discovered to contain a Server-Side Request Forgery (SSRF) via the component /Repositories. | 7.5 |
2022-08-19 | CVE-2022-35909 | Unspecified vulnerability in Jellyfin In Jellyfin before 10.8, the /users endpoint has incorrect access control for admin functionality. | 8.8 |
2022-08-19 | CVE-2022-35910 | Cross-site Scripting vulnerability in Jellyfin In Jellyfin before 10.8, stored XSS allows theft of an admin access token. | 5.4 |
2021-05-06 | CVE-2021-29490 | Unspecified vulnerability in Jellyfin Jellyfin is a free software media system that provides media from a dedicated server to end-user devices via multiple apps. | 5.8 |
2021-03-23 | CVE-2021-21402 | Unspecified vulnerability in Jellyfin Jellyfin is a Free Software Media System. | 6.5 |