Media Server

Vendor:

First CVE: Dec 2, 2014 · Active for 11 years

15
Total CVEs
More Total CVEs than 92% of tracked products
1.9
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
7.2
Avg CVSS
Higher Avg CVSS than 43% of tracked products
6.7%
KEV Rate
Higher KEV Rate than 97% of tracked products

Trends Over Time

The number and severity of CVEs published that impact Media Server over time

Volume of CVEsAvg CVSS Base Score
First CVE
Dec 2, 2014
11 years ago
Most Recent CVE
Jan 2, 2026
203 days ago

CVE Severity & Scoring

Media Server15 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local2 (13.3%)
Network11 (73.3%)
Unknown2 (13.3%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low12 (80.0%)
High1 (6.7%)
Unknown2 (13.3%)
User Interaction
None12 (80.0%)
Unknown2 (13.3%)
Required1 (6.7%)
Privileges Required
Low9 (60.0%)
High1 (6.7%)
None3 (20.0%)
Unknown2 (13.3%)

Top CVEs

Signals from CVEs in this product scope (15 CVEs).

15 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.
May 8, 20207.294YESYES
In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attack
Aug 13, 20189.861NOYES
Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the s
Aug 21, 20258.532NONO
Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
Jan 18, 20237.531NONO
Plex Media Server before 0.9.9.3 allows remote attackers to bypass the web server whitelist, conduct SSRF attacks, and execute arbitrary administrative actions via multiple crafted
Dec 7, 20147.531NOYES
Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.
Jun 15, 20208.828NONO
The Camera Upload functionality in Plex Media Server through 1.18.2.2029 allows remote authenticated users to write files anywhere the user account running the Plex Media Server ha
Dec 19, 20198.827NONO
Multiple directory traversal vulnerabilities in Plex Media Server before 0.9.9.3 allow remote attackers to read arbitrary files via a .. (dot dot) in the URI to (1) manage/ or (2)
Dec 2, 20145.026NOYES
Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.
Jan 2, 20267.125NONO
In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with
Jan 2, 20267.124NONO

Exploit Exposure

Signals from CVEs in this product scope (15 CVEs).

CISA KEV
1 CVE
6.7% of CVEs· 97th percentile
Metasploit
1 CVE
6.7% of CVEs· 97th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
3 CVEs
20.0% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (15 CVEs).

Media Mentions

Signals from CVEs in this product scope (15 CVEs).

Top CNAs Publishing CVEs For Media Server

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
1.18.2.2029-36236cc4c16.52.1%00
1.13.2.515419.831.8%01