CVE-2025-69417
- EPSS 0.01%
- Veröffentlicht 02.01.2026 16:55:18
- Zuletzt bearbeitet 27.02.2026 15:08:04
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve share tokens (intended for unrelated access) via a shared_servers endpoint.
CVE-2025-69416
- EPSS 0.01%
- Veröffentlicht 02.01.2026 16:52:56
- Zuletzt bearbeitet 27.02.2026 15:08:18
In the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can retrieve other tokens (intended for unrelated access) via clients.plex.tv/devices.xml.
CVE-2025-69415
- EPSS 0.02%
- Veröffentlicht 02.01.2026 16:49:36
- Zuletzt bearbeitet 27.02.2026 15:27:18
In Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device token is not properly aligned with whether the device is currently associated with an account.
CVE-2025-69414
- EPSS 0.04%
- Veröffentlicht 02.01.2026 16:43:09
- Zuletzt bearbeitet 27.02.2026 15:27:26
Plex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myplex/account call with a transient access token.
CVE-2025-34158
- EPSS 0.03%
- Veröffentlicht 21.08.2025 13:43:30
- Zuletzt bearbeitet 02.01.2026 16:15:51
Plex Media Server (PMS) 1.41.7.x through 1.42.0.x before 1.42.1 is affected by incorrect resource transfer between spheres because /myplex/account provides the credentials of the server owner (and a /api/resources call reveals other servers accessibl...
CVE-2021-33959
- EPSS 5.59%
- Veröffentlicht 18.01.2023 14:15:10
- Zuletzt bearbeitet 04.04.2025 18:15:41
Plex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.
- EPSS 14.2%
- Veröffentlicht 08.12.2021 15:15:10
- Zuletzt bearbeitet 21.11.2024 06:28:12
An issue was discovered in Plex Media Server through 1.24.4.5081-e362dc1ee. An attacker (with a foothold in a endpoint via a low-privileged user account) can access the exposed RPC service of the update service component. This RPC functionality allow...
CVE-2020-5742
- EPSS 0.82%
- Veröffentlicht 15.06.2020 20:15:11
- Zuletzt bearbeitet 21.11.2024 05:34:31
Improper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cross-origin application requests.
CVE-2020-5741
- EPSS 40.51%
- Veröffentlicht 08.05.2020 13:15:11
- Zuletzt bearbeitet 31.10.2025 22:10:54
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arbitrary Python code.
CVE-2020-5740
- EPSS 0.06%
- Veröffentlicht 22.04.2020 16:15:13
- Zuletzt bearbeitet 21.11.2024 05:34:30
Improper Input Validation in Plex Media Server on Windows allows a local, unauthenticated attacker to execute arbitrary Python code with SYSTEM privileges.