Sicherheit
Security
All tracked CVEs and security advisories — sorted by date or severity. Each entry links to the official source. The plain-text explanations are generated automatically — the source remains authoritative.
| CVE / GHSA | Item | Vertical | Severity | Date |
|---|---|---|---|---|
| CVE-2023-30626 Source A critical security vulnerability in Jellyfin allows attackers with low-privilege user accounts to execute arbitrary commands on the server by chaining directory traversal, file upload, and cross-site scripting exploits. |
Jellyfin | Self-hosted apps | Critical | 06.06.2026 |
| CVE-2023-49096 Source A vulnerability in Jellyfin allows attackers to inject additional commands into FFmpeg calls, enabling arbitrary file reading or overwriting. While technically exploitable without authentication, practical exploitation is highly unlikely as it requires guessing random GUIDs. |
Jellyfin | Self-hosted apps | High | 06.06.2026 |
| CVE-2023-48702 Source A vulnerability in Jellyfin allows administrators to execute arbitrary programs via network shares by sending a special path to a system endpoint. |
Jellyfin | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2024-43801 Source Jellyfin media software allows uploading SVG files as profile pictures, enabling attackers to inject malicious SVG files that can steal admin credentials and elevate regular users to administrator privileges. |
Jellyfin | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2025-31499 Source Jellyfin media server contains a vulnerability that allows authenticated users to inject malicious commands into FFmpeg, potentially enabling them to execute arbitrary code on the server. |
Jellyfin | Self-hosted apps | High | 06.06.2026 |
| CVE-2025-32012 Source A vulnerability in Jellyfin allows attackers to spoof their IP address and restart the server without authentication, enabling repeated denial-of-service attacks against the media server. |
Jellyfin | Self-hosted apps | Medium | 06.06.2026 |
| GHSA-rrr6-mvwg-9pg9 Source A vulnerability in Jellyfin allows unauthenticated users to request arbitrarily large splash screen images through the Branding API, which can cause memory, CPU, and disk space issues when repeatedly requested, potentially crashing the server. |
Jellyfin | Self-hosted apps | Low | 06.06.2026 |
| CVE-2026-35031 Source A critical security vulnerability in Jellyfin allows users with subtitle upload permissions to write arbitrary files on the server and ultimately execute code as administrator. |
Jellyfin | Self-hosted apps | Critical | 06.06.2026 |
| CVE-2026-35032 Source A vulnerability in Jellyfin allows authenticated users to read arbitrary files, forge server requests, and steal the database through an unsecured LiveTV endpoint, enabling them to gain administrator privileges. |
Jellyfin | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-35034 Source A vulnerability in Jellyfin allows malicious users to create SyncPlay groups with extremely long names, which can block the service and lock out other users. |
Jellyfin | Self-hosted apps | Medium | 06.06.2026 |
| CVE-2026-35033 Source A security vulnerability in Jellyfin allows unauthenticated attackers to read arbitrary files from the server by injecting malicious parameters into video streaming requests and extracting file contents through the video output. |
Jellyfin | Self-hosted apps | High | 06.06.2026 |
| CVE-2026-9929 Source A vulnerability in Google Chrome's WebGL implementation on Android allows attackers to steal data from other websites through specially crafted web pages. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-9921 Source A vulnerability in Chrome's WebGL component on Android allows attackers to access protected information from other websites through malicious web pages that users visit. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-9920 Source A vulnerability in Google Chrome's GPU component on Android allows attackers who have already compromised the browser renderer to steal data from other websites through specially crafted HTML pages. |
Android | OS & platform | Low | 05.06.2026 |
| CVE-2026-9919 Source A vulnerability in Google Chrome's WebGL component on Android allows attackers to access data from other websites that should normally be protected, using specially crafted web pages. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-9917 Source A vulnerability in Chrome's WebGL component on Android allows attackers to access uninitialized memory areas through malicious web pages, potentially exposing sensitive data from the browser's process memory. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-9912 Source A vulnerability in Google Chrome's GPU implementation on Android allows attackers to read sensitive information from process memory through specially crafted web pages. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-9898 Source A vulnerability in Google Chrome's GPU component on Android allows attackers who have already compromised the renderer process to escape the browser's sandbox and potentially gain broader system access through malicious web pages. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-9892 Source A vulnerability in Chrome's Skia graphics library on Android allows attackers who have already compromised the browser renderer to escape the security sandbox and potentially compromise the entire system. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-9889 Source A vulnerability in Chrome's Dawn component on Android allows attackers to read and write memory outside permitted boundaries through malicious web pages, potentially enabling them to escape the browser's security sandbox. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-9888 Source A memory management vulnerability in Chrome's WebView component on Android allows attackers who have already compromised the renderer process to potentially escape the sandbox and gain broader system access. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-9876 Source A memory management vulnerability in Chrome's WebGL component on Android allows attackers to bypass the browser's security barriers and potentially execute malicious code through specially crafted web pages. |
Android | OS & platform | Critical | 05.06.2026 |
| CVE-2026-9875 Source A vulnerability in Chrome's WebGL component on Android allows attackers to escape the browser sandbox and potentially compromise the device through specially crafted web pages. |
Android | OS & platform | Critical | 05.06.2026 |
| CVE-2026-9872 Source A vulnerability in Google Chrome's GPU component on Android allows attackers to bypass the browser's security barriers and potentially execute malicious code through specially crafted web pages. |
Android | OS & platform | Critical | 05.06.2026 |
| CVE-2026-10020 Source A vulnerability in Chrome's Skia graphics library on Android allows attackers who have already compromised the browser renderer to escape the security sandbox and potentially compromise the entire system. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-10014 Source A memory management vulnerability in Chrome's WebMIDI feature on Android allows attackers who have already compromised the browser renderer to potentially escape the security sandbox and gain elevated system privileges. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-10010 Source A vulnerability in Google Chrome's input handling on Android allows attackers who have already compromised the browser renderer to bypass security boundaries between websites. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-10008 Source A vulnerability in Google Chrome's GPU component on Android allows attackers to access uninitialized memory areas through specially crafted web pages, potentially exposing sensitive data from process memory. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-9123 Source A vulnerability in Google Chrome's Chromecast feature allows local attackers to execute malicious code by sending specially crafted network data to the browser. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-8583 Source A security vulnerability in Google Chrome's WebXR feature on Android allows attackers who have already compromised the browser renderer to access sensitive information from process memory. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-8572 Source A vulnerability in Google Chrome for Android allowed attackers who had already compromised the browser renderer to steal data from other websites through a malicious webpage. |
Android | OS & platform | Low | 05.06.2026 |
| CVE-2026-8571 Source A security vulnerability in Google Chrome's GPU component on Android allows attackers who have already compromised the renderer process to escape the sandbox and gain broader system access through malicious web pages. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-8566 Source A vulnerability in Google Chrome's payment feature on Android allowed attackers to bypass security policies and gain unauthorized access to payment data by using specially crafted web pages. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-8564 Source A security vulnerability in Google Chrome for Android and Mac allows attackers to manipulate the download user interface and deceive users through malicious web pages. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-8552 Source A vulnerability in Google Chrome's GPU component on Android allows attackers to write data outside intended memory boundaries through specially crafted web pages, potentially causing system instability or code execution. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-8539 Source A vulnerability in Google Chrome's SanitizerAPI on Android allows attackers to inject and execute malicious scripts or HTML code through crafted web pages. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-8513 Source A memory management vulnerability in Google Chrome's input handling on Android allows attackers who have already compromised the renderer process to potentially escape the browser's security sandbox and gain elevated system privileges. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-8020 Source A vulnerability in Chrome's GPU component on Android allows attackers who have already compromised the browser renderer to read sensitive information from process memory. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-7993 Source A vulnerability in Google Chrome for Android allowed attackers who had already compromised the browser renderer to display fake URLs in the address bar, deceiving users about which website they were actually visiting. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-7941 Source A vulnerability in Google Chrome for Android allows local attackers to inject malicious scripts or HTML code through crafted browser extensions, potentially leading to cross-site scripting attacks. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-7915 Source A vulnerability in Google Chrome's developer tools on Android allows attackers to bypass navigation restrictions by using specially crafted web pages. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-7913 Source A security vulnerability in Google Chrome's developer tools on Android allows local attackers to gain elevated system privileges through a malicious file. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-7912 Source An integer overflow in Chrome's GPU component on Android allows attackers who have already compromised the renderer process to perform arbitrary memory access through malicious web pages. |
Android | OS & platform | Medium | 05.06.2026 |
| CVE-2026-7905 Source A security vulnerability in Google Chrome's media processing on Android allows attackers who have already compromised the browser renderer to escape the security sandbox and potentially compromise the entire system. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-7352 Source A memory management vulnerability in Google Chrome's media functionality on Android allows attackers who have already compromised the browser renderer to potentially escape the security sandbox and gain elevated system privileges. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-7342 Source A vulnerability in Chrome's WebView component on Android allows attackers to execute malicious code through crafted web pages when using an outdated Chrome version. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-6920 Source A vulnerability in Google Chrome's GPU component on Android allows attackers who have already compromised the renderer process to bypass sandbox security protections through specially crafted web pages. |
Android | OS & platform | Critical | 05.06.2026 |
| CVE-2026-6358 Source A vulnerability in Google Chrome's XR feature on Android allows attackers to access previously freed memory and read data outside permitted boundaries through malicious web pages. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-6319 Source A memory management vulnerability in Google Chrome's payment feature on Android allows attackers to execute malicious code when users visit crafted web pages and perform specific interactions. |
Android | OS & platform | High | 05.06.2026 |
| CVE-2026-6315 Source A vulnerability in Google Chrome for Android allows attackers to execute malicious code when users visit specially crafted websites and perform certain actions. |
Android | OS & platform | High | 05.06.2026 |