-Infinity
0

Vendor Risk Score

See how plex compares to other vendors in security performance

View Risk Score →

BleepingComputerFFmpeg fixes PixelSmash flaw in widely used video decoder

First published (updated )

Plex Plex Media ServerIn the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can…

Risk 26
Severity
5
First published (updated )

Plex Plex Media ServerIn the plex.tv backend for Plex Media Server (PMS) through 2025-12-31, a non-server device token can…

Risk 26
Severity
5
First published (updated )

Plex Plex Media ServerIn Plex Media Server (PMS) through 1.42.2.10156, ability to access /myplex/account with a device tok…

Risk 48
Severity
7.1
First published (updated )

Plex Plex Media ServerPlex Media Server (PMS) through 1.42.2.10156 allows retrieval of a permanent access token via a /myp…

Risk 55
Severity
8.5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

The RegisterWhat the Plex? Streaming service suffers yet another password spill

First published (updated )

BleepingComputerPlex tells users to reset passwords after new data breach

First published (updated )

300k+ Plex Media Server instances still vulnerable to attack via CVE-2025-34158

First published (updated )
Social
reddit

Plex Plex Media ServerPlex Media Server (PMS) 1.41.7.x - 1.42.0.x Unspecified Vulnerabiliity

Risk 58
Severity
8.5
First published (updated )

BleepingComputerPlex warns users to patch security vulnerability immediately

First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Plex Media ServerPlex media server 1.21 and before is vulnerable to ddos reflection attack via plex service.

Risk 43
Severity
7.5
First published (updated )

Plex media serverRace Condition

Risk 63
Severity
7
First published (updated )

Plex Media ServerImproper Access Control in Plex Media Server prior to June 15, 2020 allows any origin to execute cro…

Risk 77
Severity
8.8
First published (updated )

Plex media serverPlex Media Server Remote Code Execution Vulnerability

Risk 84
Severity
7.2
First published (updated )

Plex media serverInput Validation

Risk 69
Severity
7.8
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Plex Media ServerPath Traversal

Risk 79
Severity
8.8
First published (updated )

Plex Media ServerTautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex…

Risk 38
Severity
6.5
First published (updated )

Plex Media ServerXEE

Risk 86
Severity
9.8
First published (updated )

Plex Media ServerSSRF

Risk 52
Severity
7.5
First published (updated )

Plex Media ServerPath Traversal

Risk 26
Severity
5
First published (updated )
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203