Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.1 ZSL-2026-5993

Lyrion Music Server 9.2.0 (search.*) Multiple Script Insertions_ZSL-2026-5993

Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as "LMS" is open-source software which can control and serve stre...

N/A N/A ZEROSCIENCE
HIGH 7.2 ZSL-2026-5989

Lyrion Music Server 9.2.0 (server.log) Unauthenticated Stored XSS_ZSL-2026-5989

Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as "LMS" is open-source software which can control and serve stre...

N/A N/A ZEROSCIENCE
HIGH 7.2 ZSL-2026-5990

Lyrion Music Server 9.2.0 (metadata) Stored XSS_ZSL-2026-5990

Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as "LMS" is open-source software which can control and serve stre...

N/A N/A ZEROSCIENCE
MEDIUM 6.9 ZSL-2026-5991

Lyrion Music Server 9.2.0 Arbitrary Directory Listing_ZSL-2026-5991

Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as "LMS" is open-source software which can control and serve stre...

N/A N/A ZEROSCIENCE
HIGH 8.7 ZSL-2026-5992

Lyrion Music Server 9.2.0 Path Traversal File Read_ZSL-2026-5992

Summary Lyrion Music Server formerly Logitech Media Server, and often abbreviated as "LMS" is open-source software which can control and serve stre...

N/A N/A ZEROSCIENCE
HIGH 7.2 28BA8DE6-E5F6-

Dirty-cow-exploit_28BA8DE6-E5F6-5EDA-B23F-99DD01F58B76

System Documentation Architecture - Frontend: React 19 + Vite + TailwindCSS 4. - Backend: Express.js REST API with modular routing. - Database: SQL...

N/A N/A GITHUBEXPLOIT
NONE MSF:EXPLOIT-MULTI-

ClickFix Server_MSF:EXPLOIT-MULTI-MISC-CLICKFIX_SERVER-

This creates a Web Server which hosts a ClickFix type exploit. When a user visits the site they are given instructions on pasting our payload into ...

N/A N/A METASPLOIT
HIGH 7.2 PACKETSTORM:222804

📄 Lyrion Music Server 9.2.0 server.log Persistent Cross Site Scripting_PACKETSTORM:222804

The log viewer in Lyrion Music Server version 9.2.0 reflects request parameters and raw log content into HTML with no escaping. Any attacker-provid...

N/A N/A PACKETSTORM
HIGH 8.7 PACKETSTORM:222811

📄 Lyrion Music Server 9.2.0 Path Traversal / File Read_PACKETSTORM:222811

Lyrion Music Server version 9.2.0 suffers from a directory traversal vulnerability. Exploiting this issue will allow an unauthenticated attacker to...

N/A N/A PACKETSTORM
MEDIUM 6.1 PACKETSTORM:222812

📄 Lyrion Music Server 9.2.0 search Cross Site Scripting_PACKETSTORM:222812

Lyrion Music Server version 9.2.0 has advanced search parameters that are stuffed back into the page so the form keeps its values. Several free-tex...

N/A N/A PACKETSTORM