Emby
6 CVEs tracked since 2025. Since Aug 2025, none of them reached CISA KEV.
Emby CVEs per month
| Month | CVEs | In CISA KEV |
|---|---|---|
| 2025-08 | 6 | 0 |
Products
The products that kept showing up in Emby's monthly top three, with their CVEs summed over those months.
Latest CVEs
The 15 most recently published vulnerabilities affecting Emby.
- CVE-2025-64113Emby Server allows attackers to gain administrative server access without preconditions9.8
- CVE-2025-64325Emby Server is Vulnerable to Remote Code Execution Through XSS in Admin Dashboard9.0
- CVE-2025-46391CWE-284: Improper Access Control6.5
- CVE-2025-46390CWE-204: Observable Response Discrepancy7.5
- CVE-2025-46389CWE-620: Unverified Password Change6.5
- CVE-2025-46388CWE-200 Exposure of Sensitive Information to an Unauthorized Actor4.3
- CVE-2025-46387CWE-639 Authorization Bypass Through User-Controlled Key8.8
- CVE-2025-46386CWE-639 Authorization Bypass Through User-Controlled Key8.8
- CVE-2025-46385CWE-918 Server-Side Request Forgery (SSRF)8.6
- CVE-2025-46384CWE-434 Unrestricted Upload of File with Dangerous Type8.8
- CVE-2025-46383CWE-79 Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting')6.1
- CVE-2023-4167Media Browser Emby Server cross site scripting3.5
- CVE-2021-25827Emby Server < 4.7.12.0 is vulnerable to a login bypass attack by setting the X-Forwarded-For header to a local IP-address.9.8
- CVE-2021-25828Emby Server versions < 4.6.0.50 is vulnerable to Cross Site Scripting (XSS) vulnerability via a crafted GET request to /web.6.1
- CVE-2023-33193Emby Server Proxy Header Spoofing Vulnerability9.1
The record
- Peak rank
- #137 in Aug 2025
- Busiest month shown
- Aug 2025, 6 CVEs
- Months with a KEV entry
- 0 since Aug 2025
- Monthly snapshots
- 1 since 2025