Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

2405 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaSin puntuar——Userprivatefiles User Private FilesAI7/10/20267/10/2026
The User Private Files WordPress plugin before 2.1.9 does not validate that a supplied user belongs to the document being operated on before returning that user's email address, allowing any authenticated user, such as a Subscriber, to obtain the email address of any registered account, including administrators.
AplazadaAlta (7.5)——Keking KkfileviewAI6/10/20266/10/2026
kkFileView v5.0.0 through v5.0.2 contains a directory traversal vulnerability in FileController.java. The fileUpload, createFolder and existsFile endpoints accept a "path" parameter that is concatenated into the upload base path without validation, allowing unauthenticated attackers to create arbitrary directories and…
AplazadaAlta (8.6)0.36%—Simplefilelist Simple File ListAI6/10/20266/10/2026
Unauthenticated Arbitrary File Deletion in Simple File List <= 6.3.11 versions.
AplazadaAlta (7.1)0.24%—Najeebmedia Frontend File ManagerAI6/10/20266/10/2026
Unauthenticated Cross Site Scripting (XSS) in Frontend File Manager <= 23.6 versions.
AplazadaAlta (8.8)0.32%—WP User ProfilesAI6/10/20266/10/2026
Subscriber Privilege Escalation in WP User Profiles <= 2.7.3 versions.
AplazadaMedia (5.5)0.13%—File Media RenamerAI6/10/20266/10/2026
The File Media Renamer WordPress plugin through 1.3 does not verify that the requesting user is authorised to modify a given media attachment, allowing any user with file-upload privileges to rename attachments belonging to other users, including administrators, and to corrupt unrelated stored site data that…
AplazadaMedia (5.9)0.20%—Imaginate-solutions File Uploads Addon FOR WoocommerceAI5/10/20266/10/2026
The File Uploads Addon for WooCommerce WordPress plugin before 1.7.6 does not verify that the person requesting a customer-uploaded file is the customer who uploaded it, allowing unauthenticated attackers who know or guess a file's name to download other customers' uploaded files.
AplazadaMedia (5.9)0.29%—Wedevs File UploadsAI5/10/20266/10/2026
The File Uploads Addon for WooCommerce WordPress plugin through 1.7.6 stores customer-uploaded files in a publicly web-accessible uploads directory and the access restriction it generates is ineffective, so an unauthenticated attacker who knows or guesses a file's name can retrieve customer-uploaded files directly,…
AplazadaMedia (5.3)0.19%—Userprivatefiles User Private FilesAI4/10/20266/10/2026
The User Private Files WordPress plugin before 2.2.0 does not properly protect its stored private files on multisite installations, where the rewrite rule it relies on to route file requests through its access check is never reached, allowing unauthenticated users to retrieve other users' private files directly.
AplazadaMedia (4.9)0.23%—Fivestarplugins Five Star Business Profile AND SchemaAI4/10/20266/10/2026
The Five Star Business Profile and Schema WordPress plugin before 2.4.0 does not properly restrict the callbacks used to resolve schema field default values, allowing authenticated users with Author-level access and above to store input that discloses sensitive data, including other users' password hashes and…
AplazadaMedia (6.1)0.22%—ProfilepressAI3/10/20266/10/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input…
AplazadaAlta (8.8)0.63%—ProfilepressAI3/10/20266/10/2026
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated…
AplazadaAlta (8.1)0.52%—Ninjaforms Ninja Forms File UploadsAI2/10/20262/10/2026
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used…
AplazadaCrítica (9.3)0.24%—Wordpress File UploadAI1/10/20261/10/2026
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions.
AplazadaMedia (5.3)0.20%—Metagauss ProfilegridAI1/10/20261/10/2026
Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2.
AplazadaMedia (4.3)0.21%—Prevent Files Folders AccessAI30/9/202630/9/2026
Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions.
AplazadaMedia (6.5)0.21%—Cozmoslabs Profile BuilderAI30/9/202630/9/2026
Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions.
AplazadaMedia (4.3)0.15%—ALL IN ONE Files UploadAI30/9/202630/9/2026
The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them.
AplazadaAlta (8.8)0.28%—Wpeverest ALL IN ONE Files UploadAI30/9/202630/9/2026
The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim…
AplazadaMedia (5.9)0.19%—Mark3labs MCP Filesystem ServerAI29/9/202630/9/2026
mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved…
Pendiente de análisisAlta (8.8)0.31%—NetxAIFilexAI29/9/202629/9/2026
The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not against the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX. Two things follow from that one missing check, both…
AplazadaAlta (7.5)0.22%—File ManagerAIFileorganizerAIFilemanagerpro File Manager PROAI26/9/202628/9/2026
The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the…
AplazadaMedia (5.9)0.22%—File ManagerAI26/9/202628/9/2026
The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on…
AplazadaAlta (7.8)0.09%—Seclore Filesecure Desktop ClientAI25/9/202630/9/2026
Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems.
AplazadaAlta (7.2)0.26%—User Profile BuilderAI25/9/202625/9/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for…
Orbitaley — Vulnerabilidades