Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

304 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.71%—M-files Server2/5/202217/6/2026
Script injection in M-Files Admin versions before 22.2.11051.0, allows executing stored script in admin tool. M-Files Admin tool allows storing configuration data with script which may then get run by another vault administrator. Requires vault admin level authentication and is not remotely exploitable
ModificadaMedia (4.3)0.56%—M-files Server18/1/202217/6/2026
SSRF vulnerability in M-Files Server products with versions before 22.1.11017.1, in a preview function allowed making queries from the server with certain document types referencing external entities.
ModificadaBaja (2.3)0.25%—M-files Server18/1/202217/6/2026
In M-Files Server product with versions before 21.11.10775.0, enabling logging of Federated authentication to event log wrote sensitive information to log. Mitigating factors are logging is disabled by default.
ModificadaCrítica (9.8)1.1%—M-files ServerM-files WEB18/1/202217/6/2026
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.
ModificadaAlta (8.8)1.2%—Owncloud Files Antivirus15/1/202217/6/2026
The files_antivirus component before 1.0.0 for ownCloud mishandles the protection mechanism by which malicious files (that have been uploaded to a public share) are supposed to be deleted upon detection.
ModificadaAlta (7.2)2.1%—Owncloud Files Antivirus15/1/202217/6/2026
The files_antivirus component before 1.0.0 for ownCloud allows OS Command Injection via the administration settings.
ModificadaAlta (7.5)2.9%—M-files WEB5/12/202117/6/2026
M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of the web server, not the responsibility of the individual web application
ModificadaMedia (4.8)0.67%—Tammersoft Shared Files17/11/202117/6/2026
The Shared Files WordPress plugin before 1.6.61 does not sanitise and escape the Download Counter Text settings, which could allow high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaAlta (8.8)3.8%—Liquidfiles11/11/202117/6/2026
LiquidFiles before 3.6.3 allows remote attackers to elevate their privileges from Admin (or User Admin) to Sysadmin.
ModificadaAlta (7.5)1.3%—M-files WEB28/10/202117/6/2026
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.
ModificadaMedia (4.8)0.64%—Tammersoft Shared Files18/10/202117/6/2026
The Easy Download Manager and File Sharing Plugin with frontend file upload – a better Media Library — Shared Files WordPress plugin before 1.6.57 does not sanitise and escape some of its settings before outputting them in attributes, which could lead to Stored Cross-Site Scripting issues.
ModificadaMedia (6.1)1.0%—Miraheze Globalnewfiles1/9/202117/6/2026
GlobalNewFiles is a MediaWiki extension maintained by Miraheze. Prior to commit number cee254e1b158cdb0ddbea716b1d3edc31fa4fb5d, the username column of the GlobalNewFiles special page is vulnerable to a stored XSS. Commit number cee254e1b158cdb0ddbea716b1d3edc31fa4fb5d contains a patch. As a workaround, one may…
ModificadaMedia (6.5)1.3%—Miraheze Globalnewfiles28/6/202117/6/2026
GlobalNewFiles is a mediawiki extension. Versions prior to 48be7adb70568e20e961ea1cb70904454a671b1d are affected by an uncontrolled resource consumption vulnerability. A large amount of page moves within a short space of time could overwhelm Database servers due to improper handling of load balancing and a lack of an…
ModificadaMedia (6.1)0.41%—Gallery From Files Project Gallery From Files14/6/202117/6/2026
This Gallery from files WordPress plugin through 1.6.0 gives the functionality of uploading images to the server. But filenames are not properly sanitized before being output in an error message when they have an invalid extension, leading to a reflected Cross-Site Scripting issue. Due to the lack of CSRF check, the…
ModificadaCrítica (9.8)1.1%—Apple Files2/6/202116/6/2026
Multiple buffer overflows in the (1) cdf_read_sat, (2) cdf_read_long_sector_chain, and (3) cdf_read_ssat function in file before 5.02.
ModificadaCrítica (9.8)1.1%—Apple Files2/6/202116/6/2026
Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sat functions in file before 5.02.
ModificadaAlta (8.8)1.6%—Jenkins Filesystem Trigger25/5/202117/6/2026
Jenkins Filesystem Trigger Plugin 0.40 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaAlta (7.5)0.62%—Piwigo Localfiles Editor26/4/202117/6/2026
show_default.php in the LocalFilesEditor extension before 11.4.0.1 for Piwigo allows Local File Inclusion because the file parameter is not validated with a proper regular-expression check.
ModificadaMedia (5.4)1.4%—Liquidfiles6/4/202117/6/2026
LiquidFiles 3.4.15 has stored XSS through the "send email" functionality when sending a file via email to an administrator. When a file has no extension and contains malicious HTML / JavaScript content (such as SVG with HTML content), the payload is executed upon a click. This is fixed in 3.5.
ModificadaCrítica (9.8)1.9%—Vanquish Woocommerce Upload Files5/4/202117/6/2026
The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "blocked" extension in the "wcuf_file_name" parameter. It was also…
ModificadaAlta (7.8)0.45%—Rockwellautomation Drivetools Add-on ProfilesRockwellautomation Drivetools SP18/3/202117/6/2026
Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited privileges may be able to exploit resulting in privilege escalation and complete control of the system.
ModificadaMedia (5.7)0.80%—Owncloud Files Antivirus9/2/202117/6/2026
When using an object storage like S3 as the file store, when a user creates a public link to a folder where anonymous users can upload files, and another user uploads a virus the files antivirus app would detect the virus but fails to delete it due to permission issues. This affects the files_antivirus component…
ModificadaAlta (7.5)1.4%—Files FAT Client19/1/202117/6/2026
Files.com Fat Client 3.3.6 allows authentication bypass because the client continues to have access after a logout and a removal of a login profile.
ModificadaMedia (6.1)0.71%—Liquidfiles25/11/202017/6/2026
A Cross-Site Script Inclusion vulnerability was found on LiquidFiles before 3.3.19. This client-side attack requires user interaction (opening a link) and successful exploitation could lead to encrypted e-mail content leakage via messages/sent?format=js and popup?format=js.
ModificadaCrítica (9)1.7%—Liquidfiles25/11/202017/6/2026
An XSS issue was found in the Shares feature of LiquidFiles before 3.3.19. The issue arises from the insecure rendering of HTML files uploaded to the platform as attachments, when the -htmlview URL is directly accessed. The impact ranges from executing commands as root on the server to retrieving sensitive information…