Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.38% | — | Openr Opentmpfiles | 26/10/2020 | 17/6/2026 | opentmpfiles through 0.3.1 allows local users to take ownership of arbitrary files because d entries are mishandled and allow a symlink attack. | |
| Modificada | Media (4.9) | 1.2% | — | Oracle Database Filesystem | 21/10/2020 | 17/6/2026 | Vulnerability in the Database Filesystem component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Resource, Create Table, Create View, Create Procedure, Dbfs_role privilege with network access… | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Locked Files Report | 16/9/2020 | 17/6/2026 | Jenkins Locked Files Report Plugin 1.6 and earlier does not escape locked files' names in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission. | |
| Modificada | Media (6.3) | 0.20% | — | Opensuse Texlive-filesystemOpensuse Leap | 2/4/2020 | 17/6/2026 | A Race Condition Enabling Link Following vulnerability in the cron job shipped with texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users in… | |
| Modificada | Alta (7) | 0.29% | — | Opensuse Texlive-filesystem | 2/4/2020 | 17/6/2026 | A Race Condition Enabling Link Following vulnerability in the packaging of texlive-filesystem of SUSE Linux Enterprise Module for Desktop Applications 15-SP1, SUSE Linux Enterprise Software Development Kit 12-SP4, SUSE Linux Enterprise Software Development Kit 12-SP5; openSUSE Leap 15.1 allows local users to corrupt… | |
| Modificada | Crítica (9.8) | 45% | 💥 Exploit | Sibsoft Xfilesharing | 13/11/2019 | 17/6/2026 | SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP. | |
| Modificada | Alta (7.5) | 20% | 💥 Exploit | Sibsoft Xfilesharing | 13/11/2019 | 17/6/2026 | SibSoft Xfilesharing through 2.5.1 allows op=page&tmpl=../ directory traversal to read arbitrary files. | |
| Modificada | Media (5.3) | 1.2% | — | SilverstripeSymbiote Versionedfiles | 26/9/2019 | 17/6/2026 | In the Versioned Files module through 2.0.3 for SilverStripe 3.x, unpublished versions of files are publicly exposed to anyone who can guess their URL. This guess could be highly informed by a basic understanding of the symbiote/silverstripe-versionedfiles source code. (Users who upgrade from SilverStripe 3.x to 4.x… | |
| Modificada | Media (4.8) | 0.66% | — | Profiles Project Profiles | 26/4/2019 | 17/6/2026 | XSS exists in the ProFiles 1.5 component for Joomla! via the name or path parameter when creating a new folder in the administrative panel. | |
| Modificada | Crítica (9.8) | 3.5% | — | PrestashopMypresta Customer Files Upload | 19/11/2018 | 17/6/2026 | modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations under modules/productfiles), order (for… | |
| Modificada | Crítica (10) | 7.0% | — | Apex-publish-static-files Project Apex-publish-static-files | 30/10/2018 | 17/6/2026 | A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument. | |
| Modificada | Alta (7) | 0.36% | — | Base-files Project Base-filesCanonical Ubuntu Linux | 21/8/2018 | 17/6/2026 | The MOTD update script in the base-files package in Ubuntu 18.04 LTS before 10.1ubuntu2.2, and Ubuntu 18.10 before 10.1ubuntu6 incorrectly handled temporary files. A local attacker could use this issue to cause a denial of service, or possibly escalate privileges if kernel symlink restrictions were disabled. | |
| Modificada | Media (5.5) | 0.40% | — | Openr Opentmpfiles | 14/2/2018 | 17/6/2026 | OpenRC opentmpfiles through 0.1.3, when the fs.protected_hardlinks sysctl is turned off, allows local users to obtain ownership of arbitrary files by creating a hard link inside a directory on which "chown -R" will be run. | |
| Modificada | Media (6.7) | 0.18% | — | Huawei Files | 22/11/2017 | 17/6/2026 | The Files APP 7.1.1.308 and earlier versions in some Huawei mobile phones has a vulnerability of plaintext storage of users' Safe passwords. An attacker with the root privilege of an Android system could forge the Safe to read users' plaintext Safe passwords, leading to information leak. | |
| Modificada | Alta (7.8) | 0.25% | — | Huawei Files | 22/11/2017 | 17/6/2026 | The Files APP 7.1.1.309 and earlier versions in some Huawei mobile phones has a brute-force password cracking vulnerability due to the improper design of the Safe key database. An unauthorized attacker could access sensitive database information and may crack users' Safe passwords, leading to information leak. | |
| Modificada | Baja (2.1) | 0.20% | — | Mcafee Endpoint Encryption FOR Files AND FoldersMcafee File AND Removable Media Protection | 29/10/2014 | 17/6/2026 | The (1) Removable Media and (2) CD and DVD encryption offsite access options (formerly Endpoint Encryption for Removable Media or EERM) in McAfee File and Removable Media Protection (FRP) 4.3.0.x, and Endpoint Encryption for Files and Folders (EEFF) 3.2.x through 4.2.x, uses a hard-coded salt, which makes it easier… | |
| Modificada | Media (4.3) | 1.6% | — | HOT Files\ File Sharing AND Download Manager Project | 2/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in tpls/editmedia.php in the Hot Files: File Sharing and Download Manager (wphotfiles) plugin 1.0.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the mediaid parameter. | |
| Modificada | Alta (7.4) | 0.62% | — | Filesanywhere | 4/11/2012 | 16/6/2026 | FilesAnywhere does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate. | |
| Modificada | Baja (3.6) | 0.50% | — | Shlomi Fish Config-inifiles | 27/6/2012 | 16/6/2026 | The Config::IniFiles module before 2.71 for Perl creates temporary files with predictable names, which allows local users to overwrite arbitrary files via a symlink attack. NOTE: some of these details are obtained from third party information. NOTE: it has been reported that this might only be exploitable by writing… | |
| Modificada | Media (4.3) | 1.2% | — | Robert Gonda RTG Files | 14/2/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Documents download (rtg_files) extension before 1.5.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Robert Gonda RTG Files | 14/2/2012 | 16/6/2026 | SQL injection vulnerability in the Documents download (rtg_files) extension before 1.5.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Ut-files Utstats | 2/11/2011 | 16/6/2026 | SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL commands via the pid parameter in a matchp action. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Ut-files Utstats | 2/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers to inject arbitrary web script or HTML via the mid parameter. | |
| Modificada | Alta (7.5) | 1.2% | — | Files2links F2L 3000 Appliance | 2/2/2010 | 16/6/2026 | SQL injection vulnerability in Files2Links F2L 3000 appliance 4.0.0, and possibly other versions and models, allows remote attackers to execute arbitrary SQL commands via unspecified parameters to the login page. | |
| Modificada | Media (6.8) | 3.4% | 💥 Exploit | Marcelo Costa Fileserver | 20/7/2009 | 16/6/2026 | Directory traversal vulnerability in the Marcelo Costa FileServer component 1.0 for Microsoft Windows Live Messenger and Messenger Plus! Live (MPL) allows remote authenticated users to list arbitrary directories and read arbitrary files via a .. (dot dot) in a pathname. |