Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.54% | — | Prasathmani TinyfilemanagerAI | 17/4/2026 | 17/6/2026 | A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /filemanager.php of the component POST Parameter Handler. The manipulation of the argument file[] results in path traversal. The attack may be performed from remote. The exploit has been made public and… | |
| Aplazada | Media (4.3) | 0.36% | — | ProfilepressAI | 15/4/2026 | 17/6/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 4.16.12. This is due to the 'process_checkout' function not properly enforcing the plan active… | |
| Analizada | Crítica (9.8) | 0.28% | — | BMC Control-m/managed File Transfer | 10/4/2026 | 17/6/2026 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the application package. If left unchanged, these credentials can be easily obtained and may allow unauthorized access to the MFT API debug interface. | |
| Analizada | Alta (7.5) | 0.27% | — | BMC Control-m/managed File Transfer | 10/4/2026 | 17/6/2026 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its corresponding secret value. With these exposed secrets, an attacker could invoke privileged API operations, potentially leading to unauthorized access. | |
| Analizada | Alta (8.8) | 0.40% | — | BMC Control-m/managed File Transfer | 10/4/2026 | 17/6/2026 | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitrary file read/write… | |
| Aplazada | Media (5.3) | 0.30% | — | Glowlogix WP Frontend ProfileAI | 8/4/2026 | 24/7/2026 | Missing Authorization vulnerability in Glowlogix WP Frontend Profile wp-front-end-profile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Frontend Profile: from n/a through <= 1.3.9. | |
| Analizada | Alta (8.8) | 0.56% | — | Filebrowser | 7/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in commit b6a4fb1 ("self-registered users don't get execute perms") stripped Execute permission and Commands from users created via the signup handler. The… | |
| Analizada | Media (5.3) | 0.39% | — | Filebrowser | 7/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the resourceGetHandler in http/resource.go returns full text file content without checking the Perm.Download permission flag. All three other content-serving… | |
| Analizada | Media (6.3) | 0.44% | — | Filebrowser | 7/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the Matches() function in rules/rules.go uses strings.HasPrefix() without a trailing directory separator when matching paths against access rules. A rule for… | |
| Analizada | Alta (8.2) | 0.43% | — | Filebrowser | 7/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, when an admin revokes a user's Share and Download permissions, existing share links created by that user remain fully accessible to unauthenticated users. The public… | |
| Modificada | Alta (7.5) | 2.4% | 💥 PoC | Filebrowser | 7/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.0.0 until 2.33.8, the hook system in File Browser — which executes administrator-defined shell commands on file events such as upload, rename, and delete — is vulnerable to OS… | |
| Aplazada | Crítica (9.8) | 63% | 💥 Exploit | Ninjaforms Ninja Forms File UploadsAI | 7/4/2026 | 17/6/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to upload arbitrary files on… | |
| Analizada | Media (6.9) | 0.17% | — | Filezilla-project Filezilla Client | 5/4/2026 | 24/7/2026 | FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by 'BBBB' and 'CCCC' sequences in… | |
| Aplazada | Alta (8.7) | 0.41% | — | Unisharp Laravel File ManagerAI | 5/4/2026 | 24/7/2026 | UniSharp Laravel File Manager v2.0.0-alpha7 and v2.0 contain an arbitrary file upload vulnerability that allows authenticated attackers to upload malicious files by sending multipart form data to the upload endpoint. Attackers can upload PHP files with the type parameter set to Files and execute arbitrary code by… | |
| Aplazada | Media (6.5) | 0.38% | — | ProfilepressAI | 4/4/2026 | 24/7/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.11. This is due to the plugin allowing user-supplied billing field values from the… | |
| Aplazada | Alta (7.1) | 0.31% | — | ProfilepressAI | 4/4/2026 | 21/7/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to unauthorized membership payment bypass in all versions up to, and including, 4.16.11. This is due to a missing ownership verification on the… | |
| Analizada | Alta (8.8) | 3.4% | — | Progress Sharefile Storage Zones Controller | 2/4/2026 | 17/6/2026 | Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. | |
| Analizada | Crítica (9.8) | 3.2% | 💥 Exploit | Progress Sharefile Storage Zones Controller | 2/4/2026 | 17/6/2026 | Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution. | |
| Aplazada | Baja (2.1) | 1.8% | — | Efforthye Fast-filesystem-mcpAI | 2/4/2026 | 17/6/2026 | A security flaw has been discovered in efforthye fast-filesystem-mcp up to 3.5.1. The affected element is the function handleGetDiskUsage of the file src/index.ts. Performing a manipulation results in command injection. The attack is possible to be carried out remotely. The exploit has been released to the public and… | |
| Analizada | Media (6.9) | 0.36% | — | Filebrowser | 1/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the SPA index page in File Browser is vulnerable to Stored Cross-Site Scripting (XSS) via admin-controlled branding fields. An admin who sets branding.name… | |
| Analizada | Crítica (9) | 0.39% | — | Filebrowser | 1/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the EPUB preview function in File Browser is vulnerable to Stored Cross-Site Scripting (XSS). JavaScript embedded in a crafted EPUB file executes in the… | |
| Analizada | Crítica (9.8) | 0.66% | — | Filebrowser | 1/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the signupHandler in File Browser applies default user permissions via d.settings.Defaults.Apply(user), then strips only Admin. The Execute permission and… | |
| Analizada | Media (6.9) | 0.19% | — | M-files Server | 1/4/2026 | 17/6/2026 | Blind server-side request forgery (SSRF) vulnerability in legacy connection methods of document co-authoring features in M-Files Server before 26.3 allow an unauthenticated attacker to cause the server to send HTTP GET requests to arbitrary URLs. | |
| Aplazada | Media (4.3) | 0.26% | — | Cozmoslabs User Profile BuilderAI | 31/3/2026 | 25/7/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Insecure Direct Object Reference in versions up to, and including, 3.15.5 via the wppb_save_avatar_value() function due to missing validation on a user controlled key. This makes it… | |
| Analizada | Media (6.9) | 0.39% | — | Deciphered Filefield Paths | 26/3/2026 | 17/6/2026 | Information disclosure in the file URI processing of File (Field) Paths in Drupal File (Field) Paths 7.x prior to 7.1.3 on Drupal 7.x allows authenticated users to disclose other users’ private files via filename‑collision uploads. This can cause hook_node_insert() consumers (for example, email attachment modules) to… |