Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.31% | — | Geeks4change File Access FIX | 26/3/2026 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated): from 0.0.0 before 1.2.0. | |
| Analizada | Media (5.3) | 0.31% | — | Geeks4change File Access FIX | 26/3/2026 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal File Access Fix (deprecated) allows Forceful Browsing.This issue affects File Access Fix (deprecated): from 0.0.0 before 1.2.0. | |
| Analizada | Media (4.3) | 0.32% | — | Filerise | 26/3/2026 | 17/6/2026 | FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. In versiosn 2.3.7 through 3.10.0, the file snippet endpoint `/api/file/snippet.php` allows an authenticated user with only `read_own` access to a folder to retrieve snippet content from files uploaded by other users… | |
| Aplazada | Media (6.8) | 0.43% | — | Shared FilesAI | 26/3/2026 | 17/6/2026 | The Shared Files WordPress plugin before 1.7.58 allows users with a role as low as Contributor to download any file on the web server (such as wp-config.php) via a path traversal vector | |
| Modificada | Alta (8.7) | 0.46% | — | Seafile Server | 25/3/2026 | 17/6/2026 | Multiple Stored XSS vulnerabilities exist in Seafile Server version 13.0.15,13.0.16-pro,12.0.14 and prior and fixed in 13.0.17, 13.0.17-pro, and 12.0.20-pro, via the Seadoc (sdoc) editor. The application fails to properly sanitize WebSocket messages regarding document structure updates. This allows authenticated… | |
| Aplazada | Media (6.5) | 0.16% | — | Metagauss ProfilegridAI | 25/3/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Stored XSS.This issue affects ProfileGrid : from n/a through <= 5.9.8.1. | |
| Aplazada | Alta (7.5) | 0.43% | — | Snowray Software File Uploader FOR WoocommerceAI | 25/3/2026 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in Snowray Software File Uploader for WooCommerce file-uploader-for-woocommerce allows Path Traversal.This issue affects File Uploader for WooCommerce: from n/a through <= 1.0.4. | |
| Aplazada | Media (6.8) | 0.35% | — | Add-ons.org Products-file-upload-for-woocommerceAI | 25/3/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Product File Upload for WooCommerce products-file-upload-for-woocommerce allows Path Traversal.This issue affects Product File Upload for WooCommerce: from n/a through <= 2.2.4. | |
| Analizada | Alta (7.1) | 0.38% | — | Filerise | 24/3/2026 | 17/6/2026 | FileRise is a self-hosted web file manager / WebDAV server. Prior to version 3.10.0, a broken access control issue in FileRise's ONLYOFFICE integration allows an authenticated user with read-only access to obtain a signed save callbackUrl for a file and then directly forge the ONLYOFFICE save callback to overwrite… | |
| Analizada | Alta (8.1) | 0.61% | — | Filerise | 24/3/2026 | 17/6/2026 | FileRise is a self-hosted web file manager / WebDAV server. From version 1.0.1 to before version 3.10.0, the resumableIdentifier parameter in the Resumable.js chunked upload handler (UploadModel::handleUpload()) is concatenated directly into filesystem paths without any sanitization. An authenticated user with upload… | |
| Analizada | Media (6.9) | 0.56% | — | Dulldusk Phpfilemanager | 24/3/2026 | 17/6/2026 | phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd… | |
| Aplazada | Media (4.3) | 0.14% | — | ADD Google Social Profiles TO Knowledge Graph BOXAI | 21/3/2026 | 17/6/2026 | The Add Google Social Profiles to Knowledge Graph Box plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.0. This is due to missing nonce validation on the settings update functionality. This makes it possible for unauthenticated attackers to update the plugin's… | |
| Analizada | Media (4.3) | 0.64% | — | Leefish File Thingie | 20/3/2026 | 17/6/2026 | File Thingie 2.5.7 is vulnerable to Directory Traversal. A malicious user can leverage the "create folder from url" functionality of the application to read arbitrary files on the target system. | |
| Analizada | Media (6.5) | 0.24% | — | Leefish File Thingie | 20/3/2026 | 17/6/2026 | File Thingie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "upload file" functionality to upload a file with a crafted file name used to trigger a Javascript payload. | |
| Analizada | Media (6.5) | 0.24% | — | Leefish File Thingie | 20/3/2026 | 17/6/2026 | File Thinghie 2.5.7 is vulnerable to Cross Site Scripting (XSS). A malicious user can leverage the "dir" parameter of the GET request to invoke arbitrary javascript code. | |
| Analizada | Alta (7.5) | 0.25% | — | Filerise | 20/3/2026 | 17/6/2026 | FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.9.0, a hardcoded default encryption key (default_please_change_this_key) is used for all cryptographic operations — HMAC token generation, AES config encryption, and session tokens — allowing any unauthenticated attacker to forge upload… | |
| Analizada | Alta (8.8) | 0.72% | — | Filerise | 20/3/2026 | 17/6/2026 | FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, the WebDAV upload endpoint accepts any file extension including .phtml, .php5, .htaccess, and other server-side executable types, bypassing the filename validation enforced by the regular upload path. In non-default deployments… | |
| Analizada | Media (4.8) | 0.33% | — | Filerise | 20/3/2026 | 17/6/2026 | FileRise is a self-hosted web file manager / WebDAV server. In versions prior to 3.8.0, a missing-authentication vulnerability in the deleteShareLink endpoint allows any unauthenticated user to delete arbitrary file share links by providing only the share token, causing denial of service to shared file access. The… | |
| Analizada | Media (6.5) | 0.46% | — | Filebrowser | 20/3/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.0 and below contain a permission enforcement bypass which allows users who are denied download privileges (perm.download = false) but granted share privileges… | |
| Analizada | Crítica (10) | 0.69% | — | Filebrowser | 20/3/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, any unauthenticated visitor can register a full administrator account when self-registration (signup = true) is enabled and the default user permissions… | |
| Modificada | Media (5.3) | 2.2% | — | Filebrowser | 20/3/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions on the 2.x branch prior to 2.33.8, the TUS resumable upload handler parses the Upload-Length header as a signed 64-bit integer without validating that the value is… | |
| Analizada | Media (6.5) | 0.44% | — | Filebrowser | 20/3/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.2 and below are vulnerable to Path Traversal through the resourcePatchHandler (http/resource.go). The destination path in resourcePatchHandler is validated against… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Cozmoslabs Profile Builder PROAI | 19/3/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Cozmoslabs Profile Builder Pro allows Blind SQL Injection.This issue affects Profile Builder Pro: from n/a before 3.14.0. | |
| Analizada | Media (6.5) | 0.18% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 17/3/2026 | 17/6/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 allows a remote unauthenticated attacker to view and delete the partners of a community and to delete the communities. | |
| Analizada | Alta (7.5) | 0.34% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 17/3/2026 | 17/6/2026 | IBM Sterling B2B Integrator and and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could allow an unauthenticated attacker to send a specially crafted request that causes the application to crash. |