Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.43% | — | Sindresorhus File-type | 16/3/2026 | 17/6/2026 | file-type detects the file type of a file, stream, or data. From 20.0.0 to 21.3.1, a crafted ZIP file can trigger excessive memory growth during type detection in file-type when using fileTypeFromBuffer(), fileTypeFromBlob(), or fileTypeFromFile(). The ZIP inflate output limit is enforced for stream-based detection,… | |
| Analizada | Media (5.4) | 0.21% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 13/3/2026 | 17/6/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 are vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended… | |
| Analizada | Alta (7.2) | 0.31% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 13/3/2026 | 17/6/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, and 6.2.1.0 through 6.2.1.1_1 are vulnerable to SQL injection. An administrative user could send specially crafted SQL statements, which could allow the attacker to view, add, modify, or delete information… | |
| Analizada | Media (5.4) | 0.21% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 13/3/2026 | 17/6/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended… | |
| Analizada | Media (6.5) | 0.24% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 13/3/2026 | 17/6/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1, and 6.2.2.0 could disclose sensitive host information to authenticated users in responses that could be used in further attacks against the system. | |
| Analizada | Media (5.4) | 0.21% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 13/3/2026 | 17/6/2026 | IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.1.0.0 through 6.1.2.7_2, and 6.2.0.0 through 6.2.0.5_1, 6.2.1.0 through 6.2.1.1_1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially… | |
| Analizada | Alta (7.5) | 0.13% | — | Lenovo Filez | 11/3/2026 | 19/8/2026 | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code. | |
| Analizada | Media (6) | 0.08% | — | Lenovo Filez | 11/3/2026 | 19/8/2026 | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application. | |
| Analizada | Baja (2.4) | 0.09% | — | Lenovo Filez | 11/3/2026 | 19/8/2026 | A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file. | |
| Aplazada | Alta (8.6) | 0.15% | — | Easy File Sharing WEB ServerAI | 11/3/2026 | 17/6/2026 | Easy File Sharing Web Server 7.2 contains a local structured exception handling buffer overflow vulnerability that allows local attackers to execute arbitrary code by creating a malicious username. Attackers can craft a username with a payload containing 4059 bytes of padding followed by a nseh value and seh pointer… | |
| Analizada | Crítica (9.3) | 0.90% | — | Leefish File Thingie | 11/3/2026 | 7/10/2026 | FileThingie 2.5.7 contains an arbitrary file upload vulnerability that allows attackers to upload malicious files by sending ZIP archives through the ft2.php endpoint. Attackers can upload ZIP files containing PHP shells, use the unzip functionality to extract them into accessible directories, and execute arbitrary… | |
| Analizada | Crítica (9.3) | 0.96% | — | Xiaomi Fileexplorer | 11/3/2026 | 14/7/2026 | MiCode FileExplorer contains an authentication bypass vulnerability in the embedded SwiFTP FTP server component that allows network attackers to log in without valid credentials. Attackers can send arbitrary username and password combinations to the PASS command handler, which unconditionally grants access and allows… | |
| Aplazada | Alta (8.1) | 0.50% | — | ProfilepressAI | 11/3/2026 | 17/6/2026 | The ProfilePress plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.16.11. This is due to missing ownership validation on the change_plan_sub_id parameter in the process_checkout() function. The ppress_process_checkout AJAX handler accepts a user-controlled… | |
| Analizada | Media (5.3) | 0.43% | — | Sindresorhus File-type | 10/3/2026 | 17/6/2026 | file-type detects the file type of a file, stream, or data. Prior to 21.3.1, a denial of service vulnerability exists in the ASF (WMV/WMA) file type detection parser. When parsing a crafted input where an ASF sub-header has a size field of zero, the parser enters an infinite loop. The payload value becomes negative… | |
| Analizada | Media (5.4) | 0.38% | — | Filebrowser | 10/3/2026 | 17/6/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /public/share/<hash> without context-aware escaping. The server uses text/template instead of… | |
| Analizada | Alta (7.5) | 0.54% | — | Filebrowser | 10/3/2026 | 17/6/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable. | |
| Aplazada | Media (4.3) | 0.13% | — | Metagauss ProfilegridAI | 7/3/2026 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 5.9.8.2. This is due to missing nonce validation on the membership request management page (approve and decline actions). This makes it possible for… | |
| Aplazada | Media (4.3) | 0.22% | — | Metagauss ProfilegridAI | 7/3/2026 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized message deletion due to a missing capability check on the pg_delete_msg() function in all versions up to, and including, 5.9.8.1. This is due to the function not verifying that the requesting user has permission… | |
| Aplazada | Media (4.3) | 0.16% | — | WP Frontend ProfileAI | 7/3/2026 | 17/6/2026 | The WP Frontend Profile plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.3.8. This is due to missing nonce validation on the 'update_action' function. This makes it possible for unauthenticated attackers to approve or reject user account registrations via a… | |
| Analizada | Alta (8.1) | 0.61% | — | Filebrowser | 5/3/2026 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.1, a broken access control vulnerability in the TUS protocol DELETE endpoint allows authenticated users with only Create permission to delete… | |
| Analizada | Alta (7.1) | 0.48% | — | Filebrowser | 5/3/2026 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.0, when a user creates a public share link for a directory, the withHashFile middleware in http/public.go uses filepath.Dir(link.Path) to compute the… | |
| Aplazada | Alta (8.1) | 0.95% | — | Drag AND Drop Multiple File Upload Contact Form 7AI | 5/3/2026 | 17/6/2026 | The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files… | |
| Aplazada | Media (6.6) | 0.28% | — | Hallo Welt Gmbh Extension NsfilerepoAIHallowelt BluespiceAI | 4/3/2026 | 17/6/2026 | Files or Directories Accessible to External Parties, Incorrect Permission Assignment for Critical Resource vulnerability in Hallo Welt! GmbH BlueSpice (Extension:NSFileRepo modules) allows Accessing Functionality Not Properly Constrained by ACLs, Bypassing Electronic Locks and Access Controls.This issue affects… | |
| Analizada | Alta (7.1) | 0.43% | — | Gtsteffaniak Filebrowser Quantum | 25/2/2026 | 17/6/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protected files, the recipient can completely bypass the password and still download the file. This happens because the API returns a direct download link in the details of the… | |
| Analizada | Media (6.1) | 0.22% | — | Claris Filemaker Server | 24/2/2026 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in a FileMaker WebDirect custom homepage could lead to unauthorized access and remote code execution. This vulnerability has been fully addressed in FileMaker Server 22.0.4 and FileMaker Server 21.1.7. |