Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.39% | — | Simplefilelist Simple File ListAI | 20/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Path Traversal.This issue affects Simple File List: from n/a through <= 6.1.15. | |
| Aplazada | Alta (7.5) | 0.38% | — | Vanquish Upload Files AnywhereAI | 20/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhere allows Path Traversal.This issue affects Upload Files Anywhere: from n/a through <= 2.8. | |
| Aplazada | Alta (8.6) | 0.39% | — | Vanquish Upload Files AnywhereAI | 20/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhere allows Path Traversal.This issue affects Upload Files Anywhere: from n/a through <= 2.8. | |
| Aplazada | Alta (7.7) | 0.36% | — | Murtaza Bhurgri WOO File DropzoneAI | 20/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Murtaza Bhurgri Woo File Dropzone woo-file-dropzone allows Path Traversal.This issue affects Woo File Dropzone: from n/a through <= 1.1.7. | |
| Aplazada | Alta (7.3) | 0.59% | 💥 Exploit | Kapasias LottiefilesAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in LottieFiles LottieFiles lottiefiles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LottieFiles: from n/a through <= 3.0.0. | |
| Aplazada | Media (5.3) | 0.27% | — | Anssi Laitila Shared FilesAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.19. | |
| Aplazada | Media (5.3) | 0.34% | — | Nmedia Frontend File ManagerAI | 19/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.5. | |
| Aplazada | Media (6.7) | 0.20% | — | FileflowsAI | 19/2/2026 | 17/6/2026 | Fileflows versions before 25.05.2 are affected by an authenticated SQL injection vulnerability in the library-file search function. Successful exploitation requires the system to use MySQL as the underlying database and could result in privilege escalation or data exfiltration. | |
| Aplazada | Alta (8.7) | 0.41% | — | FileoptimizerAI | 18/2/2026 | 17/6/2026 | FileOptimizer 14.00.2524 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the FileOptimizer32.ini configuration file. Attackers can overwrite the TempDirectory parameter with a 5000-character buffer to cause the application to crash when opening options. | |
| Aplazada | Media (6.4) | 0.19% | — | FilestackAI | 18/2/2026 | 17/6/2026 | The Filestack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'filepicker' shortcode in all versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Analizada | Media (4.9) | 0.32% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 17/2/2026 | 17/6/2026 | IBM Sterling B2B Integrator versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1, and IBM Sterling File Gateway versions 6.1.0.0 through 6.1.2.7_2, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 through 6.2.1.1 may expose sensitive information to a remote privileged attacker due to the… | |
| Aplazada | Media (5.8) | 0.70% | 💥 Exploit | Najeebmedia Frontend File ManagerAI | 17/2/2026 | 17/6/2026 | The Frontend File Manager Plugin WordPress plugin through 23.5 allows unauthenticated users to send emails through the site without any security checks. This lets attackers use the WordPress site as an open relay for spam or phishing emails to anyone. Attackers can also guess file IDs to access and share uploaded… | |
| Analizada | Alta (8.7) | 5.2% | ⚠ Explotación activa | Soliton Filezen | 13/2/2026 | 17/6/2026 | FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command. | |
| Analizada | Baja (1.3) | 0.57% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect File Station 6. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later | |
| Analizada | Baja (1.3) | 0.44% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and later | |
| Analizada | Baja (1.3) | 0.35% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and… | |
| Analizada | Baja (1.3) | 0.36% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect File Station 5. If a local attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and… | |
| Analizada | Baja (1.3) | 0.57% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | An uncontrolled resource consumption vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5190 and… | |
| Analizada | Media (5.2) | 0.64% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later | |
| Analizada | Baja (1.3) | 0.54% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | A weak authentication vulnerability has been reported to affect File Station 5. The remote attackers can then exploit the vulnerability to gain sensitive information. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and later | |
| Analizada | Baja (1.1) | 0.70% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | An improper neutralization of directives in statically saved code ('Static Code Injection') vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to access restricted data / files. We have already fixed the vulnerability in the… | |
| Analizada | Media (4.9) | 0.36% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | An out-of-bounds read vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5068 and later | |
| Analizada | Baja (1.2) | 0.53% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5166 and… | |
| Analizada | Media (4.8) | 0.46% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5068… | |
| Analizada | Baja (3.6) | 0.43% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already… |