Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.6) | 0.43% | — | Qnap File Station | 11/2/2026 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already… | |
| Aplazada | Media (5.4) | 0.14% | — | Intel Vtune ProfilerAIIntel Oneapi Base ToolkitAI | 10/2/2026 | 17/6/2026 | Uncontrolled search path in some software installer for some VTune(TM) Profiler software and Intel(R) oneAPI Base Toolkits before version 2025.0. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable… | |
| Analizada | Alta (8.1) | 0.61% | 💥 PoC | Filebrowser | 9/2/2026 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an authenticated user can bypass the application's "Disallow" file path rules by modifying the request URL. By adding multiple slashes (e.g., //private/)… | |
| Analizada | Media (5.4) | 0.45% | — | Filebrowser | 9/2/2026 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, a case-sensitivity flaw in the password validation logic allows any authenticated user to change their password (or an admin to change any user's password)… | |
| Analizada | Alta (7.5) | 1.7% | 💥 Exploit | Filerise | 9/2/2026 | 17/6/2026 | FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 3.3.0, the application contains an unauthenticated file read vulnerability due to the lack of access control on the /uploads directory. Files uploaded to this directory can be accessed directly by any user who knows or can guess the file… | |
| Analizada | Media (5.4) | 0.24% | — | Filerise | 9/2/2026 | 17/6/2026 | FileRise is a self-hosted web file manager / WebDAV server. Prior to 3.3.0, an HTML Injection vulnerability allows an authenticated user to modify the DOM and add e.g. form elements that call certain endpoints or link elements that redirect the user on active interaction. This vulnerability is fixed in 3.3.0. | |
| Aplazada | Media (5.3) | 0.36% | — | Metagauss ProfilegridAI | 5/2/2026 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.9.7.2 via the 'pm_upload_image' and 'pm_upload_cover_image' AJAX actions. This is due to the update_user_meta() function being called outside of the… | |
| Aplazada | Media (4.3) | 0.32% | — | Metagauss ProfilegridAI | 5/2/2026 | 17/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to unauthorized user suspension due to a missing capability check on the pm_deactivate_user_from_group() function in all versions up to, and including, 5.9.7.2. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.1) | 0.43% | — | FilettoAI | 3/2/2026 | 17/6/2026 | Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attackers can send an oversized FEAT command with 11,008 bytes of repeated characters to trigger a buffer overflow and terminate the FTP service. | |
| Analizada | Media (4.3) | 0.28% | — | Prasathmani Tiny File Manager | 3/2/2026 | 17/6/2026 | Tiny File Manager through 2.6 contains a server-side request forgery (SSRF) vulnerability in the URL upload feature. Due to insufficient validation of user-supplied URLs, an attacker can send crafted requests to localhost by using http://www.127.0.0.1.example.com/ or a similarly constructed domain name. This may lead… | |
| Aplazada | Crítica (9.8) | 0.54% | 💥 PoC | User Profile BuilderAI | 2/2/2026 | 17/6/2026 | The User Profile Builder WordPress plugin before 3.15.2 does not have a proper password reset process, allowing a few unauthenticated requests to reset the password of any user by knowing their username, such as administrator ones, and therefore gain access to their account | |
| Aplazada | Media (5.1) | 0.34% | — | Wifi File TransferAI | 1/2/2026 | 17/6/2026 | WiFi File Transfer 1.0.8 contains a persistent cross-site scripting vulnerability that allows remote attackers to inject malicious script codes through file and folder names. Attackers can exploit the web server's input validation weakness to execute arbitrary JavaScript when users preview infected file paths,… | |
| Aplazada | Alta (8.7) | 0.48% | — | Ajax File BrowserAI | 28/1/2026 | 17/6/2026 | PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary web server locations. Attackers can upload a .txt webshell, rename it to .php, and move it to accessible directories using double-encoded path traversal techniques. | |
| Aplazada | Media (4.8) | 0.24% | — | Ajax File BrowserAI | 28/1/2026 | 17/6/2026 | PDW File Browser version 1.3 contains stored and reflected cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through file rename and path parameters. Attackers can craft malicious URLs or rename files with XSS payloads to execute arbitrary JavaScript in victims'… | |
| Aplazada | Alta (7.5) | 0.34% | — | Najeebmedia Frontend File ManagerAI | 28/1/2026 | 17/6/2026 | The Frontend File Manager Plugin for WordPress is vulnerable to unauthorized file sharing due to a missing capability check on the 'wpfm_send_file_in_email' AJAX action in all versions up to, and including, 23.5. This makes it possible for unauthenticated attackers to share arbitrary uploaded files via email by… | |
| Aplazada | Media (6.9) | 0.29% | — | Yetishare File Hosting ScriptAI | 23/1/2026 | 17/6/2026 | YetiShare File Hosting Script 5.1.0 contains a server-side request forgery vulnerability that allows attackers to read local system files through the remote file upload feature. Attackers can exploit the url parameter in the url_upload_handler endpoint to access sensitive files like /etc/passwd by using file:///… | |
| Aplazada | Media (5.3) | 0.22% | — | Imaginate-solutions File Uploads Addon FOR WoocommerceAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Imaginate Solutions File Uploads Addon for WooCommerce woo-addon-uploads allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects File Uploads Addon for WooCommerce: from n/a through <= 1.7.3. | |
| Aplazada | Media (4.3) | 0.21% | — | Sully Media Library File SizeAI | 23/1/2026 | 17/6/2026 | Missing Authorization vulnerability in Sully Media Library File Size media-library-file-size allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Media Library File Size: from n/a through <= 1.6.7. | |
| Modificada | Media (6.9) | 0.41% | — | M-files Server | 21/1/2026 | 17/6/2026 | Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vault administrator privileges to crash the M-Files Server process by calling a vulnerable API endpoint. | |
| Analizada | Media (5.3) | 0.48% | — | Filebrowser | 19/1/2026 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and can be used to upload, delete, preview, rename, and edit files. Prior to version 2.55.0, the JSONAuth. Auth function contains a logic flaw that allows unauthenticated attackers to enumerate valid usernames by measuring the response time… | |
| Aplazada | Crítica (9.3) | 0.72% | — | Omni Secure FilesAI | 16/1/2026 | 16/6/2026 | Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-content/plugins/omni-secure-files/plupload/examples/upload.php handler allows unauthenticated uploads without enforcing safe file type restrictions, enabling an attacker to… | |
| Analizada | Crítica (9.8) | 0.64% | — | Livewire-filemanager Filemanager | 16/1/2026 | 17/6/2026 | Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel… | |
| Analizada | Media (5.3) | 0.36% | — | Libsndfile Project Libsndfile | 14/1/2026 | 17/6/2026 | Libsndfile <=1.2.2 contains a memory leak vulnerability in the mpeg_l3_encoder_init() function within the mpeg_l3_encode.c file. | |
| Aplazada | Media (5.3) | 0.94% | 💥 Exploit | Lottiefiles Lottie Block FOR GutenbergAI | 14/1/2026 | 17/6/2026 | The LottieFiles – Lottie block for Gutenberg plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.0 via the `/wp-json/lottiefiles/v1/settings/` REST API endpoint. This makes it possible for unauthenticated attackers to retrieve the site owner's LottieFiles.com… | |
| Modificada | Media (5.1) | 0.29% | — | Skyjos Owlfiles | 13/1/2026 | 17/6/2026 | Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the path parameter in HTTP server endpoints. Attackers can craft URLs targeting the download and list endpoints with embedded script tags to execute arbitrary JavaScript in users'… |