Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 1.1% | — | Skyjos Owlfiles | 13/1/2026 | 17/6/2026 | Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers to access system directories. Attackers can exploit the vulnerability by crafting GET requests with directory traversal sequences to access restricted system directories on the device. | |
| Analizada | Media (5.3) | 0.13% | — | Tox-dev Filelock | 10/1/2026 | 17/6/2026 | filelock is a platform-independent file lock for Python. Prior to version 3.20.3, a TOCTOU race condition vulnerability exists in the SoftFileLock implementation of the filelock package. An attacker with local filesystem access and permission to create symlinks can exploit a race condition between the permission… | |
| Analizada | Alta (7.5) | 0.62% | — | Sylphx Filesystem MCP | 7/1/2026 | 16/9/2026 | @sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerability in its "read_content" tool. This vulnerability arises from improper symlink handling in the path validation mechanism: the resolvePath… | |
| Analizada | Alta (7.5) | 0.63% | — | Efforthye Fast-filesystem-mcp | 7/1/2026 | 17/6/2026 | fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including fast_read_file. This vulnerability arises from improper path validation that fails to resolve symbolic links to their actual physical paths. The safePath and isPathAllowed functions use… | |
| Aplazada | Media (6.1) | 0.37% | — | Drag AND Drop Multiple File Upload Contact Form 7AI | 7/1/2026 | 7/10/2026 | The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to limited upload of files with a dangerous type in all versions up to, and including, 1.3.9.2. This is due to the plugin not blocking .phar and .svg files. This makes it possible for unauthenticated attackers to upload… | |
| Aplazada | Alta (7.7) | 0.27% | — | Najeebmedia Frontend File ManagerAI | 7/1/2026 | 7/10/2026 | The Frontend File Manager Plugin WordPress plugin before 23.5 did not validate a path parameter and ownership of the file, allowing any authenticated users, such as subscribers to delete arbitrary files on the server | |
| Aplazada | Alta (8.8) | 0.72% | — | Buddypress Xprofile Custom Field TypesAI | 6/1/2026 | 7/10/2026 | The BuddyPress Xprofile Custom Field Types plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the 'delete_field' function in all versions up to, and including, 1.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Crítica (9.1) | 0.33% | — | Meowapps Media File RenamerAI | 5/1/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Meow Apps Media File Renamer allows Using Malicious Files.This issue affects Media File Renamer: from n/a through 5.7.7. | |
| Analizada | Baja (2.1) | 0.30% | — | Campcodes School File Management System | 1/1/2026 | 7/10/2026 | A security vulnerability has been detected in campcodes School File Management System 1.0. The affected element is an unknown function of the file /save_file.php. The manipulation of the argument File leads to unrestricted upload. The attack may be initiated remotely. The exploit has been disclosed publicly and may be… | |
| Aplazada | Media (4.3) | 0.22% | — | Fahadmahmood Easy Upload Files During CheckoutAI | 31/12/2025 | 28/9/2026 | Missing Authorization vulnerability in Fahad Mahmood Easy Upload Files During Checkout easy-upload-files-during-checkout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Upload Files During Checkout: from n/a through <= 3.0.0. | |
| Analizada | Baja (2.1) | 0.33% | — | Fabian Student File Management System | 30/12/2025 | 7/10/2026 | A vulnerability has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /download.php of the component File Download Handler. The manipulation of the argument store_id leads to improper authorization. The attack is possible to be carried out remotely.… | |
| Analizada | Baja (2.1) | 0.35% | — | Fabian Student File Management System | 29/12/2025 | 7/10/2026 | A vulnerability was identified in code-projects Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /download.php. The manipulation of the argument istore_id leads to sql injection. The attack can be initiated remotely. The exploit is publicly available and might… | |
| Analizada | Baja (2) | 0.66% | — | Prasathmani Tiny File Manager | 28/12/2025 | 7/10/2026 | A flaw has been found in prasathmani TinyFileManager up to 2.6. Affected by this issue is some unknown functionality of the file tinyfilemanager.php. This manipulation of the argument fullpath causes path traversal. Remote exploitation of the attack is possible. The exploit has been published and may be used. The… | |
| Aplazada | Media (5.4) | 0.25% | — | Simplefilelist Simple File ListAI | 24/12/2025 | 7/10/2026 | Missing Authorization vulnerability in Mitchell Bennis Simple File List simple-file-list allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Simple File List: from n/a through <= 6.1.18. | |
| Analizada | Baja (2.1) | 0.34% | — | Fabian Student File Management System | 24/12/2025 | 17/6/2026 | A security vulnerability has been detected in code-projects Student File Management System 1.0. This affects an unknown part of the file /save_file.php. Such manipulation of the argument File leads to unrestricted upload. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. | |
| Aplazada | Alta (7.7) | 0.40% | — | Happyfiles PROAI | 21/12/2025 | 17/6/2026 | Missing Authorization vulnerability in HappyFiles HappyFiles Pro happyfiles-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HappyFiles Pro: from n/a through 1.8.1. | |
| Aplazada | Media (5.4) | 0.24% | — | Happyfiles PROAI | 21/12/2025 | 17/6/2026 | Missing Authorization vulnerability in HappyFiles HappyFiles Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HappyFiles Pro: from n/a through 1.8.1. | |
| Aplazada | Crítica (9.8) | 0.73% | — | File Uploader FOR WoocommerceAI | 20/12/2025 | 17/6/2026 | The File Uploader for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the callback function for the 'add-image-data' REST API endpoint in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to upload arbitrary… | |
| Analizada | Alta (8.5) | 0.85% | — | Filezilla-project Filezilla Client | 19/12/2025 | 17/6/2026 | FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the… | |
| Analizada | Alta (7.5) | 0.61% | — | Takes Tkfiles | 19/12/2025 | 17/6/2026 | The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system. | |
| Modificada | Media (5.6) | 0.38% | — | M-files Server | 19/12/2025 | 17/6/2026 | Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7 | |
| Aplazada | Alta (8.6) | 0.48% | — | M-filesAI | 19/12/2025 | 25/9/2026 | An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users. | |
| Analizada | Media (6.5) | 0.19% | — | Elastic Filebeat | 18/12/2025 | 17/6/2026 | Improper Validation of Specified Index, Position, or Offset in Input (CWE-1285) in Filebeat Syslog parser and the Libbeat Dissect processor can allow a user to trigger a Buffer Overflow (CAPEC-100) and cause a denial of service (panic/crash) of the Filebeat process via either a malformed Syslog message or a malicious… | |
| Analizada | Crítica (9.4) | 0.58% | — | Leefish File Thingie | 18/12/2025 | 17/6/2026 | File Thingie 2.5.7 contains an authenticated file upload vulnerability that allows remote attackers to upload malicious PHP zip archives to the web server. Attackers can create a custom PHP payload, upload and unzip it, and then execute arbitrary system commands through a crafted PHP script with a command parameter. | |
| Modificada | Media (5.3) | 0.31% | — | M-files Server | 18/12/2025 | 17/6/2026 | Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using Web Companion despite Print and Download Prevention module being enabled. |