Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.20% | — | Tox-dev Filelock | 16/12/2025 | 17/6/2026 | filelock is a platform-independent file lock for Python. In versions prior to 3.20.1, a Time-of-Check-Time-of-Use (TOCTOU) race condition allows local attackers to corrupt or truncate arbitrary user files through symlink attacks. The vulnerability exists in both Unix and Windows lock file creation where filelock… | |
| Analizada | Media (5.4) | 0.17% | — | Claris Filemaker Server | 16/12/2025 | 17/6/2026 | An authorization bypass vulnerability in FileMaker Server Admin Console allowed administrator roles with minimal privileges to access administrative features such as viewing license details and downloading application logs. This vulnerability has been fully addressed in FileMaker Server 22.0.4. | |
| Analizada | Crítica (9.8) | 1.0% | 💥 PoC | Claris Filemaker Server | 16/12/2025 | 17/6/2026 | Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an attacker could potentially achieve… | |
| Analizada | Media (5.3) | 0.23% | — | Claris Filemaker Server | 16/12/2025 | 17/6/2026 | To enhance security, the FileMaker Server 22.0.4 installer now includes an option to disable IIS short filename enumeration by setting NtfsDisable8dot3NameCreation in the Windows registry. This prevents attackers from using the tilde character to discover hidden files and directories. This vulnerability has been fully… | |
| Analizada | Media (5.4) | 0.27% | 💥 PoC | Filerise | 16/12/2025 | 17/6/2026 | FileRise is a self-hosted web file manager / WebDAV server. Versions prior to 2.7.1 are vulnerable to Stored Cross-Site Scripting (XSS) due to unsafe handling of browser-renderable user uploads when served through the sharing and download endpoints. An attacker who can get a crafted SVG (primary) or HTML (secondary)… | |
| Analizada | Crítica (9.3) | 0.62% | — | Dulldusk Phpfilemanager | 16/12/2025 | 17/6/2026 | phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server. | |
| Aplazada | Media (5.4) | 0.25% | — | Ninjateam Filebird PROAI | 16/12/2025 | 17/6/2026 | Missing Authorization vulnerability in NinjaTeam FileBird Pro filebird-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects FileBird Pro: from n/a through <= 6.5.1. | |
| Analizada | Media (5.3) | 0.28% | — | Ateme Titan File | 15/12/2025 | 17/6/2026 | Ateme TITAN File 3.9.12.4 contains an authenticated server-side request forgery vulnerability in the job callback URL parameter that allows attackers to bypass network restrictions. Attackers can exploit the unvalidated parameter to initiate file, service, and network enumeration by forcing the application to make… | |
| Aplazada | Media (4.3) | 0.23% | — | Ninjateam FilebirdAI | 15/12/2025 | 7/10/2026 | The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to missing authorization in all versions up to, and including, 6.5.1 via the "ConvertController::insertToNewTable" function due to missing validation on a user controlled key. This makes it possible for authenticated… | |
| Analizada | Baja (1.9) | 0.24% | — | Fabian Student File Management System | 14/12/2025 | 7/10/2026 | A vulnerability was determined in code-projects Student File Management System 1.0. This vulnerability affects unknown code of the file /admin/update_student.php. Executing manipulation can lead to cross site scripting. The attack may be launched remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Baja (1.9) | 0.23% | — | Fabian Student File Management System | 14/12/2025 | 7/10/2026 | A vulnerability was found in code-projects Student File Management System 1.0. This affects an unknown part of the file /admin/update_user.php of the component Update User Page. Performing manipulation results in cross site scripting. The attack may be initiated remotely. The exploit has been made public and could be… | |
| Analizada | Media (5.5) | 0.41% | — | Fabian Student File Management System | 14/12/2025 | 7/10/2026 | A security flaw has been discovered in code-projects Student File Management System 1.0. This impacts an unknown function of the file /admin/delete_student.php. The manipulation of the argument stud_id results in sql injection. The attack may be performed from remote. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.41% | — | Fabian Student File Management System | 14/12/2025 | 7/10/2026 | A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown function of the file /admin/delete_user.php. The manipulation of the argument user_id leads to sql injection. The attack is possible to be carried out remotely. The exploit is publicly available and might be… | |
| Analizada | Media (5.5) | 0.41% | — | Fabian Student File Management System | 14/12/2025 | 7/10/2026 | A flaw has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /admin/save_student.php. Executing manipulation of the argument stud_no can lead to sql injection. The attack may be launched remotely. The exploit has been published and may be used. | |
| Analizada | Media (5.5) | 0.41% | — | Fabian Student File Management System | 13/12/2025 | 7/10/2026 | A weakness has been identified in code-projects Student File Management System 1.0. This issue affects some unknown processing of the file /admin/update_student.php. This manipulation of the argument stud_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to… | |
| Analizada | Media (5.5) | 0.41% | — | Fabian Student File Management System | 13/12/2025 | 7/10/2026 | A security flaw has been discovered in code-projects Student File Management System 1.0. This vulnerability affects unknown code of the file /admin/save_user.php. The manipulation of the argument firstname results in sql injection. The attack can be executed remotely. The exploit has been released to the public and… | |
| Analizada | Media (5.5) | 0.39% | — | Fabian Student File Management System | 13/12/2025 | 7/10/2026 | A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown part of the file /admin/update_user.php. The manipulation of the argument user_id leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used. | |
| Analizada | Media (5.5) | 0.52% | — | Fabian Student File Management System | 13/12/2025 | 7/10/2026 | A vulnerability was determined in code-projects Student File Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/login_query.php. Executing manipulation of the argument Username can lead to sql injection. The attack may be launched remotely. The exploit has been publicly… | |
| Analizada | Media (5.5) | 0.52% | — | Fabian Student File Management System | 13/12/2025 | 7/10/2026 | A vulnerability was found in code-projects Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login_query.php. Performing manipulation of the argument stud_no results in sql injection. The attack may be initiated remotely. The exploit has been made public and… | |
| Analizada | Media (6.5) | 0.57% | — | A1apps Office App-edit Word, PDF File | 10/12/2025 | 17/6/2026 | A lack of security checks in the file import process of RHOPHI Analytics LLP Office App-Edit Word v6.4.1 allows attackers to execute a directory traversal. | |
| Aplazada | Media (4.3) | 0.13% | — | Wpmediadownload Media Library File DownloadAI | 9/12/2025 | 7/10/2026 | Cross-Site Request Forgery (CSRF) vulnerability in wpmediadownload Media Library File Download media-download allows Cross Site Request Forgery.This issue affects Media Library File Download: from n/a through <= 1.4. | |
| Aplazada | Media (5.4) | 0.48% | — | ProfilepressAI | 9/12/2025 | 7/10/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.7 due to insufficient input sanitization on the `type` parameter in the form preview… | |
| Analizada | Media (5.5) | 0.39% | — | Code-projects Employee Profile Management System | 9/12/2025 | 7/10/2026 | A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_personnel.php. The manipulation of the argument per_id results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. | |
| Analizada | Baja (2.1) | 0.31% | — | Carmelogarcia Employee Profile Management System | 8/12/2025 | 7/10/2026 | A flaw has been found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file /print_personnel_report.php. This manipulation of the argument per_id causes sql injection. The attack may be initiated remotely. The exploit has been published and may be used. | |
| Modificada | Media (5.5) | 0.39% | — | Campcodes School File Management System | 8/12/2025 | 7/10/2026 | A weakness has been identified in Campcodes School File Management System 1.0. This impacts an unknown function of the file /update_query.php. This manipulation of the argument stud_id causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for… |