Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.57% | — | FilebrowserAI | 13/8/2026 | 8/9/2026 | filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing… | |
| Aplazada | Alta (7.2) | 0.56% | — | FilebrowserAI | 13/8/2026 | 8/9/2026 | filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission to delete arbitrary files outside their scope. Attackers can swap an ancestor directory with a symlink during the cache TTL… | |
| Aplazada | Alta (8.6) | 0.48% | — | Filebrowser File BrowserAI | 13/8/2026 | 8/9/2026 | File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by operating on their allowed parent directory, defeating rule-based… | |
| Aplazada | Media (6.6) | 0.51% | — | Baseline-browser-mappingAI | 13/8/2026 | 9/9/2026 | baseline-browser-mapping 2.x before 2.11.0 calls process.exit() instead of throwing on invalid or conflicting input parameters, and can trigger immediate process termination, causing denial of service. | |
| Aplazada | Alta (7.6) | 0.43% | — | Filebrowser File BrowserAI | 13/8/2026 | 30/9/2026 | File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fresh ones via the… | |
| Analizada | Baja (0.5) | 0.13% | — | Paloaltonetworks Prisma Browser | 13/8/2026 | 9/9/2026 | An information disclosure vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a local attacker to view sensitive data. | |
| Analizada | Baja (0.5) | 0.22% | — | Paloaltonetworks Prisma Browser | 13/8/2026 | 9/9/2026 | A security bypass vulnerability in the Account Protection feature of Palo Alto Networks Prisma® Browser enables a user to bypass intended security controls. | |
| Pendiente de análisis | Alta (7.5) | 0.66% | — | BrowserslistAI | 11/8/2026 | 9/9/2026 | Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, index.js retains every distinct `(queries, context)` result in cache and every parseQueries() AST in parseCache without a size cap, TTL, or eviction, allowing an attacker who can influence… | |
| Pendiente de análisis | Alta (7.5) | 0.66% | — | BrowserslistAI | 11/8/2026 | 9/9/2026 | Browserslist is a configuration tool for sharing target browsers and Node.js versions between front-end tools. Prior to 4.28.7, normalizeStats() in node.js, reached unconditionally through getStat() and loadStat() on every browserslist() call, processes untrusted browserslist-stats.json, opts.stats, and CLI --stats… | |
| Aplazada | Alta (7.5) | 0.91% | — | Talpa HibrowserAI | 5/8/2026 | 9/9/2026 | Path Traversal in Download File Feature in com.talpa.hibrowser 2.23.1.1 on Android allows arbitrary file write via directory traversal sequences in the filename. | |
| Aplazada | Alta (7.7) | 0.46% | — | Filebrowser QuantumAI | 20/7/2026 | 23/7/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.4.3-beta, the `subtitlesHandler` endpoint (`GET /api/media/subtitles`) accepts two user-controlled query parameters: `path` and `name`, both of which are used in filesystem operations without sanitization, creating two independent… | |
| Aplazada | Media (5.3) | 0.47% | — | Filebrowser QuantumAI | 20/7/2026 | 22/7/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to version 1.3.2-beta, the `/api/auth/login` authentication endpoint does not execute in constant time. When a non-existent username is supplied, the server returns a `401`/`403` response almost immediately. When a valid username is provided,… | |
| Aplazada | Alta (8.7) | 0.45% | — | Filebrowser QuantumAI | 20/7/2026 | 22/7/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Versions prior to 1.3.2-stable and 1.4.1-beta may leak some sensitive info, such as source and path. Versions 1.3.2-stable and 1.4.1-beta fix the issue. No known workarounds are available. | |
| Aplazada | Media (6.8) | 0.39% | — | Filebrowser File BrowserAI | 15/7/2026 | 15/7/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as ..\..\evil.sh into the archive entry… | |
| Aplazada | Alta (8.1) | 0.55% | — | Filebrowser File BrowserAI | 15/7/2026 | 20/7/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new user scopes from usernames passed through cleanUsername() when Signup=true and CreateUserDir=true, but the many-to-one normalization can… | |
| Aplazada | Baja (3.1) | 0.32% | — | Filebrowser File BrowserAI | 15/7/2026 | 15/7/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser can leave a public directory share behind when the shared directory is deleted through a path with a trailing slash because the share cleanup path… | |
| Aplazada | Media (6.3) | 0.43% | — | ZEN BrowserAI | 15/7/2026 | 15/7/2026 | Zen is a firefox-based browser. Prior to 1.19.13b, Zen Browser did not provide a persistent, clearly visible security notification when a webpage entered fullscreen mode, allowing an attacker-controlled page to hide the real browser UI and origin information, imitate a trusted website UI, and combine with long-domain… | |
| Aplazada | Baja (2.3) | 0.32% | — | FilebrowserAI | 12/7/2026 | 13/7/2026 | filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same directory to expose new contents through the… | |
| Analizada | Baja (2) | 0.17% | — | Paloaltonetworks Prisma Browser | 9/7/2026 | 14/7/2026 | A local privilege escalation vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated administrator with access to the macOS local filesystem to perform actions on the device with root privileges. This issue only affects Prisma® Browser on macOS. | |
| Aplazada | Media (6.3) | 0.38% | — | Filebrowser File BrowserAI | 8/7/2026 | 8/7/2026 | File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user with Create and Modify permissions to create attacker-controlled files outside the… | |
| Aplazada | Alta (8.2) | 0.49% | — | Filebrowser File BrowserAI | 25/6/2026 | 26/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.16, a scoped, non-admin File Browser user holding only the Create permission can delete arbitrary files outside their scope (other tenants' data, and the application's… | |
| Aplazada | Alta (7.2) | 0.45% | — | FilebrowserAI | 25/6/2026 | 26/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, a low-privileged authenticated user of filebrowser (with create + delete permissions in their own isolated scope) can silently destroy share-link records belonging… | |
| Aplazada | Alta (8.4) | 0.18% | — | Filebrowser File BrowserAI | 25/6/2026 | 25/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.7, `POST /api/share/<path>` accepts an authenticated request for an arbitrary path and stores a public share record without checking whether the target file currently… | |
| Aplazada | Alta (7.5) | 0.50% | — | Filebrowser File BrowserAI | 25/6/2026 | 25/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.14, it does not stop the HTTP file handlers from following symbolic links before they open, serve, write, share, or list a file. As a result, a scoped user — and in… | |
| Aplazada | Media (6.8) | 0.19% | — | FilebrowserAI | 25/6/2026 | 25/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, filebrowser builds the download-as-zip / download-as-tar archive entry names with filepath.ToSlash, which on a Linux host is a no-op for backslashes (\ is only a… |