Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.59% | — | Backpackforlaravel Filemanager | 13/11/2024 | 17/6/2026 | FileManager provides a Backpack admin interface for files and folder. Prior to 3.0.9, deserialization of untrusted data from the mimes parameter could lead to remote code execution. This vulnerability is fixed in 3.0.9. | |
| Analizada | Media (5.4) | 0.34% | — | Filemanagerpro File Manager | 16/10/2024 | 17/6/2026 | The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due to a lack of proper checks on allowed file types. This makes it possible for unauthenticated attackers, with permissions granted by an administrator, to upload .css and .js… | |
| Analizada | Alta (8.8) | 0.65% | — | Filemanagerpro File Manager | 16/10/2024 | 17/6/2026 | The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers, if granted access to the… | |
| Analizada | Alta (8.8) | 0.25% | — | Filemanagerpro File Manager | 16/10/2024 | 17/6/2026 | The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to missing or incorrect nonce validation on the 'mk_file_folder_manager' ajax action. This makes it possible for unauthenticated attackers to upload arbitrary files via a… | |
| Analizada | Crítica (9.8) | 0.81% | — | Filemanagerpro File Manager | 16/10/2024 | 17/6/2026 | The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for… | |
| Analizada | Media (5.4) | 0.38% | — | Advancedfilemanager Advanced File Manager | 26/9/2024 | 17/6/2026 | Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cannot upload .css and .js files to arbitrary directories. This makes it possible for authenticated attackers, with Subscriber-level access and… | |
| Analizada | Alta (7.2) | 0.88% | — | Advancedfilemanager Advanced File Manager | 26/9/2024 | 17/6/2026 | The Advanced File Manager plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 5.2.8 via the 'fma_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the… | |
| Analizada | Alta (8.8) | 0.95% | — | Advancedfilemanager Advanced File Manager | 26/9/2024 | 17/6/2026 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.8. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an Administrator, to upload a… | |
| Analizada | Alta (8.8) | 0.85% | — | Filemanagerpro.io File Manager PRO | 23/8/2024 | 17/6/2026 | The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager AJAX action in all versions up to, and including, 8.3.7. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Modificada | Alta (8.8) | 0.83% | — | Advancedfilemanager File Manager Advanced Shortcode | 10/7/2024 | 17/6/2026 | The Advanced File Manager Shortcodes plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 2.5.3. This makes it possible for authenticated attackers with contributor access or above to upload arbitrary files on the affected site's server which may make remote code execution… | |
| Modificada | Alta (7.5) | 0.56% | — | Advancedfilemanager Advanced File Manager | 29/6/2024 | 17/6/2026 | The Advanced File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 5.2.4 via the 'fma_local_file_system' function. This makes it possible for unauthenticated attackers to extract sensitive data including backups or other sensitive information if the… | |
| Modificada | Media (6.1) | 0.25% | — | Dulldusk Phpfilemanager | 6/6/2024 | 17/6/2026 | Vulnerability in Dulldusk's PHP File Manager affecting version 1.7.8. This vulnerability consists of an XSS through the fm_current_dir parameter of index.php. An attacker could send a specially crafted JavaScript payload to an authenticated user and partially hijack their browser session. | |
| Modificada | Media (6.8) | 0.91% | — | Filemanagerpro File Manager | 9/4/2024 | 17/6/2026 | The File Manager plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 7.2.5 via the fm_download_backup function. This makes it possible for authenticated attackers, with administrator access and above, to read the contents of arbitrary zip files on the server, which can… | |
| Modificada | Alta (8.8) | 11% | — | Filemanagerpro File Manager | 21/3/2024 | 17/6/2026 | The File Manager plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 7.2.4. This is due to missing or incorrect nonce validation on the wp_file_manager page that includes files through the 'lang' parameter. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (6.1) | 0.47% | — | Filemanagerpro.io File Manager PRO | 13/3/2024 | 17/6/2026 | The File Manager Pro plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'tb' parameter in all versions up to, and including, 8.3.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Alta (7.5) | 1.0% | — | Filemanagerpro File Manager | 5/2/2024 | 17/6/2026 | The File Manager plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 7.2.1 due to insufficient randomness in the backup filenames, which use a timestamp plus 4 random digits. This makes it possible for unauthenticated attackers, to extract sensitive data including… | |
| Modificada | Alta (8.8) | 16% | — | Filemanagerpro File Manager | 5/2/2024 | 17/6/2026 | The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function. This makes it possible for authenticated attackers, with subscriber access and above, to execute code on the server. Version 8.3.5… | |
| Modificada | Media (4.9) | 0.62% | — | Advancedfilemanager Advanced File Manager | 4/9/2023 | 17/6/2026 | The Advanced File Manager WordPress plugin before 5.1.1 does not adequately authorize its usage on multisite installations, allowing site admin users to list and read arbitrary files and folders on the server. | |
| Modificada | Crítica (9.8) | 2.3% | — | Tecrail Responsive Filemanager | 28/6/2023 | 17/6/2026 | In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE. | |
| Modificada | Crítica (9.8) | 40% | — | Advancedfilemanager File Manager Advanced Shortcode | 27/6/2023 | 17/6/2026 | The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users. | |
| Modificada | Media (5.4) | 0.49% | — | Responsivefilemanager | 9/5/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Trippo ResponsiveFilemanager v.9.14.0 and before allows a remote attacker to execute arbitrary code via the sort_by parameter in the dialog.php file. | |
| Modificada | Alta (8.8) | 8.6% | — | Tecrail Responsive Filemanager | 2/2/2023 | 17/6/2026 | An issue in Tecrail Responsive FileManager v9.9.5 and below allows attackers to bypass the file extension check mechanism and upload a crafted PHP file, leading to arbitrary code execution. | |
| Modificada | Media (6.5) | 5.2% | — | Unisharp Laravel Filemanager | 14/9/2022 | 17/6/2026 | UniSharp laravel-filemanager (aka Laravel Filemanager) before 2.6.4 allows download?working_dir=%2F.. directory traversal to read arbitrary files, as exploited in the wild in June 2022. This is related to league/flysystem before 2.0.0. | |
| Modificada | Crítica (9.8) | 1.0% | — | Tecrail Responsive Filemanager | 25/7/2022 | 17/6/2026 | A vulnerability was found in Tecrail Responsive Filemanger up to 9.10.x and classified as critical. The manipulation leads to path traversal. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 9.11.0 is able to address this issue. It is recommended… | |
| Modificada | Alta (8.8) | 1.8% | — | Unisharp Laravel-filemanager | 17/12/2021 | 17/6/2026 | This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following steps: 1. Install a package with a web Laravel application. 2. Navigate to the Upload window 3. Upload an… |