Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

92 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.31%—Filerise20/10/202517/6/2026
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to version 1.4.0, a business logic flaw in FileRise’s file/folder handling allows low-privilege users to perform unauthorized operations (view/delete/modify) on files created by other users. The root cause was…
AplazadaCrítica (9.4)3.4%💥 ExploitOpenfilerAI11/8/202516/6/2026
Openfiler v2.x contains a command injection vulnerability in the system.html page. The device parameter is used to instantiate a NetworkCard object, whose constructor in network.inc calls exec() with unsanitized input. An authenticated attacker can exploit this to execute arbitrary commands as the openfiler user. Due…
AplazadaMedia (6.5)0.22%—Activity-log.com Profiler - What Slowing Down Your WPAI16/7/202517/6/2026
Missing Authorization vulnerability in activity-log.com Profiler - What Slowing Down Your WP allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Profiler - What Slowing Down Your WP: from n/a through 1.0.0.
AplazadaCrítica (10)2.9%💥 ExploitRiverbed Steelcentral NetprofilerAIRiverbed Steelcentral NetexpressAI15/7/202517/6/2026
An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability in the '/api/common/1.0/login' endpoint can be exploited to create a new user account in the appliance database. This user can then…
AplazadaMedia (5.3)0.26%—THE Profiler What Slowing Down Your WPAI7/6/202517/6/2026
The Profiler – What Slowing Down Your WP plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the wpsd_plugin_control() function in all versions up to, and including, 1.0.0. This makes it possible for unauthenticated attackers to reactivate previously deactivated…
AplazadaBaja (2.1)0.47%—Julmud PhpdvdprofilerAIInvelos DvdprofilerAI12/5/202517/6/2026
julmud/phpDVDProfiler is an adoption of the defunct phpDVDProfiler project, which allows users to display on the web their DVD collections maintained with Invelos's DVDProfiler software. Starting in v_20230807 and prior to v_20250511, cross-site scripting in the search function. v_20250511 contains a patch for the…
AplazadaMedia (5.3)0.50%—Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI1/4/202517/6/2026
Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Retrieve Embedded Sensitive Data.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a through…
AplazadaMedia (4.3)0.28%—Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI27/3/202517/6/2026
Missing Authorization vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a…
AplazadaMedia (5.4)0.15%—Forge12 Interactive Gmbh F12-profilerAI24/2/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Forge12 Interactive GmbH F12-Profiler f12-profiler allows Cross Site Request Forgery.This issue affects F12-Profiler: from n/a through <= 1.3.9.
AplazadaMedia (5.5)0.36%—Django CMS Association Django FilerAI20/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type, Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in django CMS Association django Filer allows Input Data Manipulation, Stored XSS. This issue affects django Filer: from 3 before 3.3.
AnalizadaMedia (5.2)0.16%—Intel Oneapi Base ToolkitIntel System Bring-up ToolkitIntel Vtune Profiler13/11/202417/6/2026
Improper Input validation in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable denial of service via local access.
AnalizadaMedia (5.4)0.17%—Intel Oneapi Base ToolkitIntel System Bring-up ToolkitIntel Vtune Profiler13/11/202417/6/2026
Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.14%—Intel Oneapi Base ToolkitIntel Vtune Profiler14/8/202417/6/2026
Uncontrolled search path in some Intel(R) VTune(TM) Profiler software before versions 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (7.8)0.18%—Intel Vtune Profiler16/5/202417/6/2026
Uncontrolled search path element in some Intel(R) VTune(TM) Profiler software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaCrítica (9.8)1.6%💥 PoCDeskfiler29/2/202417/6/2026
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
AnalizadaAlta (7.8)0.16%—Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+1214/2/202417/6/2026
Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (6)0.17%—Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+1214/2/202417/6/2026
Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaCrítica (9.8)0.63%—Filerun22/12/202317/6/2026
FileRun 20220519 allows SQL Injection via the "dir" parameter in a /?module=users&section=cpanel&page=list request.
ModificadaMedia (6.1)0.44%—Openfiler11/12/202317/6/2026
A cross-site scripting (XSS) vulnerability in Openfiler ESA v2.99.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted payload into the nic parameter.
ModificadaMedia (4.3)0.48%—Afian Filerun6/12/202317/6/2026
A Broken Access Control issue in comments to uploaded files in Filerun through Update 20220202 allows attackers to delete comments on files uploaded by other users.
ModificadaMedia (5.4)0.43%—Afian Filerun6/12/202317/6/2026
A Stored XSS issue in shared files download terms in Filerun Update 20220202 allows attackers to inject JavaScript code that is executed when a user follows the crafted share link.
ModificadaAlta (7.3)0.17%—Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+2511/8/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.18%—Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+2511/8/202317/6/2026
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.3)0.43%—Jenkins TAG Profiler16/5/202317/6/2026
A missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission to reset profiler statistics.
ModificadaMedia (4.3)0.30%—Jenkins TAG Profiler16/5/202317/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers to reset profiler statistics.
Orbitaley — Vulnerabilidades