Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
62 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.66% | — | Maxfoundry Media Library Folders | 10/4/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Max Foundry Media Library Folders.This issue affects Media Library Folders: from n/a through 8.1.8. | |
| Modificada | Alta (8.8) | 0.58% | — | Maxfoundry Media Library Folders | 29/3/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Max Foundry Media Library Folders.This issue affects Media Library Folders: from n/a through 8.1.7. | |
| Modificada | Alta (7.2) | 0.83% | — | Premio Folders | 20/12/2023 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Premio Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager.This issue affects Folders – Unlimited Folders to Organize Media Library Folder, Pages, Posts, File Manager: from n/a through 2.9.2. | |
| Modificada | Media (5.4) | 0.31% | — | Codedraft Mediabay - Wordpress Media Library Folders | 16/10/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in Codedrafty Mediabay – Media Library Folders plugin <= 1.6 versions. | |
| Modificada | Alta (7.2) | 1.6% | — | Miniorange Prevent Files / Folders Access | 25/9/2023 | 17/6/2026 | The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server. | |
| Modificada | Media (4.8) | 0.36% | — | Avirtum Ifolders | 25/9/2023 | 17/6/2026 | Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Avirtum iFolders plugin <= 1.5.0 versions. | |
| Modificada | Media (4.3) | 0.64% | — | Jenkins Folders | 16/8/2023 | 17/6/2026 | Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier displays an error message that includes an absolute path of a log file when attempting to access the Scan Organization Folder Log if no logs are available, exposing information about the Jenkins controller file system. | |
| Modificada | Media (4.3) | 0.39% | — | Jenkins Folders | 16/8/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy a view inside a folder. | |
| Modificada | Alta (8.8) | 0.47% | — | Jenkins Folders | 16/8/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Folders Plugin 6.846.v23698686f0f6 and earlier allows attackers to copy folders. | |
| Modificada | Media (4.3) | 0.29% | — | Wickedplugins Wicked Folders | 9/6/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_sort_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request… | |
| Modificada | Alta (8.8) | 0.27% | — | Mediamatic Media Library Folders | 22/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Plugincraft Mediamatic – Media Library Folders plugin <= 2.8.1 versions. | |
| Modificada | Media (4.3) | 0.31% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_edit_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… | |
| Modificada | Media (4.3) | 0.31% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_clone_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… | |
| Modificada | Media (4.3) | 0.31% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_add_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… | |
| Modificada | Media (4.3) | 0.31% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_state function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder_order function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_delete_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_edit_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_clone_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_state function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and perform… | |
| Modificada | Media (4.3) | 0.31% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_unassign_folders function. This makes it possible for unauthenticated attackers to invoke this function via forged request… | |
| Modificada | Media (4.3) | 0.58% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_unassign_folders function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.59% | — | Wickedplugins Wicked Folders | 8/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to authorization bypass due to a missing capability check on the ajax_save_folder function in versions up to, and including, 2.18.16. This makes it possible for authenticated attackers, with subscriber-level permissions and above, to invoke this function and… | |
| Modificada | Media (4.3) | 0.32% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_save_folder_order function. This makes it possible for unauthenticated attackers to invoke this function via forged request… | |
| Modificada | Media (4.3) | 0.32% | — | Wickedplugins Wicked Folders | 7/2/2023 | 17/6/2026 | The Wicked Folders plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 2.18.16. This is due to missing or incorrect nonce validation on the ajax_delete_folder function. This makes it possible for unauthenticated attackers to invoke this function via forged request granted… |