Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.18% | — | Coatedmedia User Profile BuilderAI | 19/11/2025 | 17/6/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's wppb-embed shortcode in all versions up to, and including, 3.14.8 due to insufficient input sanitization and output escaping on user supplied… | |
| Aplazada | Alta (7.2) | 0.23% | — | Checkout Files UploadAI | 18/11/2025 | 17/6/2026 | The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Alta (7.1) | 0.39% | — | M-files Server | 17/11/2025 | 7/10/2026 | Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash. | |
| Aplazada | Media (4.3) | 0.19% | — | Nmedia Frontend File ManagerAI | 13/11/2025 | 7/10/2026 | Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.2. | |
| Analizada | Alta (7.2) | 0.43% | — | Filebrowser | 12/11/2025 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Versions prior to 2.45.1 have an Insecure Direct Object Reference (IDOR) vulnerability in the FileBrowser application's share deletion functionality. This vulnerability… | |
| Aplazada | Media (4.8) | 0.12% | — | Intel Vtune ProfilerAI | 11/11/2025 | 17/6/2026 | Improper input validation for some Intel VTune Profiler before version 2025.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local… | |
| Analizada | Alta (7.2) | 0.45% | — | Cmsmadesimple File Manager | 10/11/2025 | 17/6/2026 | An authenticated arbitrary file upload vulnerability in the /uploads/ endpoint of CMS Made Simple Foundation File Manager v2.2.22 allows attackers with Administrator privileges to execute arbitrary code via uploading a crafted PHP file. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Sterling B2B IntegratorIBM Sterling File Gateway | 7/11/2025 | 17/6/2026 | IBM Sterling B2B Integrator 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7_1, 6.2.0.0 through 6.2.0.5, and 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web… | |
| Analizada | Baja (2) | 0.34% | — | Campcodes School File Management System | 7/11/2025 | 7/10/2026 | A security flaw has been discovered in Campcodes School File Management 1.0. This affects an unknown part of the file /admin/update_user.php. Performing manipulation of the argument user_id results in sql injection. It is possible to initiate the attack remotely. The exploit has been released to the public and may be… | |
| Analizada | Baja (2.2) | 0.20% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to bypass security mechanisms or read application data. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018… | |
| Analizada | Media (4.9) | 0.46% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the… | |
| Analizada | Baja (0.6) | 0.46% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and later | |
| Analizada | Baja (1.2) | 0.48% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains an administrator account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already… | |
| Analizada | Media (4.9) | 0.46% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the… | |
| Analizada | Media (4.9) | 0.46% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the… | |
| Analizada | Baja (1.3) | 0.34% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and later | |
| Analizada | Baja (1.3) | 0.34% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and later | |
| Analizada | Media (5.3) | 0.34% | — | Qnap File Station | 7/11/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect several product versions. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.5018 and… | |
| Analizada | Alta (8.6) | 85% | ⚠ Explotación activa💥 Exploit | Sangoma Filestore | 7/11/2025 | 17/6/2026 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection ->… | |
| Analizada | Alta (8.1) | 0.40% | 💥 PoC | Alexusmai Laravel File Manager | 6/11/2025 | 17/6/2026 | alexusmai laravel-file-manager 3.3.1 is vulnerable to Cross Site Scripting (XSS). The application permits user-controlled upload, create, and rename of files to HTML and SVG types and serves those files inline without adequate content-type validation or output sanitization. | |
| Aplazada | Alta (7.5) | 2.5% | 💥 Exploit | File Manager FOR Google DriveAI | 5/11/2025 | 17/6/2026 | The File Manager for Google Drive – Integrate Google Drive with WordPress plugin for WordPress is vulnerable to sensitive information exposure in all versions up to, and including, 1.5.3 via the "get_localize_data" function. This makes it possible for unauthenticated attackers to extract sensitive data including… | |
| Aplazada | Crítica (9.8) | 0.65% | — | Easy Upload Files During CheckoutAI | 4/11/2025 | 17/6/2026 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in the 'file_during_checkout' function in all versions up to, and including, 2.9.8. This makes it possible for unauthenticated attackers to upload arbitrary JavaScript files… | |
| Aplazada | Media (5.3) | 0.26% | — | Erifl ERI File LibraryAI | 31/10/2025 | 7/10/2026 | The ERI File Library plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'erifl_file' AJAX action in all versions up to, and including, 1.1.0. This makes it possible for unauthenticated attackers to download files restricted to specific user roles. | |
| Aplazada | Alta (8.8) | 0.60% | 💥 PoC | Alexusmai Laravel-file-managerAI | 28/10/2025 | 5/7/2026 | alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload. A file with a '.png` extension containing PHP code can be uploaded via the file manager interface. Although the upload appears to fail client-side validation, the file… | |
| Analizada | Alta (7.5) | 0.36% | — | Audiofile | 23/10/2025 | 17/6/2026 | Audiofile v0.3.7 was discovered to contain a NULL pointer dereference via the ModuleState::setup function. |