Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

2405 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.5)0.25%—IBM Sterling B2B IntegratorIBM Sterling File Gateway19/8/202517/6/2026
IBM Sterling B2B Integrator and IBM Sterling File Gateway 6.0.0.0 through 6.1.2.7, 6.2.0.0 through 6.2.0.4, and 6.2.1.0 could disclose sensitive server information to an unauthorized user that could aid in further attacks against the system.
AnalizadaMedia (5.4)0.24%—IBM Sterling B2B IntegratorIBM Sterling File Gateway19/8/202517/6/2026
IBM Sterling B2B Integrator 6.2.1.0 and IBM Sterling File Gateway 6.2.1.0 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
AplazadaAlta (8.2)0.28%—Fortra FilecatalystAI19/8/202517/6/2026
Improper Access Control issue in the Workflow component of Fortra's FileCatalyst allows unauthenticated users to upload arbitrary files via the order forms page.
AnalizadaAlta (7.1)0.38%—Qnap File Station18/8/202517/6/2026
An out-of-bounds write vulnerability has been reported to affect File Station 5. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: File Station 5 5.5.6.4933 and later
AplazadaBaja (1.9)0.17%—Elseplus File Recovery APPAI18/8/202517/6/2026
A vulnerability was determined in Elseplus File Recovery App 4.4.21 on Android. Affected by this issue is some unknown functionality of the file AndroidManifest.xml. The manipulation leads to improper export of android application components. The attack needs to be approached locally. The exploit has been disclosed to…
AplazadaMedia (6.5)0.44%—ProfilepressAI16/8/202517/6/2026
The The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.16.4. This is due to the software allowing users to execute an action that does not…
AplazadaMedia (5.3)0.71%—Drag AND Drop Multiple File Upload FOR Contact Form 7AI16/8/202517/6/2026
The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7_guest_user_id cookie. This makes it possible for unauthenticated attackers to upload and delete files outside of the originally intended…
AplazadaMedia (6.4)0.20%—Codesigner User Profile BuilderAI16/8/202517/6/2026
The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'gdpr_communication_preferences[]' parameter in all versions up to, and including, 3.14.3 due to insufficient input sanitization and output escaping.…
AnalizadaMedia (6.1)0.22%—Shopfiles Ebook Store16/8/202517/6/2026
The Ebook Store WordPress plugin before 5.8015 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers.
AplazadaMedia (4.3)0.13%—Shopfiles Ebook StoreAI14/8/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in motov.net Ebook Store ebook-store allows Cross Site Request Forgery.This issue affects Ebook Store: from n/a through <= 5.8013.
AplazadaAlta (8.5)0.27%—Metagauss ProfilegridAI14/8/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Blind SQL Injection.This issue affects ProfileGrid : from n/a through <= 5.9.5.3.
AplazadaCrítica (9.4)2.3%💥 ExploitExtremez-ip File ServerAI13/8/202516/6/2026
QuickShare File Server 1.2.1 contains a path traversal vulnerability in its FTP service due to improper sanitation of user-supplied file paths. Authenticated users can exploit this flaw by submitting crafted sequences to access or write files outside the intended virtual directory. When the "Writable" option is…
AnalizadaAlta (7.8)0.30%—Microsoft Azure File Sync12/8/202517/6/2026
Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
AplazadaCrítica (9.4)3.4%💥 ExploitOpenfilerAI11/8/202516/6/2026
Openfiler v2.x contains a command injection vulnerability in the system.html page. The device parameter is used to instantiate a NetworkCard object, whose constructor in network.inc calls exec() with unsanitized input. An authenticated attacker can exploit this to execute arbitrary commands as the openfiler user. Due…
AplazadaMedia (6.5)0.39%—Ninjateam FilebirdAI6/8/202517/6/2026
The FileBird – WordPress Media Library Folders & File Manager plugin for WordPress is vulnerable to SQL Injection via the 'search' parameter in all versions up to, and including, 6.4.8 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes…
AnalizadaBaja (3.8)0.53%—Liquidfiles4/8/202517/6/2026
LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript.
AnalizadaAlta (8.8)0.55%—Liquidfiles4/8/202517/6/2026
LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration.
AnalizadaCrítica (9.2)0.32%—Humhub Files2/8/20252/9/2026
Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the exploitation of backend SQL queries without direct output, potentially allowing unauthorized data access. This is fixed in version 0.16.10.
AnalizadaMedia (5.1)0.28%—Humhub Files2/8/20252/9/2026
Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, the File Move functionality does not contain logic that prevents injection of arbitrary JavaScript, which can lead to Browser JS code execution in the context of the user’s session. This is fixed in version 0.16.10.
AnalizadaBaja (2.1)0.43%—Jingmen Zeyou Large File Upload Control26/7/202517/6/2026
A vulnerability classified as critical has been found in Jingmen Zeyou Large File Upload Control up to 6.3. Affected is an unknown function of the file /index.jsp. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and…
AplazadaAlta (7.5)0.32%—Najeebmedia Frontend File ManagerAI25/7/202517/6/2026
The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete_multiple_files() function in all versions up to, and including, 21.5. This makes it possible for unauthenticated attackers to delete arbitrary posts.
AplazadaCrítica (9.8)1.3%—Shopfiles Ebook StoreAI24/7/202517/6/2026
The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions up to, and including, 5.8012. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may…
AplazadaAlta (7)0.24%—Joomla ProfilesAI23/7/202517/6/2026
A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.
AplazadaAlta (7.7)0.76%—Files-bucket-serverAI23/7/202517/6/2026
All versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the file system and access files outside of the intended directory.
AnalizadaCrítica (9.8)4.7%💥 ExploitNajeebmedia Website Contact Form With File Upload22/7/202517/6/2026
The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_file()' function in versions up to, and including, 1.3.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server…