Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
187 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.32% | — | Nmedia Frontend File ManagerAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Frontend File Manager: from n/a through <= 23.3. | |
| Aplazada | Media (4.9) | 0.50% | 💥 PoC | Managefy File Manager Code Editor AND BackupAI | 28/8/2025 | 17/6/2026 | The File Manager, Code Editor, and Backup by Managefy plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.4.8 via the ajax_downloadfile() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform actions on files outside of… | |
| Aplazada | Alta (7.5) | 0.32% | — | Najeebmedia Frontend File ManagerAI | 25/7/2025 | 17/6/2026 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the wpfm_delete_multiple_files() function in all versions up to, and including, 21.5. This makes it possible for unauthenticated attackers to delete arbitrary posts. | |
| Aplazada | Media (4.6) | 0.21% | — | Nmedia Frontend File ManagerAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in N-Media Frontend File Manager nmedia-user-file-uploader allows Code Injection.This issue affects Frontend File Manager: from n/a through <= 23.6. | |
| Aplazada | Crítica (9.1) | 0.40% | — | Getredhawkstudio File Manager Plugin FOR WordpressAI | 27/6/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in getredhawkstudio File Manager Plugin For Wordpress file-manager-plugin-for-wordpress allows Upload a Web Shell to a Web Server.This issue affects File Manager Plugin For Wordpress: from n/a through <= 7.5. | |
| Aplazada | Media (5.9) | 0.20% | — | Ninjateam File Manager PROAI | 20/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Ninja Team File Manager Pro filester allows Stored XSS.This issue affects File Manager Pro: from n/a through <= 1.8.8. | |
| Aplazada | Alta (7.2) | 0.62% | — | Filemanagerpro.io File Manager PROAI | 14/6/2025 | 17/6/2026 | The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.8.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's… | |
| Aplazada | Media (6.4) | 0.22% | — | BIT File ManagerAI | 3/6/2025 | 17/6/2026 | The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 6.7 due to insufficient input sanitization and output escaping. This makes it possible for authenticated… | |
| Analizada | Media (6.1) | 0.27% | 💥 PoC | Prasathmani Tiny File Manager | 23/5/2025 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the component /tinyfilemanager.php of TinyFileManager v2.4.7 allows attackers to execute arbitrary JavaScript or HTML via injecting a crafted payload into the js-theme-3 parameter. | |
| Aplazada | Alta (7.2) | 0.83% | — | Advanced File Manager PRO PremiumAIAdvancedfilemanager File Manager Advanced ShortcodeAI | 15/5/2025 | 17/6/2026 | The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.4 (file-manager-advanced-shortcode) and 2.5.6 (advanced-file-manager-pro-premium), via the 'file_manager_advanced' shortcode. This makes it possible for authenticated attackers, with… | |
| Modificada | Crítica (9.8) | 0.37% | — | Advancedfilemanager Advanced File Manager | 7/5/2025 | 17/6/2026 | Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced File Manager: from n/a through <= 5.3.1. | |
| Analizada | Media (5.4) | 0.27% | — | Advancedfilemanager Advanced File Manager | 7/3/2025 | 17/6/2026 | The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Alta (7.9) | 0.20% | — | Teamamaze Amaze File ManagerAI | 11/2/2025 | 17/6/2026 | An issue in Team Amaze Amaze File Manager v.3.8.5 and fixed in v.3.10 allows a local attacker to execute arbitrary code via the onCreate method of DatabaseViewerActivity.java. | |
| Analizada | Crítica (9.8) | 0.82% | 💥 PoC | Prasathmani Tiny File Manager | 6/2/2025 | 17/6/2026 | Tiny File Manager v2.4.7 and below is vulnerable to session fixation. | |
| Modificada | Media (4.8) | 0.40% | 💥 PoC | Prasathmani Tiny File Manager | 6/2/2025 | 17/6/2026 | Tiny File Manager v2.4.7 and below was discovered to contain a Cross Site Scripting (XSS) vulnerability. This vulnerability allows attackers to execute arbitrary code via a crafted payload injected into the name of an uploaded or already existing file. | |
| Analizada | Alta (7.5) | 0.90% | — | Advancedfilemanager Advanced File Manager | 17/1/2025 | 17/6/2026 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above and upload permissions granted by… | |
| Analizada | Alta (7.5) | 0.70% | — | Advancedfilemanager Advanced File Manager | 3/12/2024 | 17/6/2026 | The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted… | |
| Aplazada | Media (4.3) | 0.34% | — | Mndpsingh287 File ManagerAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in mndpsingh287 File Manager allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects File Manager: from n/a through 7.2.7. | |
| Analizada | Crítica (9.8) | 5.7% | 💥 Exploit | Najeebmedia Frontend File ManagerNajeebmedia Post Front-end Form | 16/10/2024 | 17/6/2026 | The Frontend File Manager (versions < 4.0), N-Media Post Front-end Form (versions < 1.1) plugins for WordPress are vulnerable to arbitrary file uploads due to missing file type validation via the `nm_filemanager_upload_file` and `nm_postfront_upload_file` AJAX actions. This makes it possible for unauthenticated… | |
| Analizada | Media (5.4) | 0.34% | — | Filemanagerpro File Manager | 16/10/2024 | 17/6/2026 | The File Manager Pro plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 8.3.9. This is due to a lack of proper checks on allowed file types. This makes it possible for unauthenticated attackers, with permissions granted by an administrator, to upload .css and .js… | |
| Analizada | Alta (8.8) | 0.65% | — | Filemanagerpro File Manager | 16/10/2024 | 17/6/2026 | The File Manager Pro plugin for WordPress is vulnerable to arbitrary backup file downloads and uploads due to missing file type validation via the 'mk_file_folder_manager_shortcode' ajax action in all versions up to, and including, 8.3.9. This makes it possible for unauthenticated attackers, if granted access to the… | |
| Analizada | Alta (8.8) | 0.25% | — | Filemanagerpro File Manager | 16/10/2024 | 17/6/2026 | The File Manager Pro plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 8.3.9. This is due to missing or incorrect nonce validation on the 'mk_file_folder_manager' ajax action. This makes it possible for unauthenticated attackers to upload arbitrary files via a… | |
| Analizada | Crítica (9.8) | 0.81% | — | Filemanagerpro File Manager | 16/10/2024 | 17/6/2026 | The File Manager plugin for WordPress is vulnerable to authorization bypass due to a missing capability check in the /inc/root.php file in versions up to, and including, 3.0. This makes it possible for unauthenticated attackers to download arbitrary files from the server and upload arbitrary files that can be used for… | |
| Aplazada | Media (6.8) | 0.79% | 💥 PoC | BIT File ManagerAI | 5/10/2024 | 17/6/2026 | The Bit File Manager – 100% Free & Open Source File Manager and Code Editor for WordPress plugin for WordPress is vulnerable to Limited JavaScript File Upload in all versions up to, and including, 6.5.7. This is due to a lack of proper checks on allowed file types. This makes it possible for authenticated attackers,… | |
| Analizada | Media (5.4) | 0.38% | — | Advancedfilemanager Advanced File Manager | 26/9/2024 | 17/6/2026 | Multiple plugins and/or themes for WordPress are vulnerable to Limited File Upload in various versions. This is due to a lack of proper checks to ensure lower-privileged roles cannot upload .css and .js files to arbitrary directories. This makes it possible for authenticated attackers, with Subscriber-level access and… |