Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

95 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.90%—Filemanagerpro File Manager5/4/202117/6/2026
In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitFilemanagerpro File Manager9/9/202017/6/2026
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to…
ModificadaAlta (7.5)16%💥 ExploitFilemanagerpro File Manager26/8/202017/6/2026
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
ModificadaMedia (6.1)0.91%—Tecrail Responsive Filemanager30/3/202017/6/2026
An issue was discovered in Responsive Filemanager through 9.14.0. In the dialog.php page, the session variable $_SESSION['RF']["view_type"] wasn't sanitized if it was already set. This made stored XSS possible if one opens ajax_calls.php and uses the "view" action and places a payload in the type parameter, and then…
ModificadaCrítica (9.8)20%💥 PoCTecrail Responsive Filemanager14/3/202017/6/2026
An issue was discovered in Responsive Filemanager through 9.14.0. In the ajax_calls.php file in the save_img action in the name parameter, there is no validation of what kind of extension is sent. This makes it possible to execute PHP code if a legitimate JPEG image contains this code in the EXIF data, and the .php…
ModificadaCrítica (9.8)1.5%—Tecrail Responsive Filemanager7/3/202017/6/2026
upload.php in Responsive FileManager 9.13.4 and 9.14.0 allows SSRF via the url parameter because file-extension blocking is mishandled and because it is possible for a DNS hostname to resolve to an internal IP address. For example, an SSRF attempt may succeed if a .ico filename is added to the PATH_INFO. Also, an…
ModificadaMedia (6.1)1.4%—Filemanagerpro File Manager15/4/201917/6/2026
There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
ModificadaAlta (8.8)0.92%—Filemanagerpro File Manager15/4/201917/6/2026
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
ModificadaAlta (7.5)3.5%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary files via path traversal with the path parameter, through the copy_cut action in ajax_calls.php and the paste_clipboard action in execute.php.
ModificadaAlta (7.5)4.0%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary image file (jpg/jpeg/png) via path traversal with the path parameter, through the save_img action in ajax_calls.php.
ModificadaAlta (7.5)5.0%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows remote attackers to write to an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass, through the create_file action in execute.php.
ModificadaAlta (7.5)3.5%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows remote attackers to read arbitrary file via path traversal with the path parameter, through the get_file action in ajax_calls.php.
ModificadaMedia (6.1)0.81%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows XSS via a media file upload with an XSS payload in the name, because of mishandling of the media_preview action.
ModificadaAlta (7.5)3.6%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary file as a consequence of a paths[0] path traversal mitigation bypass through the delete_file action in execute.php.
ModificadaAlta (7.5)3.6%—Tecrail Responsive Filemanager25/2/201917/6/2026
tecrail Responsive FileManager 9.13.4 allows remote attackers to delete an arbitrary directory as a consequence of a paths[0] path traversal mitigation bypass through the delete_folder action in execute.php.
ModificadaAlta (8.6)1.5%—Tecrail Responsive Filemanager31/10/201817/6/2026
An SSRF issue was discovered in tecrail Responsive FileManager 9.13.4 via the upload.php url parameter. NOTE: this issue exists because of an incomplete fix for CVE-2018-15495.
ModificadaMedia (6.1)0.81%—Tecrail Responsive Filemanager10/10/201817/6/2026
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote attackers to inject arbitrary web script or HTML.
ModificadaAlta (7.5)0.91%—Tecrail Responsive Filemanager10/10/201817/6/2026
An issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that provides them with the ability to upload and delete files.
ModificadaMedia (5.4)1.4%💥 ExploitFilemanagerpro File Manager7/9/201817/6/2026
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php and there is an echo of lang in lib\wpfilemanager.php.
ModificadaMedia (5.5)6.4%💥 ExploitTecrail Responsive Filemanager24/8/201817/6/2026
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.
ModificadaAlta (7.5)45%💥 ExploitTecrail Responsive Filemanager24/8/201817/6/2026
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to a location that is outside of that directory, aka Directory…
ModificadaAlta (7.5)2.4%—Tecrail Responsive Filemanager18/8/201817/6/2026
/filemanager/upload.php in Responsive FileManager before 9.13.3 allows Directory Traversal and SSRF because the url parameter is used directly in a curl_exec call, as demonstrated by a file:///etc/passwd value.
ModificadaCrítica (9.8)77%💥 ExploitTecrail Responsive Filemanager3/8/201817/6/2026
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
ModificadaAlta (8.8)27%💥 ExploitPhpfilemanager Project Phpfilemanager31/8/201717/6/2026
phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.
ModificadaMedia (6.4)1.8%—S-link Slfilemanager26/9/201417/6/2026
Directory traversal vulnerability in the S-Link SLFileManager application 1.2.5 and earlier for Android allows remote attackers to write to files via unspecified vectors.
Orbitaley — Vulnerabilidades