Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
303 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.38% | — | Vanquish Upload Files AnywhereAI | 20/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhere allows Path Traversal.This issue affects Upload Files Anywhere: from n/a through <= 2.8. | |
| Aplazada | Alta (8.6) | 0.39% | — | Vanquish Upload Files AnywhereAI | 20/2/2026 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in vanquish Upload Files Anywhere wp-upload-files-anywhere allows Path Traversal.This issue affects Upload Files Anywhere: from n/a through <= 2.8. | |
| Aplazada | Alta (7.3) | 0.59% | — | Kapasias LottiefilesAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in LottieFiles LottieFiles lottiefiles allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects LottieFiles: from n/a through <= 3.0.0. | |
| Aplazada | Media (5.3) | 0.27% | — | Anssi Laitila Shared FilesAI | 20/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.19. | |
| Aplazada | Media (6.4) | 0.19% | — | FilestackAI | 18/2/2026 | 17/6/2026 | The Filestack plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'filepicker' shortcode in all versions up to, and including, 2.0.8 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (6.9) | 0.41% | — | M-files Server | 21/1/2026 | 17/6/2026 | Denial-of-service vulnerability in M-Files Server versions before 26.1.15632.3 allows an authenticated attacker with vault administrator privileges to crash the M-Files Server process by calling a vulnerable API endpoint. | |
| Aplazada | Crítica (9.3) | 0.72% | — | Omni Secure FilesAI | 16/1/2026 | 16/6/2026 | Omni Secure Files plugin versions prior to 0.1.14 contain an arbitrary file upload vulnerability in the bundled plupload example endpoint. The /wp-content/plugins/omni-secure-files/plupload/examples/upload.php handler allows unauthenticated uploads without enforcing safe file type restrictions, enabling an attacker to… | |
| Aplazada | Media (5.3) | 0.94% | — | Lottiefiles Lottie Block FOR GutenbergAI | 14/1/2026 | 17/6/2026 | The LottieFiles – Lottie block for Gutenberg plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 3.0.0 via the `/wp-json/lottiefiles/v1/settings/` REST API endpoint. This makes it possible for unauthenticated attackers to retrieve the site owner's LottieFiles.com… | |
| Modificada | Media (5.1) | 0.29% | — | Skyjos Owlfiles | 13/1/2026 | 17/6/2026 | Owlfiles File Manager 12.0.1 contains a cross-site scripting vulnerability that allows attackers to inject malicious scripts through the path parameter in HTTP server endpoints. Attackers can craft URLs targeting the download and list endpoints with embedded script tags to execute arbitrary JavaScript in users'… | |
| Analizada | Alta (8.7) | 1.1% | — | Skyjos Owlfiles | 13/1/2026 | 17/6/2026 | Owlfiles File Manager 12.0.1 contains a path traversal vulnerability in its built-in HTTP server that allows attackers to access system directories. Attackers can exploit the vulnerability by crafting GET requests with directory traversal sequences to access restricted system directories on the device. | |
| Analizada | Alta (7.5) | 0.62% | — | Sylphx Filesystem MCP | 7/1/2026 | 16/9/2026 | @sylphxltd/filesystem-mcp v0.5.8 is an MCP server that provides file content reading functionality. Version 0.5.8 of filesystem-mcp contains a critical path traversal vulnerability in its "read_content" tool. This vulnerability arises from improper symlink handling in the path validation mechanism: the resolvePath… | |
| Analizada | Alta (7.5) | 0.63% | — | Efforthye Fast-filesystem-mcp | 7/1/2026 | 17/6/2026 | fast-filesystem-mcp version 3.4.0 contains a critical path traversal vulnerability in its file operation tools including fast_read_file. This vulnerability arises from improper path validation that fails to resolve symbolic links to their actual physical paths. The safePath and isPathAllowed functions use… | |
| Aplazada | Media (4.3) | 0.22% | — | Fahadmahmood Easy Upload Files During CheckoutAI | 31/12/2025 | 28/9/2026 | Missing Authorization vulnerability in Fahad Mahmood Easy Upload Files During Checkout easy-upload-files-during-checkout allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Easy Upload Files During Checkout: from n/a through <= 3.0.0. | |
| Aplazada | Alta (7.7) | 0.40% | — | Happyfiles PROAI | 21/12/2025 | 17/6/2026 | Missing Authorization vulnerability in HappyFiles HappyFiles Pro happyfiles-pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HappyFiles Pro: from n/a through 1.8.1. | |
| Aplazada | Media (5.4) | 0.24% | — | Happyfiles PROAI | 21/12/2025 | 17/6/2026 | Missing Authorization vulnerability in HappyFiles HappyFiles Pro allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects HappyFiles Pro: from n/a through 1.8.1. | |
| Analizada | Alta (7.5) | 0.61% | — | Takes Tkfiles | 19/12/2025 | 17/6/2026 | The Takes web framework's TkFiles take thru 2.0-SNAPSHOT fails to canonicalize HTTP request paths before resolving them against the filesystem. A remote attacker can include ../ sequences in the request path to escape the configured base directory and read arbitrary files from the host system. | |
| Modificada | Media (5.6) | 0.38% | — | M-files Server | 19/12/2025 | 17/6/2026 | Incomplete removal of sensitive information before transfer vulnerability in M-Files Corporation M-Files Server allows data leak exposure affecting versions before 25.12.15491.7 | |
| Aplazada | Alta (8.6) | 0.48% | — | M-filesAI | 19/12/2025 | 25/9/2026 | An information disclosure vulnerability in M-Files Server before versions 25.12.15491.7, 25.8 LTS SR3, 25.2 LTS SR3 and 24.8 LTS SR5 allows an authenticated attacker using M-Files Web to capture session tokens of other active users. | |
| Modificada | Media (5.3) | 0.31% | — | M-files Server | 18/12/2025 | 17/6/2026 | Improper access checks in M-Files Server before 25.12.15491.7 allows users to download files through M-Files Web using Web Companion despite Print and Download Prevention module being enabled. | |
| Aplazada | Media (5.4) | 0.18% | — | FilesAI | 26/11/2025 | 17/6/2026 | Files is a module for managing files inside spaces and user profiles. Prior to versions 0.16.11 and 0.17.2, insufficient authorization checks allow non-member users to create new folders, up- and download files as a ZIP archive in public spaces. Private spaces are not affected. This issue has been patched in versions… | |
| Aplazada | Alta (7.2) | 0.23% | — | Checkout Files UploadAI | 18/11/2025 | 17/6/2026 | The Checkout Files Upload for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via file uploads in all versions up to, and including, 2.2.1 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Modificada | Alta (7.1) | 0.39% | — | M-files Server | 17/11/2025 | 30/9/2026 | Denial-of-service condition in M-Files Server versions before 25.11.15392.1, before 25.2 LTS SR2 and before 25.8 LTS SR2 allows an authenticated user to cause the MFserver process to crash. | |
| Analizada | Alta (8.6) | 85% | ⚠ Explotación activa | Sangoma Filestore | 7/11/2025 | 17/6/2026 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions 17.0.2.36 and above before 17.0.3, the filestore module within the Administrative interface is vulnerable to a post-authentication command injection by an authenticated known user via the testconnection ->… | |
| Aplazada | Crítica (9.8) | 0.65% | — | Easy Upload Files During CheckoutAI | 4/11/2025 | 17/6/2026 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to arbitrary JavaScript file uploads due to missing file type validation in the 'file_during_checkout' function in all versions up to, and including, 2.9.8. This makes it possible for unauthenticated attackers to upload arbitrary JavaScript files… | |
| Analizada | Alta (7.3) | 0.69% | — | Liquidfiles | 30/9/2025 | 17/6/2026 | LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and invalid email addresses, allowing unauthenticated attackers to determine the existence of user accounts. Version 4.2 introduces user-based… |