Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 1.2% | — | Falkordb BrowserAI | 10/4/2026 | 17/6/2026 | FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote code execution. | |
| Analizada | Alta (8.8) | 0.56% | — | Filebrowser | 7/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the fix in commit b6a4fb1 ("self-registered users don't get execute perms") stripped Execute permission and Commands from users created via the signup handler. The… | |
| Analizada | Media (5.3) | 0.39% | — | Filebrowser | 7/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the resourceGetHandler in http/resource.go returns full text file content without checking the Perm.Download permission flag. All three other content-serving… | |
| Analizada | Media (6.3) | 0.44% | — | Filebrowser | 7/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, the Matches() function in rules/rules.go uses strings.HasPrefix() without a trailing directory separator when matching paths against access rules. A rule for… | |
| Analizada | Alta (8.2) | 0.43% | — | Filebrowser | 7/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.1, when an admin revokes a user's Share and Download permissions, existing share links created by that user remain fully accessible to unauthenticated users. The public… | |
| Modificada | Alta (7.5) | 2.4% | — | Filebrowser | 7/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.0.0 until 2.33.8, the hook system in File Browser — which executes administrator-defined shell commands on file events such as upload, rename, and delete — is vulnerable to OS… | |
| Pendiente de análisis | Media (6) | 0.26% | — | Pega Browser ExtensionAIPega Robotic AutomationAI | 7/4/2026 | 17/6/2026 | A native messaging host vulnerability in Pega Browser Extension (PBE) affects users of all versions of Pega Robotic Automation who have installed Pega Browser Extension. A bad actor could create a website that contains malicious code that targets PBE. The vulnerability could occur if a user navigates to this website.… | |
| Pendiente de análisis | Alta (7.2) | 0.32% | — | Pega Browser ExtensionAIPega Robotic AutomationAI | 7/4/2026 | 17/6/2026 | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robotic Automation version 22.1 or R25 users who are running automations that work with Google Chrome or Microsoft Edge. A bad actor could create a website that includes malicious code. The vulnerability could occur if a Robot Runtime… | |
| Aplazada | Baja (2.1) | 0.45% | — | Imprvhub Mcp-browser-agentAI | 6/4/2026 | 24/7/2026 | A security vulnerability has been detected in imprvhub mcp-browser-agent up to 0.8.0. This impacts the function CallToolRequestSchema of the file src/handlers.ts of the component URL Parameter Handler. The manipulation of the argument request.params.name/request.params.arguments leads to server-side request forgery.… | |
| Analizada | Media (5.5) | 0.53% | — | Songli Cross Browser Fingerprinting | 5/4/2026 | 24/7/2026 | A vulnerability has been found in Song-Li cross_browser up to ca690f0fe6954fd9bcda36d071b68ed8682a786a. This affects an unknown part of the file flask/uniquemachine_app.py of the component details Endpoint. Such manipulation of the argument ID leads to sql injection. The attack can be executed remotely. The exploit… | |
| Aplazada | Alta (8.7) | 0.36% | — | VPN Browser+AI | 4/4/2026 | 21/7/2026 | VPN Browser+ 1.1.0.0 contains a denial of service vulnerability that allows unauthenticated attackers to crash the application by submitting oversized input through the search functionality. Attackers can paste a large buffer of characters into the search bar to trigger an unhandled exception that terminates the… | |
| Analizada | Media (6.9) | 0.36% | — | Filebrowser | 1/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the SPA index page in File Browser is vulnerable to Stored Cross-Site Scripting (XSS) via admin-controlled branding fields. An admin who sets branding.name… | |
| Analizada | Crítica (9) | 0.39% | — | Filebrowser | 1/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the EPUB preview function in File Browser is vulnerable to Stored Cross-Site Scripting (XSS). JavaScript embedded in a crafted EPUB file executes in the… | |
| Analizada | Crítica (9.8) | 0.66% | — | Filebrowser | 1/4/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to version 2.62.2, the signupHandler in File Browser applies default user permissions via d.settings.Defaults.Apply(user), then strips only Admin. The Execute permission and… | |
| Pendiente de análisis | Crítica (9) | 0.32% | — | Pega Browser ExtensionAIPega Robot StudioAI | 23/3/2026 | 17/6/2026 | An arbitrary file-write vulnerability in Pega Browser Extension (PBE) affects Pega Robot Studio developers who are automating Google Chrome and Microsoft Edge using either version 22.1 or R25. This vulnerability does not affect Robot Runtime users. A bad actor could create a website that includes malicious code. The… | |
| Analizada | Media (6.5) | 0.19% | — | Thebrowser ARC Search | 20/3/2026 | 17/6/2026 | ArcSearch for Android versions prior to 1.12.7 could display a different domain in the address bar than the content being shown, enabling address bar spoofing after user interaction via crafted web content. | |
| Analizada | Media (6.5) | 0.46% | — | Filebrowser | 20/3/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.0 and below contain a permission enforcement bypass which allows users who are denied download privileges (perm.download = false) but granted share privileges… | |
| Analizada | Crítica (10) | 0.69% | — | Filebrowser | 20/3/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions 2.61.2 and below, any unauthenticated visitor can register a full administrator account when self-registration (signup = true) is enabled and the default user permissions… | |
| Modificada | Media (5.3) | 2.2% | — | Filebrowser | 20/3/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. In versions on the 2.x branch prior to 2.33.8, the TUS resumable upload handler parses the Upload-Length header as a signed 64-bit integer without validating that the value is… | |
| Analizada | Media (6.5) | 0.44% | — | Filebrowser | 20/3/2026 | 17/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Versions 2.61.2 and below are vulnerable to Path Traversal through the resourcePatchHandler (http/resource.go). The destination path in resourcePatchHandler is validated against… | |
| Analizada | Media (5.4) | 0.36% | — | Filebrowser | 10/3/2026 | 17/6/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, Stored XSS is possible via share metadata fields (e.g., title, description) that are rendered into HTML for /public/share/<hash> without context-aware escaping. The server uses text/template instead of… | |
| Analizada | Alta (7.5) | 0.52% | — | Filebrowser | 10/3/2026 | 17/6/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-beta and 1.2.2-stable, the remediation for CVE-2026-27611 is incomplete. Password protected shares still disclose tokenized downloadURL via /public/api/share/info. This vulnerability is fixed in 1.3.1-beta and 1.2.2-stable. | |
| Analizada | Alta (8.1) | 0.61% | — | Filebrowser | 5/3/2026 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.1, a broken access control vulnerability in the TUS protocol DELETE endpoint allows authenticated users with only Create permission to delete… | |
| Analizada | Alta (7.1) | 0.48% | — | Filebrowser | 5/3/2026 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to version 2.61.0, when a user creates a public share link for a directory, the withHashFile middleware in http/public.go uses filepath.Dir(link.Path) to compute the… | |
| Analizada | Media (5.4) | 0.14% | — | Soliton Securebrowser FOR OnegateSoliton Securebrowser IISoliton Secureworkspace | 27/2/2026 | 17/6/2026 | The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges. |