Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
95 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 8.9% | 💥 Exploit | Devexpress Aspxfilemanager Control FOR Webforms AND MVC | 6/6/2014 | 17/6/2026 | Directory traversal vulnerability in the File Manager component in DevExpress ASPxFileManager Control for ASP.NET WebForms and MVC before 13.1.10 and 13.2.x before 13.2.9 allows remote authenticated users to read or write arbitrary files via a .. (dot dot) in the __EVENTARGUMENT parameter. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Libra File Manager PHP Filemanager | 21/8/2009 | 16/6/2026 | Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the user and pass cookies to 1. | |
| Modificada | Media (6.8) | 1.7% | 💥 Exploit | Dutchmonkey DM Filemanager | 9/7/2009 | 16/6/2026 | PHP remote file inclusion vulnerability in dm-albums/template/album.php in DM FileManager 3.9.4, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Dutchmonkey DM Filemanager | 9/6/2009 | 16/6/2026 | admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access by setting the (1) USER, (2) GROUPID, (3) GROUP, and (4) USERID cookies to certain values. | |
| Modificada | Media (6.8) | 1.9% | 💥 Exploit | Dutchmonkey DM Filemanager | 20/5/2009 | 16/6/2026 | Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) Username and (2) Password fields. | |
| Modificada | Alta (7.5) | 1.8% | — | Thomas Waggershauser AIR Filemanager | 10/4/2009 | 16/6/2026 | Unspecified vulnerability in Frontend Filemanager (air_filemanager) 0.6.1 and earlier extension for TYPO3 allows remote attackers to execute arbitrary commands via unknown vectors. | |
| Modificada | Media (6.4) | 2.3% | 💥 Exploit | Libra File Manager PHP Filemanager | 29/9/2008 | 16/6/2026 | fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass authentication, and read arbitrary files, modify arbitrary files, and list arbitrary directories, by inserting certain user and isadmin parameters in the query string. | |
| Modificada | Alta (10) | 1.9% | — | Typo3 AIR Filemanager | 19/5/2008 | 16/6/2026 | Unspecified vulnerability in the air_filemanager 0.6.0 and earlier extension for TYPO3 allows remote attackers to execute arbitrary PHP code via unspecified vectors related to "insufficient file filtering." | |
| Modificada | Media (4.3) | 0.84% | — | Typo3 AIR Filemanager | 19/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the air_filemanager 0.6.0 and earlier extension for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Qtofilemanager | 7/5/2008 | 16/6/2026 | Unrestricted file upload vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension, then accessing it via a direct request. | |
| Modificada | Alta (7.5) | 7.7% | 💥 Exploit | Wordpress Filemanager | 10/1/2008 | 16/6/2026 | Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remote attackers to upload and execute arbitrary PHP code via unspecified vectors. | |
| Modificada | Media (6.8) | 1.3% | — | Platon Phpwebfilemanager | 1/8/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in index.php in phpWebFileManager 0.5 allows remote attackers to execute arbitrary PHP code via a URL in the PN_PathPrefix parameter. NOTE: this issue is disputed by a reliable third party, who demonstrates that PN_PathPrefix is defined before use | |
| Modificada | Alta (7.5) | 1.2% | — | Easy-content Filemanager | 16/1/2007 | 16/6/2026 | Unspecified vulnerability in easy-content filemanager allows remote attackers to upload or modify arbitrary files via unspecified vectors. | |
| Modificada | Media (5.1) | 3.2% | 💥 Exploit | Knusperleicht Filemanager | 5/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remote attackers to execute arbitrary PHP code via a URL in the (1) dwl_download_path or (2) dwl_include_path parameters. | |
| Modificada | Media (5.8) | 1.8% | 💥 Exploit | Qtofilemanager | 7/7/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the (1) delete, (2) pathext, and (3) edit parameters. | |
| Modificada | Media (6.4) | 1.4% | — | Qtofilemanager | 7/7/2006 | 16/6/2026 | Directory traversal vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to modify arbitrary files via a .. (dot dot) sequence in the edit parameter. | |
| Modificada | Media (5.8) | 1.5% | — | Qtofilemanager | 22/6/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in qtofm.php4 in QTOFileManager 1.0 allows remote attackers to inject arbitrary web script or HTML via the msg parameter, as originally reported for index.php. | |
| Modificada | Media (5) | 8.2% | 💥 Exploit | Easyweb Filemanager | 23/7/2004 | 16/6/2026 | Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbitrary files via a .. (dot dot) in the pathext parameter. | |
| Modificada | Media (5) | 1.5% | — | Ondrej Jombik Phpwebfilemanager | 31/12/2003 | 16/6/2026 | Directory traversal vulnerability in plugins/file.php in phpWebFileManager before 0.4.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the fm_path parameter. | |
| Modificada | Baja (3.6) | 0.29% | — | Ralf Hoffmann Worker Filemanager | 31/12/2003 | 16/6/2026 | Worker Filemanager 1.0 through 2.7 sets the permissions on the destination directory to world-readable and executable while copying data, which could allow local users to obtain sensitive information. |