Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

92 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.3%—Afian Filerun6/3/201817/6/2026
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata&section=cpanel&page=list_filetypes request.
ModificadaAlta (7.2)1.3%—Afian Filerun6/3/201817/6/2026
Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=users&section=cpanel&page=list request.
ModificadaCrítica (9.8)59%💥 ExploitSolarwinds Backup ProfilerSolarwinds Storage ManagerSolarwinds Storage Profiler20/12/201716/6/2026
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field.
ModificadaCrítica (9.8)2.6%💥 ExploitFilerun30/9/201717/6/2026
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).
ModificadaMedia (5.3)1.6%—Miniprofiler Rack-mini-profiler2/5/201717/6/2026
The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks.
ModificadaMedia (6.8)2.3%💥 ExploitOpenfiler30/9/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Openfiler 2.99.1 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown or (2) reboot the server via a request to admin/system_shutdown.html.
ModificadaMedia (4.3)0.98%—Openfiler18/6/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Openfiler 2.99 allow remote attackers to inject arbitrary web script or HTML via the (1) TinkerAjax parameter to uptime.html, or remote authenticated users to inject arbitrary web script or HTML via the (2) MaxInstances, (3) PassivePorts, (4) Port, (5) ServerName,…
ModificadaMedia (5.8)1.4%—Skyarts Neofiler12/1/201417/6/2026
Directory traversal vulnerability in the NeoFiler application 5.4.3 and earlier, NeoFiler Free application 5.4.3 and earlier, and NeoFiler Lite application 2.4.2 and earlier for Android allows attackers to overwrite or create arbitrary files via unspecified vectors.
ModificadaMedia (5.8)1.2%—Yuichiro Okuyama Tetra FilerYuichiro Okuyama Tetra Filer Free12/1/201417/6/2026
Directory traversal vulnerability in the tetra filer application 2.3.1 and earlier for Android 4.0.3, tetra filer free application 2.3.1 and earlier for Android 4.0.3, tetra filer application 1.5.1 and earlier for Android before 4.0.3, and tetra filer free application 1.5.1 and earlier for Android before 4.0.3 allows…
ModificadaAlta (7.5)0.97%💥 ExploitJoomla COM ComprofilerJoomlapolis Community BuilderMambo COM Comprofiler6/5/200816/6/2026
SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action to index.php.
ModificadaMedia (6.8)1.2%—Phpmyprofiler26/9/200716/6/2026
PHP remote file inclusion vulnerability in include/plugin/block.t.php in Peter Schmidt phpmyProfiler 0.9.6b allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter. NOTE: this issue is disputed by CVE because the applicable require_once is in a function that is not called on a…
ModificadaAlta (7.1)3.9%💥 ExploitW3filer3/7/200716/6/2026
Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or crash) and possibly execute arbitrary code by sending a large banner to a client that is sending a file.
ModificadaAlta (7.5)1.8%—Filerun2/5/200716/6/2026
SQL injection vulnerability in index.php in FileRun 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter.
ModificadaMedia (5.8)1.6%—Filerun2/5/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in index.php in FileRun 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) module, or (3) section parameter.
ModificadaMedia (5.1)4.0%💥 ExploitPhpmyprofiler10/10/200616/6/2026
PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter.
ModificadaMedia (6.8)5.0%💥 ExploitJoomla COM Comprofiler ComponentMambo COM Comprofiler Component6/9/200616/6/2026
PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter.
ModificadaBaja (2.1)0.30%—ROX Filer31/12/200216/6/2026
ROX Filer 1.1.9 and 1.2 is installed with world writable permissions, which allows local users to write to arbitrary files.
Orbitaley — Vulnerabilidades