Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
92 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.3% | — | Afian Filerun | 6/3/2018 | 17/6/2026 | Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata§ion=cpanel&page=list_filetypes request. | |
| Modificada | Alta (7.2) | 1.3% | — | Afian Filerun | 6/3/2018 | 17/6/2026 | Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=users§ion=cpanel&page=list request. | |
| Modificada | Crítica (9.8) | 59% | 💥 Exploit | Solarwinds Backup ProfilerSolarwinds Storage ManagerSolarwinds Storage Profiler | 20/12/2017 | 16/6/2026 | SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Profiler before 5.1.2, and SolarWinds Backup Profiler before 5.1.2 allows remote attackers to execute arbitrary SQL commands via the loginName field. | |
| Modificada | Crítica (9.8) | 2.6% | 💥 Exploit | Filerun | 30/9/2017 | 17/6/2026 | FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function). | |
| Modificada | Media (5.3) | 1.6% | — | Miniprofiler Rack-mini-profiler | 2/5/2017 | 17/6/2026 | The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks. | |
| Modificada | Media (6.8) | 2.3% | 💥 Exploit | Openfiler | 30/9/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Openfiler 2.99.1 allow remote attackers to hijack the authentication of administrators for requests that (1) shutdown or (2) reboot the server via a request to admin/system_shutdown.html. | |
| Modificada | Media (4.3) | 0.98% | — | Openfiler | 18/6/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Openfiler 2.99 allow remote attackers to inject arbitrary web script or HTML via the (1) TinkerAjax parameter to uptime.html, or remote authenticated users to inject arbitrary web script or HTML via the (2) MaxInstances, (3) PassivePorts, (4) Port, (5) ServerName,… | |
| Modificada | Media (5.8) | 1.4% | — | Skyarts Neofiler | 12/1/2014 | 17/6/2026 | Directory traversal vulnerability in the NeoFiler application 5.4.3 and earlier, NeoFiler Free application 5.4.3 and earlier, and NeoFiler Lite application 2.4.2 and earlier for Android allows attackers to overwrite or create arbitrary files via unspecified vectors. | |
| Modificada | Media (5.8) | 1.2% | — | Yuichiro Okuyama Tetra FilerYuichiro Okuyama Tetra Filer Free | 12/1/2014 | 17/6/2026 | Directory traversal vulnerability in the tetra filer application 2.3.1 and earlier for Android 4.0.3, tetra filer free application 2.3.1 and earlier for Android 4.0.3, tetra filer application 1.5.1 and earlier for Android before 4.0.3, and tetra filer free application 1.5.1 and earlier for Android before 4.0.3 allows… | |
| Modificada | Alta (7.5) | 0.97% | 💥 Exploit | Joomla COM ComprofilerJoomlapolis Community BuilderMambo COM Comprofiler | 6/5/2008 | 16/6/2026 | SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allows remote attackers to execute arbitrary SQL commands via the user parameter in a userProfile action to index.php. | |
| Modificada | Media (6.8) | 1.2% | — | Phpmyprofiler | 26/9/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in include/plugin/block.t.php in Peter Schmidt phpmyProfiler 0.9.6b allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter. NOTE: this issue is disputed by CVE because the applicable require_once is in a function that is not called on a… | |
| Modificada | Alta (7.1) | 3.9% | 💥 Exploit | W3filer | 3/7/2007 | 16/6/2026 | Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or crash) and possibly execute arbitrary code by sending a large banner to a client that is sending a file. | |
| Modificada | Alta (7.5) | 1.8% | — | Filerun | 2/5/2007 | 16/6/2026 | SQL injection vulnerability in index.php in FileRun 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the fid parameter. | |
| Modificada | Media (5.8) | 1.6% | — | Filerun | 2/5/2007 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in index.php in FileRun 1.0 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) page, (2) module, or (3) section parameter. | |
| Modificada | Media (5.1) | 4.0% | 💥 Exploit | Phpmyprofiler | 10/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter. | |
| Modificada | Media (6.8) | 5.0% | 💥 Exploit | Joomla COM Comprofiler ComponentMambo COM Comprofiler Component | 6/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joomla! allows remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter. | |
| Modificada | Baja (2.1) | 0.30% | — | ROX Filer | 31/12/2002 | 16/6/2026 | ROX Filer 1.1.9 and 1.2 is installed with world writable permissions, which allows local users to write to arbitrary files. |