Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.69% | 💥 Exploit | Liquidfiles | 30/9/2025 | 17/6/2026 | LiquidFiles filetransfer server is vulnerable to a user enumeration issue in its password reset functionality. The application returns distinguishable responses for valid and invalid email addresses, allowing unauthenticated attackers to determine the existence of user accounts. Version 4.2 introduces user-based… | |
| Modificada | Alta (7) | 0.26% | — | M-files Hubshare | 15/9/2025 | 17/6/2026 | Stored cross-site scripting vulnerability in M-Files Hubshare before version 25.8 allows authenticated attackers to cause script execution for other users. | |
| Aplazada | Media (6.5) | 0.43% | — | Miniorange Prevent Files Folders AccessAI | 20/8/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in miniOrange Prevent files / folders access prevent-file-access allows Path Traversal.This issue affects Prevent files / folders access: from n/a through <= 2.6.0. | |
| Analizada | Media (6.1) | 0.22% | — | Shopfiles Ebook Store | 16/8/2025 | 17/6/2026 | The Ebook Store WordPress plugin before 5.8015 does not escape the $_SERVER['REQUEST_URI'] parameter before outputting it back in an attribute, which could lead to Reflected Cross-Site Scripting in old web browsers. | |
| Aplazada | Media (4.3) | 0.13% | — | Shopfiles Ebook StoreAI | 14/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in motov.net Ebook Store ebook-store allows Cross Site Request Forgery.This issue affects Ebook Store: from n/a through <= 5.8013. | |
| Analizada | Baja (3.8) | 0.53% | — | Liquidfiles | 4/8/2025 | 17/6/2026 | LiquidFiles before 4.1.2 allows directory traversal by configuring the pathname of a local executable file as an Actionscript. | |
| Analizada | Alta (8.8) | 0.55% | — | Liquidfiles | 4/8/2025 | 17/6/2026 | LiquidFiles before 4.1.2 supports FTP SITE CHMOD for mode 6777 (setuid and setgid), which allows FTPDrop users to execute arbitrary code as root by leveraging the Actionscript feature and the sudoers configuration. | |
| Analizada | Crítica (9.2) | 0.32% | — | Humhub Files | 2/8/2025 | 2/9/2026 | Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, Files does not have logic to prevent the exploitation of backend SQL queries without direct output, potentially allowing unauthorized data access. This is fixed in version 0.16.10. | |
| Analizada | Media (5.1) | 0.28% | — | Humhub Files | 2/8/2025 | 2/9/2026 | Files is a module for managing files inside spaces and user profiles. In versions 0.16.9 and below, the File Move functionality does not contain logic that prevents injection of arbitrary JavaScript, which can lead to Browser JS code execution in the context of the user’s session. This is fixed in version 0.16.10. | |
| Aplazada | Crítica (9.8) | 1.3% | — | Shopfiles Ebook StoreAI | 24/7/2025 | 17/6/2026 | The Ebook Store plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the ebook_store_save_form function in all versions up to, and including, 5.8012. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may… | |
| Aplazada | Alta (7) | 0.24% | — | Joomla ProfilesAI | 23/7/2025 | 17/6/2026 | A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered. | |
| Aplazada | Alta (7.7) | 0.76% | — | Files-bucket-serverAI | 23/7/2025 | 17/6/2026 | All versions of the package files-bucket-server are vulnerable to Directory Traversal where an attacker can traverse the file system and access files outside of the intended directory. | |
| Aplazada | Media (4.4) | 0.23% | — | Shopfiles Ebook StoreAI | 21/7/2025 | 17/6/2026 | The Ebook Store plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Order Details in all versions up to, and including, 5.8012 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access, to inject arbitrary web… | |
| Aplazada | Media (6.9) | 0.39% | — | JoomlaAIJoomla RsfilesAI | 18/7/2025 | 17/6/2026 | A DOS vulnerability in RSFiles! component 1.16.3-1.17.7 Joomla was discovered. The issue allows unauthenticated remote attackers to deny access to service via the search feature. | |
| Aplazada | Alta (7.3) | 0.58% | — | Modelcontextprotocol FilesystemAI | 2/7/2025 | 17/6/2026 | Model Context Protocol Servers is a collection of reference implementations for the model context protocol (MCP). Versions of Filesystem prior to 0.6.4 or 2025.7.01 could allow access to unintended files in cases where the prefix matches an allowed directory. Users are advised to upgrade to 0.6.4 or 2025.7.01 resolve. | |
| Aplazada | Media (5.9) | 0.20% | — | Shopfiles Ebook StoreAI | 17/6/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in motov.net Ebook Store ebook-store allows Stored XSS.This issue affects Ebook Store: from n/a through <= 5.8008. | |
| Modificada | Media (4.8) | 0.27% | — | M-files Mobile | 16/6/2025 | 17/6/2026 | An open redirection vulnerability in M-Files mobile applications for Android and iOS prior to version 25.6.0 allows attackers to use maliciously crafted PDF files to trick other users into making requests to untrusted URLs. | |
| Modificada | Alta (8.4) | 13% | 💥 PoC | M-files Server | 15/6/2025 | 17/6/2026 | A path traversal issue in the API endpoint in M-Files Server before version 25.6.14925.0 allows an authenticated user to read files in the server. | |
| Aplazada | Alta (7.2) | 0.36% | — | Shared FilesAI | 3/6/2025 | 17/6/2026 | The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via html File uploads in all versions up to, and including, 1.7.48 due to insufficient input sanitization and output escaping within the sanitize_file() function. This makes it possible… | |
| Aplazada | Media (6.5) | 0.26% | — | Shopfiles Ebook StoreAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in motov.net Ebook Store ebook-store allows DOM-Based XSS.This issue affects Ebook Store: from n/a through <= 5.8009. | |
| Aplazada | Media (5.3) | 0.40% | — | Prevent Direct Access Protect Wordpress FilesAI | 25/4/2025 | 17/6/2026 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.8.8 via the 'generate_unique_string' due to insufficient randomness of the generated file name. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.5) | 0.35% | — | Wpwham Checkout Files Upload FOR WoocommerceAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout-files-upload-woocommerce allows Stored XSS.This issue affects Checkout Files Upload for WooCommerce: from n/a through <= 2.2.0. | |
| Aplazada | Alta (8.8) | 0.39% | — | John James Jacoby WP User ProfilesAI | 10/4/2025 | 17/6/2026 | Incorrect Privilege Assignment vulnerability in John James Jacoby WP User Profiles wp-users-profiles allows Privilege Escalation.This issue affects WP User Profiles: from n/a through <= 2.6.2. | |
| Modificada | Media (5.1) | 0.27% | — | M-files WEB | 4/4/2025 | 17/6/2026 | Stored XSS in M-Files Web versions from 25.1.14445.5 to 25.2.14524.4 allows an authenticated user to run scripts | |
| Modificada | Media (6.3) | 0.42% | — | M-files Server | 4/4/2025 | 17/6/2026 | Improper isolation of users in M-Files Server version before 25.3.14549 allows anonymous user to affect other anonymous users views and possibly cause a denial of service |