Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2724▼ 159 respecto a la semana anterior
Críticas / altas1243▼ 302 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)245▲ 198 respecto a la semana anterior
–

2409 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.18%—Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+2511/8/202317/6/2026
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.38%—Bitberry File Opener8/8/20239/7/2026
Un problema en la función de extracción de archivos CAB de Bitberry FIle Opener v23.0 permite a los atacantes ejecutar un salto de directorios.
ModificadaAlta (7.8)0.16%—Cisco Broadworks Application Delivery PlatformCisco Broadworks Application ServerCisco Broadworks Database ServerCisco Broadworks Execution Server+83/8/202317/6/2026
A vulnerability in the privilege management functionality of all Cisco BroadWorks server types could allow an authenticated, local attacker to elevate privileges to root on an affected system. This vulnerability is due to incorrect implementation of user role permissions. An attacker could exploit this vulnerability…
ModificadaMedia (6.1)0.52%—Iscute Cute Http File Server3/8/202317/6/2026
A vulnerability, which was classified as problematic, was found in Cute Http File Server 2.0. This affects an unknown part of the component Search. The manipulation leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaMedia (5.4)0.57%—Wifi File Explorer Project Wifi File Explorer20/7/202317/6/2026
A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed…
ModificadaMedia (5.4)0.60%—Webile Wifi PC File Transfer Project Webile Wifi PC File Transfer20/7/202317/6/2026
Se ha encontrado una vulnerabilidad en Webile v1.0.1. Se ha clasificado como problemática. Una función desconocida del componente "HTTP POST Request Handler" es la afectada. La manipulación del argumento "new_file_name/c" conduce a Cross-Site Scripting (XSS). Es posible lanzar el ataque de forma remota. El exploit ha…
ModificadaAlta (7.8)0.36%—Libsndfile Project Libsndfile18/7/202317/6/2026
Multiple signed integers overflow in function au_read_header in src/au.c and in functions mat4_open and mat4_read_header in src/mat4.c in Libsndfile, allows an attacker to cause Denial of Service or other unspecified impacts.
ModificadaAlta (7.8)0.34%—Libsndfile Project Libsndfile18/7/202317/6/2026
An off-by-one error in function wav_read_header in src/wav.c in Libsndfile 1.1.0, results in a write out of bound, which allows an attacker to execute arbitrary code, Denial of Service or other unspecified impacts.
ModificadaAlta (8.8)0.87%—Metagauss Profilegrid18/7/202317/6/2026
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'edit_group' handler in versions up to, and including, 5.5.2. This makes it possible for authenticated attackers, with group ownership, to update group options, including the…
ModificadaAlta (8.8)0.80%—Metagauss Profilegrid18/7/202317/6/2026
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'profile_magic_check_smtp_connection' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to…
ModificadaMedia (4.3)0.57%—Metagauss Profilegrid18/7/202317/6/2026
The ProfileGrid plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'pm_upload_csv' function in versions up to, and including, 5.5.1. This makes it possible for authenticated attackers, with subscriber-level permissions or above to import new users and…
ModificadaCrítica (9.8)1.7%—Syncfusion EJ2 Aspcore File Provider12/7/202317/6/2026
The Syncfusion EJ2 ASPCore File Provider 3ac357f is vulnerable to Models/PhysicalFileProvider.cs directory traversal. As a result, an unauthenticated attacker can list files within a directory, download any file, or upload any file to any directory accessible by the web server.
ModificadaCrítica (9.8)1.9%—Syncfusion Nodejs File System Provider12/7/202317/6/2026
The Syncfusion EJ2 Node File Provider 0102271 is vulnerable to filesystem-server.js directory traversal. As a result, an unauthenticated attacker can: - On Windows, list files in any directory, read any file, delete any file, upload any file to any directory accessible by the web server. - On Linux, read any file,…
ModificadaMedia (6)0.20%—Cisco Broadworks Application Delivery Platform FirmwareCisco Broadworks Application Server FirmwareCisco Broadworks Database Server FirmwareCisco Broadworks Database Troubleshooting Server Firmware+1212/7/202317/6/2026
A vulnerability in Cisco BroadWorks could allow an authenticated, local attacker to elevate privileges to the root user on an affected device. The vulnerability is due to insufficient input validation by the operating system CLI. An attacker could exploit this vulnerability by issuing a crafted command to the affected…
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitCitrix Sharefile Storage Zones Controller10/7/202317/6/2026
A vulnerability has been discovered in the customer-managed ShareFile storage zones controller which, if exploited, could allow an unauthenticated attacker to remotely compromise the customer-managed ShareFile storage zones controller.
ModificadaCrítica (9.8)2.3%💥 PoCTecrail Responsive Filemanager28/6/202317/6/2026
In Responsive Filemanager < 9.12.0, an attacker can bypass upload restrictions resulting in RCE.
ModificadaAlta (7.5)0.84%—M-files Server27/6/202317/6/2026
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service
ModificadaCrítica (9.8)40%💥 ExploitAdvancedfilemanager File Manager Advanced Shortcode27/6/202317/6/2026
The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.
ModificadaMedia (4.8)0.44%—Wpfactory File Renaming ON Upload19/6/202317/6/2026
The File Renaming on Upload WordPress plugin before 2.5.2 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (5.4)0.37%—File Away Project File Away12/6/202317/6/2026
The File Away WordPress plugin through 3.9.9.0.1 does not validate and escape one of its shortcode attributes, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attack.
ModificadaMedia (4.8)0.37%—Aviplugins WP Register Profile With Shortcode12/6/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Aviplugins.Com WP Register Profile With Shortcode plugin <= 3.5.7 versions.
ModificadaMedia (5.5)0.38%—Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO9/6/202317/6/2026
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 4.19.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with…
ModificadaMedia (4.9)1.7%—Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO9/6/202317/6/2026
The WordPress File Upload and WordPress File Upload Pro plugins for WordPress are vulnerable to Path Traversal in versions up to, and including, 4.19.1 via the vulnerable parameter wfu_newpath. This allows administrator-level attackers to move files uploaded with the plugin (located in wp-content/uploads by default)…
ModificadaMedia (5.3)0.80%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due to lacking authorization protections, checks against users editing other's posts, and lacking a security nonce, all on the wpfm_edit_file_title_desc AJAX action. This…
ModificadaAlta (8.8)1.9%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for subscriber-level attackers to edit the plugin…
Orbitaley — Vulnerabilidades