Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2716▼ 140 respecto a la semana anterior
Críticas / altas1239▼ 295 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 207 respecto a la semana anterior
2409 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.76% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. This is due to lacking authentication protections and santisation all on the wpfm_edit_file_title_desc AJAX action. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (5.3) | 0.88% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security nonce on the wpfm_delete_file AJAX action. This makes it possible for unauthenticated attackers to… | |
| Modificada | Crítica (9.8) | 1.5% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for… | |
| Modificada | Media (5.3) | 0.68% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for unauthenticated… | |
| Modificada | Media (5.3) | 0.67% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email AJAX action. This makes it possible for unauthenticated attackers to send emails using the site with a… | |
| Modificada | Media (5.4) | 0.47% | — | Najeebmedia Frontend File Manager Plugin | 7/6/2023 | 17/6/2026 | The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking mishandling the use of user IDs that is accessible by the visitor. This makes it possible for unauthenticated or authenticated attackers to access the information and… | |
| Modificada | Media (6.1) | 0.31% | — | Splunk APP FOR Lookup File Editing | 1/6/2023 | 17/6/2026 | In the Splunk App for Lookup File Editing versions below 4.0.1, a user can insert potentially malicious JavaScript code into the app, which causes that code to run on the user’s machine. The app itself does not contain the potentially malicious JavaScript code. The vulnerability requires the attacker to phish the… | |
| Modificada | Alta (8.1) | 43% | — | SplunkSplunk APP FOR Lookup File Editing | 1/6/2023 | 17/6/2026 | In the Splunk App for Lookup File Editing versions below 4.0.1, a low-privileged user can, with a specially crafted web request, trigger a path traversal exploit that can then be used to read and write to restricted areas of the Splunk installation directory. | |
| Modificada | Media (4.8) | 0.37% | — | Upload File Type Settings Plugin Project Upload File Type Settings Plugin | 26/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Sebastian Krysmanski Upload File Type Settings plugin <= 1.1 versions. | |
| Modificada | Alta (7.8) | 0.18% | — | M-files | 25/5/2023 | 17/6/2026 | Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications | |
| Modificada | Alta (8.8) | 0.25% | — | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 24/5/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload – Contact Form 7 plugin <= 1.3.6.5 versions. | |
| Modificada | Media (4.3) | 0.43% | — | Jenkins TAG Profiler | 16/5/2023 | 17/6/2026 | A missing permission check in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers with Overall/Read permission to reset profiler statistics. | |
| Modificada | Media (4.3) | 0.30% | — | Jenkins TAG Profiler | 16/5/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Tag Profiler Plugin 0.2 and earlier allows attackers to reset profiler statistics. | |
| Modificada | Alta (8.8) | 61% | — | Jenkins File Parameters | 16/5/2023 | 17/6/2026 | Jenkins File Parameter Plugin 285.v757c5b_67a_c25 and earlier does not restrict the name (and resulting uploaded file name) of Stashed File Parameters, allowing attackers with Item/Configure permission to create or replace arbitrary files on the Jenkins controller file system with attacker-specified content. | |
| Modificada | Media (5.4) | 0.36% | — | File Gallery Project File Gallery | 16/5/2023 | 17/6/2026 | Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in Bruno "Aesqe" Babic File Gallery plugin <= 1.8.5.3 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Shopfiles Ebook Store | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.775 versions. | |
| Modificada | Media (5.4) | 0.59% | — | File Tracker Manager System Project File Tracker Manager System | 12/5/2023 | 17/6/2026 | A vulnerability has been found in SourceCodester File Tracker Manager System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /file_manager/admin/save_user.php of the component POST Parameter Handler. The manipulation of the argument firstname leads to cross site scripting. The… | |
| Modificada | Crítica (9.8) | 0.73% | — | File Tracker Manager System Project File Tracker Manager System | 11/5/2023 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester File Tracker Manager System 1.0. This vulnerability affects unknown code of the file register/update_password.php of the component POST Parameter Handler. The manipulation of the argument new_password leads to sql injection. The attack can be initiated… | |
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Vtune Profiler | 10/5/2023 | 17/6/2026 | Uncontrolled search path element in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel Vtune Profiler | 10/5/2023 | 17/6/2026 | Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.4) | 0.49% | — | Responsivefilemanager | 9/5/2023 | 17/6/2026 | Cross Site Scripting vulnerability found in Trippo ResponsiveFilemanager v.9.14.0 and before allows a remote attacker to execute arbitrary code via the sort_by parameter in the dialog.php file. | |
| Modificada | Media (4.8) | 0.37% | — | Usbmemorydirect Simple Custom Author Profiles | 9/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in USB Memory Direct Simple Custom Author Profiles plugin <= 1.0.0 versions. | |
| Modificada | Baja (3.3) | 0.20% | — | Elastic Filebeat | 4/5/2023 | 17/6/2026 | Filebeat versions through 7.17.9 and 8.6.2 have a flaw in httpjson input that allows the http request Authorization or Proxy-Authorization header contents to be leaked in the logs when debug logging is enabled. | |
| Modificada | Media (6.1) | 0.41% | — | Properfraction Profilepress | 3/5/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions. |