Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2697▼ 181 respecto a la semana anterior
Críticas / altas1225▼ 327 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)244▲ 208 respecto a la semana anterior
–

2409 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.41%—Properfraction Profilepress3/5/202317/6/2026
Auth. (contributor+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.4 versions.
ModificadaAlta (8.1)0.99%—Cozmoslabs Profile Builder27/4/202317/6/2026
The Profile Builder – User Profile & User Registration Forms plugin for WordPress is vulnerable to unauthorized password resets in versions up to, and including 3.9.0. This is due to the plugin using native password reset functionality, with insufficient validation on the password reset function…
ModificadaAlta (7.8)0.18%—M-files Server20/4/202317/6/2026
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
ModificadaAlta (7.5)0.80%—M-files Server20/4/202317/6/2026
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a scheduled job.
ModificadaAlta (7.5)0.84%—M-files Server20/4/202317/6/2026
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.
ModificadaAlta (8.8)0.63%—Nextcloud Files Automated TaggingNextcloud Server17/4/202317/6/2026
Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that the Nextcloud Server is upgraded to…
ModificadaMedia (6.1)0.54%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 717/4/202317/6/2026
The Drag and Drop Multiple File Upload PRO - Contact Form 7 Standard WordPress plugin before 2.11.1 and Drag and Drop Multiple File Upload PRO - Contact Form 7 with Remote Storage Integrations WordPress plugin before 5.0.6.4 do not sanitise and escape a parameter before outputting it back in the page, leading to a…
ModificadaCrítica (9.8)6.1%💥 ExploitFilereplicationpro File Replication PRO14/4/202317/6/2026
Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access.
ModificadaMedia (4.8)0.42%—Properfraction Profilepress6/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team ProfilePress plugin <= 4.5.3 versions.
ModificadaMedia (6.5)0.79%—M-files Server5/4/202317/6/2026
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.
ModificadaMedia (6.1)0.41%—Properfraction Profilepress29/3/202317/6/2026
Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in ProfilePress Membership Team Paid Membership Plugin, Ecommerce, Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin <= 4.5.3 versions.
ModificadaAlta (7.8)0.21%—M-files29/3/202317/6/2026
Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking.
ModificadaMedia (6.1)0.43%—File Management System Project File Management System27/3/202317/6/2026
A cross-site scripting (XSS) vulnerability in File Management Project 1.0.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name field under the Edit User module.
ModificadaMedia (4.8)0.44%—Simplefilelist Simple File List27/3/202317/6/2026
The Simple File List WordPress plugin before 6.0.10 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
ModificadaAlta (8.8)0.82%—Metagauss Profilegrid20/3/202317/6/2026
The ProfileGrid WordPress plugin before 5.3.1 provides an AJAX endpoint for resetting a user password but does not implement proper authorization. This allows a user with low privileges, such as subscriber, to change the password of any account, including Administrator ones.
ModificadaBaja (3.3)0.15%—Samsung Myfiles16/3/202317/6/2026
Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific conditions.
ModificadaMedia (5.4)0.40%—Themekraft Post Form Registration Form Profile Form FOR User Profiles AND Content Forms16/3/202317/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
ModificadaMedia (6.1)0.60%—File Tracker Manager System Project File Tracker Management System9/3/202317/6/2026
A vulnerability, which was classified as problematic, was found in SourceCodester File Tracker Manager System 1.0. This affects an unknown part of the file normal/borrow1.php. The manipulation of the argument id with the input 1"><script>alert(1111)</script> leads to cross site scripting. It is possible to initiate…
ModificadaCrítica (9.8)0.82%—File Tracker Manager System Project File Tracker Management System9/3/202317/6/2026
A vulnerability was found in SourceCodester File Tracker Manager System 1.0. It has been classified as critical. Affected is an unknown function of the file /file_manager/login.php of the component POST Parameter Handler. The manipulation of the argument username leads to sql injection. It is possible to launch the…
ModificadaAlta (7.6)0.36%—M-files Server6/3/202317/6/2026
Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information. This issue affects M-Files New Web: before 22.12.12140.3.
ModificadaAlta (7.5)0.67%—M-files Server6/3/202317/6/2026
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0.
ModificadaCrítica (9.8)3.0%💥 PoCCodedropz Drag AND Drop Multiple File Upload - Contact Form 71/3/202317/6/2026
A vulnerability was found in Drag and Drop Multiple File Upload Contact Form 7 5.0.6.1 on WordPress. It has been classified as critical. Affected is an unknown function of the file admin-ajax.php. The manipulation of the argument upload_name leads to relative path traversal. It is possible to launch the attack…
ModificadaMedia (5.4)0.63%—Simple File Downloader Project Simple File Downloader21/2/202317/6/2026
The Simple File Downloader WordPress plugin through 1.0.4 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks
ModificadaAlta (7.5)49%💥 PoCApache Commons FileuploadDebian Linux20/2/20237/10/2026
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
ModificadaAlta (7.8)0.23%—Xoslab Easy File Locker18/2/202317/6/2026
A vulnerability, which was classified as problematic, was found in Xoslab Easy File Locker 2.2.0.184. This affects the function MessageNotifyCallback in the library xlkfs.sys. The manipulation leads to denial of service. Local access is required to approach this attack. The exploit has been disclosed to the public and…