Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
736 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.43% | — | Gtsteffaniak Filebrowser Quantum | 25/2/2026 | 17/6/2026 | FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to versions 1.1.3-stable and 1.2.6-beta, when users share password-protected files, the recipient can completely bypass the password and still download the file. This happens because the API returns a direct download link in the details of the… | |
| Analizada | Alta (8.1) | 0.56% | — | Filebrowser | 9/2/2026 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, an authenticated user can bypass the application's "Disallow" file path rules by modifying the request URL. By adding multiple slashes (e.g., //private/)… | |
| Analizada | Media (5.4) | 0.41% | — | Filebrowser | 9/2/2026 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Prior to 2.57.1, a case-sensitivity flaw in the password validation logic allows any authenticated user to change their password (or an admin to change any user's password)… | |
| Aplazada | Media (5.8) | 0.17% | — | Nixos Captive BrowserAI | 9/2/2026 | 17/6/2026 | captive browser, a dedicated Chrome instance to log into captive portals without messing with DNS settings. In 25.05 and earlier, when programs.captive-browser is enabled, any user of the system can run arbitrary commands with the CAP_NET_RAW capability (binding to privileged ports, spoofing localhost traffic from… | |
| Aplazada | Alta (8.7) | 0.48% | — | Ajax File BrowserAI | 28/1/2026 | 17/6/2026 | PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary web server locations. Attackers can upload a .txt webshell, rename it to .php, and move it to accessible directories using double-encoded path traversal techniques. | |
| Modificada | Alta (7.8) | 0.81% | — | Browserstack-local | 28/1/2026 | 15/7/2026 | The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js. | |
| Aplazada | Media (4.8) | 0.24% | — | Ajax File BrowserAI | 28/1/2026 | 17/6/2026 | PDW File Browser version 1.3 contains stored and reflected cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through file rename and path parameters. Attackers can craft malicious URLs or rename files with XSS payloads to execute arbitrary JavaScript in victims'… | |
| Analizada | Media (5.3) | 0.48% | — | Filebrowser | 19/1/2026 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and can be used to upload, delete, preview, rename, and edit files. Prior to version 2.55.0, the JSONAuth. Auth function contains a logic flaw that allows unauthenticated attackers to enumerate valid usernames by measuring the response time… | |
| Aplazada | Media (6.7) | 0.23% | — | Cyberfox WEB BrowserAI | 15/1/2026 | 17/6/2026 | Cyberfox Web Browser 52.9.1 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the search bar with excessive data. Attackers can generate a 9,000,000 byte payload and paste it into the search bar to trigger an application crash. | |
| Modificada | Media (5.4) | 0.29% | — | Heytap Internet Browser | 5/1/2026 | 5/7/2026 | An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage in the built-in HeyTap/ColorOS browser. NOTE: The supplier is currently disputing this finding and the record is under review. | |
| Analizada | Alta (7.1) | 0.14% | — | Keepassxc-browser | 17/12/2025 | 17/6/2026 | KeePassXC-Browser thru 1.9.9.2 autofills or prompts to fill stored credentials into documents rendered under a browser-enforced CSP directive and iframe attribute sandbox, allowing attacker-controlled script in the sandboxed document to access populated form fields and exfiltrate credentials. | |
| Aplazada | Alta (8.5) | 0.14% | — | Lenovo APP StoreAILenovo BrowserAI | 10/12/2025 | 25/9/2026 | A DLL hijacking vulnerability was reported in the Lenovo App Store and Lenovo Browser applications that could allow a local authenticated user to execute code with elevated privileges under certain conditions. | |
| Aplazada | Media (4.4) | 0.09% | — | Paloaltonetworks Prisma BrowserAI | 14/11/2025 | 17/6/2026 | A sensitive information disclosure vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to retrieve sensitive data from Prisma Browser. Browser self-protection should be enabled to mitigate this issue. | |
| Aplazada | Baja (1.1) | 0.11% | — | Paloaltonetworks Prisma BrowserAI | 14/11/2025 | 17/6/2026 | An insufficient validation of an untrusted input vulnerability in Palo Alto Networks Prisma® Browser allows a locally authenticated non-admin user to revert the browser’s security controls. | |
| Aplazada | Baja (1.1) | 0.13% | — | Paloaltonetworks Prisma BrowserAI | 14/11/2025 | 30/9/2026 | An insufficient policy enforcement vulnerability in Palo Alto Networks Prisma® Browser on Windows allows a locally authenticated non-admin user to bypass the screenshot control feature of the browser. Browser self-protection should be enabled to mitigate this issue. | |
| Analizada | Alta (7.2) | 0.43% | — | Filebrowser | 12/11/2025 | 17/6/2026 | File Browser provides a file managing interface within a specified directory and it can be used to upload, delete, preview, rename and edit files. Versions prior to 2.45.1 have an Insecure Direct Object Reference (IDOR) vulnerability in the FileBrowser application's share deletion functionality. This vulnerability… | |
| Aplazada | Alta (7.7) | 0.21% | — | Lenovo PC ManagerAILenovo APP StoreAILenovo BrowserAILenovo Legion ZoneAI | 12/11/2025 | 17/6/2026 | A potential vulnerability was reported in the Lenovo PC Manager, Lenovo App Store, Lenovo Browser, and Lenovo Legion Zone client applications that, under certain conditions, could allow an attacker on the same logical network to execute arbitrary code. | |
| Analizada | Media (6.5) | 0.37% | — | Netsurf-browser Netsurf | 3/11/2025 | 17/6/2026 | An issue in NetSurf v3.11 causes the application to read uninitialized heap memory when creating a dom_event structure. | |
| Analizada | Media (6.5) | 0.32% | — | Netsurf-browser Netsurf | 3/11/2025 | 17/6/2026 | NetSurf 3.11 is vulnerable to Use After Free in dom_node_set_text_content function. | |
| Analizada | Media (6.5) | 0.44% | — | Netsurf-browser Netsurf | 3/11/2025 | 17/6/2026 | An issue in NetSurf v.3.11 allows a remote attacker to execute arbitrary code via the dom_node_normalize function | |
| Aplazada | Media (6.5) | 0.33% | — | Brave BrowserAI | 31/10/2025 | 17/6/2026 | In Brave Browser Desktop versions prior to 1.83.10 that have the split view feature enabled, the "Open Link in Split View" context menu item did not respect the SameSite cookie attribute. Therefore SameSite=Strict cookies would be sent on a cross-site navigation using this method. | |
| Aplazada | Media (6.1) | 0.15% | — | Browser SniffAI | 20/9/2025 | 17/6/2026 | The Browser Sniff plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.3. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to update settings and inject malicious web scripts via a forged request… | |
| Aplazada | Alta (8.5) | 0.17% | — | Lenovo BrowserAI | 11/9/2025 | 17/6/2026 | A potential DLL hijacking vulnerability was discovered in Lenovo Browser during an internal security assessment that could allow a local user to execute code with elevated privileges. | |
| Modificada | Crítica (9.1) | 0.71% | — | Browserify Sha.js | 20/8/2025 | 17/6/2026 | Improper Input Validation vulnerability in sha.js allows Input Data Manipulation.This issue affects sha.js: through 2.4.11. | |
| Modificada | Crítica (9.1) | 0.53% | — | Browserify Cipher-base | 20/8/2025 | 17/6/2026 | Improper Input Validation vulnerability in cipher-base allows Input Data Manipulation.This issue affects cipher-base: through 1.0.4. |