Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

187 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)40%💥 ExploitAdvancedfilemanager File Manager Advanced Shortcode27/6/202317/6/2026
The File Manager Advanced Shortcode WordPress plugin through 2.3.2 does not adequately prevent uploading files with disallowed MIME types when using the shortcode. This leads to RCE in cases where the allowed MIME type list does not include PHP files. In the worst case, this is available to unauthenticated users.
ModificadaMedia (5.3)0.80%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Content Injection in versions up to, and including, 18.2. This is due to lacking authorization protections, checks against users editing other's posts, and lacking a security nonce, all on the wpfm_edit_file_title_desc AJAX action. This…
ModificadaAlta (8.8)1.9%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Authenticated Settings Change in versions up to, and including, 18.2. This is due to lacking capability checks and a security nonce, all on the wpfm_save_settings AJAX action. This makes it possible for subscriber-level attackers to edit the plugin…
ModificadaMedia (6.1)0.76%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to, and including, 18.2. This is due to lacking authentication protections and santisation all on the wpfm_edit_file_title_desc AJAX action. This makes it possible for unauthenticated attackers to…
ModificadaMedia (5.3)0.88%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary Post Deletion in versions up to, and including, 18.2. This is due to lacking authentication protections and lacking a security nonce on the wpfm_delete_file AJAX action. This makes it possible for unauthenticated attackers to…
ModificadaCrítica (9.8)1.5%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Arbitrary File Download in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for…
ModificadaMedia (5.3)0.68%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated Post Meta Change in versions up to, and including, 18.2. This is due to lacking authentication protections, capability checks, and sanitization, all on the wpfm_file_meta_update AJAX action. This makes it possible for unauthenticated…
ModificadaMedia (5.3)0.67%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Unauthenticated HTML Injection in versions up to, and including, 18.2. This is due to lacking authentication protections on the wpfm_send_file_in_email AJAX action. This makes it possible for unauthenticated attackers to send emails using the site with a…
ModificadaMedia (5.4)0.47%—Najeebmedia Frontend File Manager Plugin7/6/202317/6/2026
The Frontend File Manager plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 18.2. This is due to lacking mishandling the use of user IDs that is accessible by the visitor. This makes it possible for unauthenticated or authenticated attackers to access the information and…
ModificadaCrítica (9.8)1.1%—Prasathmani Tiny File Manager25/11/202217/6/2026
Tiny File Manager version 2.4.8 executes the code of files uploaded by users of the application, instead of just returning them for download. This is possible because the application is vulnerable to insecure file upload.
ModificadaMedia (6.5)0.89%—Prasathmani Tiny File Manager25/11/202217/6/2026
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to access the application's internal files. This is possible because the application is vulnerable to broken access control.
ModificadaAlta (8.8)0.44%—Prasathmani Tiny File Manager25/11/202217/6/2026
Tiny File Manager version 2.4.8 allows an unauthenticated remote attacker to persuade users to perform unintended actions within the application. This is possible because the application is vulnerable to CSRF.
ModificadaMedia (4.3)0.29%—Najeebmedia Frontend File Manager Plugin17/10/202217/6/2026
The Frontend File Manager Plugin WordPress plugin before 21.4 does not have CSRF check when uploading files, which could allow attackers to make logged in users upload files on their behalf
ModificadaAlta (8.8)1.5%—Najeebmedia Frontend File Manager3/10/202217/6/2026
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any authenticated users, such as subscriber, to rename a file to an arbitrary extension, like PHP, which could allow them to basically be able to upload arbitrary files on the server and achieve RCE
ModificadaMedia (5.3)8.3%💥 ExploitNajeebmedia Frontend File Manager3/10/202217/6/2026
The Frontend File Manager Plugin WordPress plugin before 21.3 allows any unauthenticated user to rename uploaded files from users. Furthermore, due to the lack of validation in the destination filename, this could allow allow them to change the content of arbitrary files on the web server
ModificadaMedia (4.9)1.1%—Xplodedthemes Wpide - File Manager & Code Editor23/8/202217/6/2026
Authenticated (admin+) Arbitrary File Read vulnerability in XplodedThemes WPide plugin <= 2.6 at WordPress.
ModificadaMedia (6.5)0.42%—Wpjos Library File Manager23/6/202217/6/2026
A vulnerability was found in File Manager Plugin 3.0.1. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely.
ModificadaAlta (8.1)1.3%—Wpjos Library File Manager4/4/202217/6/2026
The Library File Manager WordPress plugin before 5.2.3 is using an outdated version of the elFinder library, which is know to be affected by security issues (CVE-2021-32682), and does not have any authorisation as well as CSRF checks in its connector AJAX action, allowing any authenticated users, such as subscriber to…
ModificadaBaja (2.5)0.27%—Mirmay File ManagerMirmay Secure Private Browser28/3/202217/6/2026
A vulnerability classified as problematic has been found in Mirmay Secure Private Browser and File Manager up to 2.5. Affected is the Auto Lock. A race condition leads to a local authentication bypass. The exploit has been disclosed to the public and may be used.
ModificadaCrítica (9.8)1.9%—Prasathmani Tiny File Manager17/3/202217/6/2026
Path Traversal in GitHub repository prasathmani/tinyfilemanager prior to 2.4.7.
ModificadaAlta (8.8)70%💥 ExploitPrasathmani Tiny File Manager15/3/202217/6/2026
A path traversal vulnerability in the file upload functionality in tinyfilemanager.php in Tiny File Manager before 2.4.7 allows remote attackers (with valid user accounts) to upload malicious PHP files to the webroot, leading to code execution.
ModificadaCrítica (9.8)1.3%—Idec Data File ManagerIdec WindeditIdec WindldrIdec Microsmart Plus Fc6b Firmware+528/12/202117/6/2026
An attacker may obtain the user credentials from file servers, backup repositories, or ZLD files saved in SD cards. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
ModificadaCrítica (9.8)1.3%—Idec Data File ManagerIdec WindeditIdec WindldrIdec Microsmart Plus Fc6b Firmware+528/12/202117/6/2026
An attacker may obtain the user credentials from the communication between the PLC and the software. As a result, the PLC user program may be uploaded, altered, and/or downloaded.
ModificadaAlta (7.5)0.59%—Idec Microsmart Fc6a FirmwareIdec Microsmart Plus Fc6a FirmwareIdec Data File ManagerIdec Windedit+124/12/202117/6/2026
Plaintext storage of a password vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to obtain…
ModificadaAlta (7.6)0.39%—Idec Microsmart Fc6a FirmwareIdec Microsmart Plus Fc6a FirmwareIdec Data File ManagerIdec Windedit+124/12/202117/6/2026
Unprotected transport of credentials vulnerability in IDEC PLCs (FC6A Series MICROSmart All-in-One CPU module v2.32 and earlier, FC6A Series MICROSmart Plus CPU module v1.91 and earlier, WindLDR v8.19.1 and earlier, WindEDIT Lite v1.3.1 and earlier, and Data File Manager v2.12.1 and earlier) allows an attacker to…
Orbitaley — Vulnerabilidades