Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.22% | — | M-files Server Admin ToolAI | 4/4/2025 | 17/6/2026 | Stored XSS in Desktop UI in M-Files Server Admin tool before version 25.3.14681.7 on Windows allows authenticated local user to run scripts via UI | |
| Analizada | Alta (8.6) | 72% | ⚠ Explotación activa💥 PoC | Tj-actions Changed-files | 15/3/2025 | 24/9/2026 | tj-actions changed-files before 46 allows remote attackers to discover secrets by reading actions logs. (The tags v1 through v45.0.7 were affected on 2025-03-14 and 2025-03-15 because they were modified by a threat actor to point at commit 0e58ed8, which contained malicious updateFeatures code.) | |
| Analizada | Media (5.5) | 0.14% | — | Samsung Myfiles | 6/3/2025 | 17/6/2026 | Improper export of Android application components in My Files prior to version 15.0.07.5 in Android 14 allows local attackers to access files with My Files' privilege. | |
| Aplazada | Media (6.4) | 0.33% | — | Userprivatefiles User Private FilesAI | 19/2/2025 | 17/6/2026 | The User Private Files – File Upload & Download Manager with Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘new-fldr-name’ parameter in all versions up to, and including, 2.1.3 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.3) | 1.9% | 💥 Exploit | WebfilesysAI | 6/2/2025 | 17/6/2026 | An issue in the relPath parameter of WebFileSys version 2.31.0 allows attackers to perform directory traversal via a crafted HTTP request. By injecting traversal payloads into the parameter, attackers can manipulate file paths and gain unauthorized access to sensitive files, potentially exposing data outside the… | |
| Aplazada | Alta (7.2) | 0.39% | — | Anambis Shared FilesAI | 31/1/2025 | 17/6/2026 | The Shared Files – Frontend File Upload Form & Secure File Sharing plugin for WordPress is vulnerable to Stored Cross-Site Scripting via dfxp File uploads in all versions up to, and including, 1.7.42 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to… | |
| Aplazada | Media (6.5) | 1.3% | 💥 PoC | Karl Ward Files.galleryAI | 30/1/2025 | 17/6/2026 | A command injection vulnerability in the video thumbnail rendering component of Karl Ward's files.gallery v0.3.0 through 0.11.0 allows remote attackers to execute arbitrary code via a crafted video file. | |
| Modificada | Media (5.9) | 0.51% | — | M-files Server | 23/1/2025 | 17/6/2026 | Unexpected server crash in database driver in M-Files Server before 25.1.14445.5 and before 24.8 LTS SR3 allows a highly privileged attacker to cause denial of service via configuration change. | |
| Modificada | Media (6.3) | 0.53% | — | M-files Server | 23/1/2025 | 17/6/2026 | Denial of service condition in M-Files Server in versions before 25.1.14445.5 allows an unauthenticated user to consume computing resources in certain conditions. | |
| Modificada | Media (4.6) | 0.42% | — | M-files Server | 23/1/2025 | 17/6/2026 | Unsafe password recovery from configuration in M-Files Server before 25.1 allows a highly privileged user to recover external connector passwords | |
| Aplazada | Crítica (10) | 0.66% | — | Scriptonite User FilesAI | 22/1/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Scriptonite user files user-files allows Upload a Web Shell to a Web Server.This issue affects user files: from n/a through <= 2.4.2. | |
| Analizada | Media (5.3) | 0.30% | — | Download ALL Files Project Download ALL Files | 9/1/2025 | 17/6/2026 | Missing Authorization vulnerability in Drupal Download All Files allows Forceful Browsing.This issue affects Download All Files: from 0.0.0 before 2.0.2. | |
| Aplazada | Media (6.4) | 0.32% | — | Files Download DelayAI | 9/1/2025 | 17/6/2026 | The Files Download Delay plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fddwrap' shortcode in all versions up to, and including, 1.0.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with… | |
| Modificada | Media (6.1) | 0.45% | — | Shopfiles Ebook Store | 21/12/2024 | 17/6/2026 | The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'step' parameter in all versions up to, and including, 5.8001 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Modificada | Media (6.1) | 0.36% | — | Shopfiles Ebook Store | 21/12/2024 | 17/6/2026 | The Ebook Store plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 5.8001. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they… | |
| Analizada | Media (4.3) | 0.35% | — | Ninjateam Filester | 19/12/2024 | 17/6/2026 | The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'ajax_install_plugin' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Alta (7.1) | 0.20% | — | Fzmaster XPD Reduce Image FilesizeAI | 16/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in fzmaster XPD Reduce Image Filesize xpd-reduce-image-filesize allows Stored XSS.This issue affects XPD Reduce Image Filesize: from n/a through <= 1.0. | |
| Aplazada | Media (6.1) | 0.39% | — | FilestackAI | 14/12/2024 | 17/6/2026 | The Filestack Official plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'fstab' and 'filestack_options' parameters in all versions up to, and including, 2.1.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Modificada | Crítica (9.8) | 1.0% | — | Shopfiles Ebook Store | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Shopfiles Ltd Ebook Store allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Ebook Store: from n/a through 5.775. | |
| Modificada | Alta (7.2) | 0.98% | — | Ninjateam Filester | 28/11/2024 | 17/6/2026 | The File Manager Pro – Filester plugin for WordPress is vulnerable to Local JavaScript File Inclusion in all versions up to, and including, 1.8.5 via the 'fm_locale' parameter. This makes it possible for authenticated attackers, with Administrator-level access and above, to include and execute arbitrary files on the… | |
| Analizada | Alta (8.8) | 1.1% | — | Ninjateam Filester | 28/11/2024 | 17/6/2026 | The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing validation in the 'fsConnector' function in all versions up to, and including, 1.8.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted permissions by an… | |
| Analizada | Media (4.3) | 0.80% | — | Jenkins Filesystem List Parameter | 27/11/2024 | 17/6/2026 | Jenkins Filesystem List Parameter Plugin 0.0.14 and earlier does not restrict the path used for the File system objects list Parameter, allowing attackers with Item/Configure permission to enumerate file names on the Jenkins controller file system. | |
| Aplazada | Media (6.4) | 0.40% | — | Support SVG Upload SVG Files IN Wordpress Without HassleAI | 26/11/2024 | 17/6/2026 | The Support SVG – Upload svg files in wordpress without hassle plugin for WordPress is vulnerable to Stored Cross-Site Scripting via REST API SVG File uploads in all versions up to, and including, 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with… | |
| Modificada | Baja (3.5) | 0.39% | — | Antongorodezkiy Yadisk Files | 25/11/2024 | 17/6/2026 | The YaDisk Files WordPress plugin through 1.2.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup). | |
| Modificada | Media (6.8) | 0.69% | — | Antongorodezkiy Yadisk Files | 25/11/2024 | 17/6/2026 | The YaDisk Files WordPress plugin through 1.2.5 does not validate and escape some of its shortcode attributes before outputting them back in a page/post where the shortcode is embed, which could allow users with the contributor role and above to perform Stored Cross-Site Scripting attacks. |