Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.53% | — | FilebrowserAI | 14/8/2026 | 8/9/2026 | FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exceed the declared upload length to exhaust available disk space and cause service… | |
| Aplazada | Alta (8.7) | 0.56% | — | FilebrowserAI | 14/8/2026 | 8/9/2026 | File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment. | |
| Aplazada | Crítica (9.2) | 0.55% | — | FilebrowserAI | 14/8/2026 | 8/9/2026 | FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (confirmed on Windows/NTFS), two self-registered usernames that differ only… | |
| Aplazada | Alta (7.6) | 0.50% | — | FilebrowserAI | 14/8/2026 | 8/9/2026 | filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can request files with alternate path representations that match no rule but resolve to the… | |
| Aplazada | Media (5.3) | 0.39% | — | FilebrowserAI | 14/8/2026 | 8/9/2026 | filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of resourceGetHandler reads the entire file to compute a digest and returns it without performing a Perm.Download check (unlike the sibling raw, preview, and subtitle paths). As a result, an… | |
| Pendiente de análisis | Media (6.3) | 0.47% | — | Actix FilesAI | 14/8/2026 | 24/9/2026 | The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path; the service then joins the request path with this empty path and canonicalizes it, causing… | |
| Pendiente de análisis | Media (6.9) | 0.49% | — | Actix-filesAI | 14/8/2026 | 24/9/2026 | actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request with an empty Range header. | |
| Aplazada | Crítica (9.3) | 0.57% | — | FilebrowserAI | 13/8/2026 | 8/9/2026 | filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing… | |
| Aplazada | Media (6.5) | 0.22% | — | Bestwebsoft Subscriber Cross Site Scripting Profile Extra FieldsAI | 13/8/2026 | 14/8/2026 | Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions. | |
| Aplazada | Alta (7.2) | 0.56% | — | FilebrowserAI | 13/8/2026 | 8/9/2026 | filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission to delete arbitrary files outside their scope. Attackers can swap an ancestor directory with a symlink during the cache TTL… | |
| Aplazada | Alta (8.6) | 0.48% | — | Filebrowser File BrowserAI | 13/8/2026 | 8/9/2026 | File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by operating on their allowed parent directory, defeating rule-based… | |
| Aplazada | Alta (7.6) | 0.43% | — | Filebrowser File BrowserAI | 13/8/2026 | 30/9/2026 | File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fresh ones via the… | |
| Aplazada | Media (5.3) | 0.47% | — | Prevent Direct Access Protect Wordpress FilesAI | 13/8/2026 | 14/8/2026 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without… | |
| Aplazada | Alta (8.7) | 2.5% | — | FilerunAIFfmpegAIImagemagickAIVipsAI+1 | 11/8/2026 | 16/9/2026 | FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in… | |
| Aplazada | Media (5.3) | 0.44% | — | Keking KkfileviewAI | 11/8/2026 | 9/9/2026 | kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/src/main/java/cn/keking/web/controller/FileController.java passes the user-controlled path parameter from FileController#getFiles to Files.newDirectoryStream without… | |
| Aplazada | Media (5.8) | 0.43% | — | Keking KkfileviewAI | 11/8/2026 | 9/9/2026 | kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView is omitted from TrustHostFilter and TrustDirFilter in server/src/main/java/cn/keking/config/WebConfig.java, allowing FileConvertQueueTask to fetch an attacker-selected URL… | |
| Aplazada | Alta (8.7) | 0.60% | — | FilepondAIMalcolmAIPhp-fpmAI | 11/8/2026 | 2/10/2026 | Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default… | |
| Aplazada | Alta (7.5) | 0.42% | — | File ManagerAI | 10/8/2026 | 26/8/2026 | The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents… | |
| Aplazada | Alta (7.5) | 0.43% | — | File ManagerAI | 10/8/2026 | 26/8/2026 | The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them. | |
| Aplazada | Alta (8.8) | 0.42% | — | File ManagerAI | 10/8/2026 | 26/8/2026 | The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to… | |
| Aplazada | Alta (8.6) | 0.45% | — | Iptanus File UploadAI | 9/8/2026 | 26/8/2026 | The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users. | |
| Aplazada | Baja (2.5) | 0.14% | — | Perl File Rotate SimpleAI | 7/8/2026 | 26/8/2026 | File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When the file to be rotated is a symbolic link to a missing file, and the touch option is enabled, then the rotate method assumes that the file is absent (since the existence check is against the target),… | |
| Analizada | Alta (8.8) | 1.0% | — | Microsoft Application Insights Profiler | 7/8/2026 | 17/8/2026 | Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (5.3) | 0.29% | — | Cozmoslabs Profile BuilderAI | 6/8/2026 | 12/8/2026 | Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions. | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wordpress File UploadAI | 6/8/2026 | 12/8/2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions. |