Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

2405 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.53%—FilebrowserAI14/8/20268/9/2026
FileBrowser versions before 2.63.19 fail to enforce the declared Upload-Length in the TUS resumable-upload PATCH endpoint, allowing authenticated users to write arbitrary data to disk. Attackers can send oversized request bodies that exceed the declared upload length to exhaust available disk space and cause service…
AplazadaAlta (8.7)0.56%—FilebrowserAI14/8/20268/9/2026
File Browser versions before 2.63.20 fail to honor the createUserDir isolation in proxy and hook authentication auto-provisioning paths. Attackers with valid upstream-authenticated credentials can read, modify, delete, and share files belonging to other users by exploiting the server root scope assignment.
AplazadaCrítica (9.2)0.55%—FilebrowserAI14/8/20268/9/2026
FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir are enabled and FileBrowser's root is on a case-insensitive filesystem (confirmed on Windows/NTFS), two self-registered usernames that differ only…
AplazadaAlta (7.6)0.50%—FilebrowserAI14/8/20268/9/2026
filebrowser versions before v2.63.21 fail to canonicalize paths before evaluating access rules, allowing authenticated users to bypass administrator-defined deny rules using case-variant or backslash-separated paths. Attackers can request files with alternate path representations that match no rule but resolve to the…
AplazadaMedia (5.3)0.39%—FilebrowserAI14/8/20268/9/2026
filebrowser before 2.63.19 contains a permission bypass in the /api/resources endpoint. The checksum (?checksum=) branch of resourceGetHandler reads the entire file to compute a digest and returns it without performing a Perm.Download check (unlike the sibling raw, preview, and subtitle paths). As a result, an…
Pendiente de análisisMedia (6.3)0.47%—Actix FilesAI14/8/202624/9/2026
The actix-files crate (actix_files) before version 0.6.10 contains an information exposure vulnerability. When a non-existing folder is passed as the serve_from argument to Files::new(), the mount path defaults to an empty path; the service then joins the request path with this empty path and canonicalizes it, causing…
Pendiente de análisisMedia (6.9)0.49%—Actix-filesAI14/8/202624/9/2026
actix-files before 0.6.10 contains a denial of service vulnerability triggered by an empty Range header in GET requests for static files. When panic is set to abort, remote attackers can crash the process on-demand by sending a GET request with an empty Range header.
AplazadaCrítica (9.3)0.57%—FilebrowserAI13/8/20268/9/2026
filebrowser through 2.63.16 fails to properly restrict scope and permissions when self-signup is enabled with default CreateUserDir setting. Unauthenticated attackers can register accounts that inherit the server root scope with full create, modify, delete, rename, share, and download permissions, allowing…
AplazadaMedia (6.5)0.22%—Bestwebsoft Subscriber Cross Site Scripting Profile Extra FieldsAI13/8/202614/8/2026
Subscriber Cross Site Scripting (XSS) in Profile Extra Fields by BestWebSoft <= 1.3.4 versions.
AplazadaAlta (7.2)0.56%—FilebrowserAI13/8/20268/9/2026
filebrowser versions before 2.63.19 contain an out-of-scope file deletion vulnerability in the TUS upload cache eviction mechanism that allows authenticated users with only Create permission to delete arbitrary files outside their scope. Attackers can swap an ancestor directory with a symlink during the cache TTL…
AplazadaAlta (8.6)0.48%—Filebrowser File BrowserAI13/8/20268/9/2026
File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by operating on their allowed parent directory, defeating rule-based…
AplazadaAlta (7.6)0.43%—Filebrowser File BrowserAI13/8/202630/9/2026
File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fresh ones via the…
AplazadaMedia (5.3)0.47%—Prevent Direct Access Protect Wordpress FilesAI13/8/202614/8/2026
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without…
AplazadaAlta (8.7)2.5%—FilerunAIFfmpegAIImagemagickAIVipsAI+111/8/202616/9/2026
FileRun up to and including version 2026.2.0 contains an OS command injection vulnerability that allows authenticated attackers to achieve remote code execution by uploading a file with a malicious filename containing shell command substitution sequences. The thumbnail generation system passes filenames wrapped in…
AplazadaMedia (5.3)0.44%—Keking KkfileviewAI11/8/20269/9/2026
kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/src/main/java/cn/keking/web/controller/FileController.java passes the user-controlled path parameter from FileController#getFiles to Files.newDirectoryStream without…
AplazadaMedia (5.8)0.43%—Keking KkfileviewAI11/8/20269/9/2026
kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView is omitted from TrustHostFilter and TrustDirFilter in server/src/main/java/cn/keking/config/WebConfig.java, allowing FileConvertQueueTask to fetch an attacker-selected URL…
AplazadaAlta (8.7)0.60%—FilepondAIMalcolmAIPhp-fpmAI11/8/20262/10/2026
Malcolm is a network traffic analysis tool suite. The file-upload component (FilePond PHP backend) accepts uploads at `POST /server/php/submit.php` and stores them in a directory served by the same nginx and php-fpm instance. The allow-list that should restrict accepted file types is an empty array by default…
AplazadaAlta (7.5)0.42%—File ManagerAI10/8/202626/8/2026
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents…
AplazadaAlta (7.5)0.43%—File ManagerAI10/8/202626/8/2026
The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them.
AplazadaAlta (8.8)0.42%—File ManagerAI10/8/202626/8/2026
The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to…
AplazadaAlta (8.6)0.45%—Iptanus File UploadAI9/8/202626/8/2026
The Iptanus File Upload WordPress plugin before 5.1.8 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to an SQL injection exploitable by unauthenticated users.
AplazadaBaja (2.5)0.14%—Perl File Rotate SimpleAI7/8/202626/8/2026
File::Rotate::Simple versions before 0.4.0 for Perl create the target of dangling symlinks when rotating files. When the file to be rotated is a symbolic link to a missing file, and the touch option is enabled, then the rotate method assumes that the file is absent (since the existence check is against the target),…
AnalizadaAlta (8.8)1.0%—Microsoft Application Insights Profiler7/8/202617/8/2026
Improper limitation of a pathname to a restricted directory ('path traversal') in Application Insights Profiler allows an authorized attacker to elevate privileges over a network.
AplazadaMedia (5.3)0.29%—Cozmoslabs Profile BuilderAI6/8/202612/8/2026
Unauthenticated Broken Access Control in Profile Builder <= 3.16.5 versions.
AplazadaCrítica (9.3)0.40%—Wordpress File UploadAI6/8/202612/8/2026
Unauthenticated SQL Injection in WordPress File Upload <= 5.1.7 versions.