Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

187 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.54%—Prasathmani Tiny File Manager15/9/202117/6/2026
A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they…
ModificadaAlta (8.8)0.60%—Prasathmani Tiny File Manager15/9/202117/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by inducing the Administrator user to browse a URL controlled by an attacker.
ModificadaMedia (6.5)8.2%💥 ExploitPrasathmani Tiny File Manager15/9/202117/6/2026
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working…
ModificadaMedia (5.4)0.90%—Filemanagerpro File Manager5/4/202117/6/2026
In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response.
ModificadaAlta (7.8)0.45%—Amaze File Manager Project Amaze File Manager19/2/202117/6/2026
Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link.
ModificadaCrítica (9.1)1.9%—Elecom File Manager12/2/202117/6/2026
Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary file or overwrite an existing file in a directory which can be accessed with the application privileges via unspecified vectors.
ModificadaAlta (7.5)2.3%—Veno File Manager Project Veno File Manager4/1/202117/6/2026
Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to download sensitive files from the server.
ModificadaCrítica (9.8)1.7%—Amaze File Manager Project Amaze File Manager30/12/202017/6/2026
The Amaze File Manager application before 3.4.2 for Android does not properly restrict intents for controlling the FTP server (aka services.ftpservice.FTPReceiver.ACTION_START_FTPSERVER and services.ftpservice.FTPReceiver.ACTION_STOP_FTPSERVER).
ModificadaAlta (8.8)18%—Themexa Secure File Manager14/12/202017/6/2026
vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder code without proper access control. Thus, any authenticated user can run the elFinder upload command to achieve remote code execution. NOTE: This vulnerability only affects products that are no longer…
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitFilemanagerpro File Manager9/9/202017/6/2026
The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to…
ModificadaAlta (7.5)16%💥 ExploitFilemanagerpro File Manager26/8/202017/6/2026
mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken.
ModificadaAlta (7.7)1.5%—Prasathmani Tiny File Manager28/4/202017/6/2026
In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to create backup copies of files (with .bak extension) outside the scope in the same directory in which they are stored.
ModificadaAlta (7.7)1.8%—Prasathmani Tiny File Manager28/4/202017/6/2026
In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This allows authenticated users to enumerate directories and files on the filesystem (outside of the application scope).
ModificadaCrítica (9.9)1.6%—Easytimestudio Easy File Manager24/1/202016/6/2026
Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass
ModificadaAlta (8.8)1.2%—Prasathmani Tiny File Manager30/12/201917/6/2026
In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted.
ModificadaAlta (7.5)1.6%—Estrongs ES File Explorer File Manager5/9/201917/6/2026
The master-password feature in the ES File Explorer File Manager application 4.2.0.1.3 for Android can be bypassed via a com.estrongs.android.pop.ftp.ESFtpShortcut intent, leading to remote FTP access to the entirety of local storage.
ModificadaMedia (6.1)1.4%—Filemanagerpro File Manager15/4/201917/6/2026
There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
ModificadaAlta (8.8)0.92%—Filemanagerpro File Manager15/4/201917/6/2026
There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter.
ModificadaMedia (4.2)0.39%—Estrongs ES File Explorer File Manager15/2/201917/6/2026
The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a WebView with no information about the URL.
ModificadaMedia (5.3)10%💥 ExploitMedia File Manager Project Media File Manager31/1/201917/6/2026
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal in the dir parameter of an mrelocator_rename action to the wp-admin/admin-ajax.php URI.
ModificadaMedia (5.3)10%💥 ExploitMedia File Manager Project Media File Manager31/1/201917/6/2026
The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to the wp-admin/admin-ajax.php URI.
ModificadaMedia (6.1)2.6%💥 ExploitMedia File Manager Project Media File Manager31/1/201917/6/2026
The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.
ModificadaMedia (5.3)12%💥 ExploitMedia File Manager Project Media File Manager31/1/201917/6/2026
The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.
ModificadaMedia (6.1)1.1%—Oracle Peoplesoft Enterprise Human Capital Management Eprofile Manager Desktop16/1/201917/6/2026
Vulnerability in the PeopleSoft Enterprise HCM eProfile Manager Desktop component of Oracle PeopleSoft Products (subcomponent: Guided Self Service). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft…
ModificadaAlta (8.1)64%💥 ExploitEstrongs ES File Explorer File Manager16/1/201917/6/2026
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated…