Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
187 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.54% | — | Prasathmani Tiny File Manager | 15/9/2021 | 17/6/2026 | A Stored XSS exists in TinyFileManager All version up to and including 2.4.6 in /tinyfilemanager.php when the server is given a file that contains HTML and javascript in its name. A malicious user can upload a file with a malicious filename containing javascript code and it will run on any user browser when they… | |
| Modificada | Alta (8.8) | 0.60% | — | Prasathmani Tiny File Manager | 15/9/2021 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload files and run OS commands by inducing the Administrator user to browse a URL controlled by an attacker. | |
| Modificada | Media (6.5) | 8.2% | 💥 Exploit | Prasathmani Tiny File Manager | 15/9/2021 | 17/6/2026 | A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to upload a file (with Admin credentials or with the CSRF vulnerability) with the "fullpath" parameter containing path traversal strings (../ and ..\) in order to escape the server's intended working… | |
| Modificada | Media (5.4) | 0.90% | — | Filemanagerpro File Manager | 5/4/2021 | 17/6/2026 | In the default configuration of the File Manager WordPress plugin before 7.1, a Reflected XSS can occur on the endpoint /wp-admin/admin.php?page=wp_file_manager_properties when a payload is submitted on the User-Agent parameter. The payload is then reflected back on the web application response. | |
| Modificada | Alta (7.8) | 0.45% | — | Amaze File Manager Project Amaze File Manager | 19/2/2021 | 17/6/2026 | Amaze File Manager before 3.5.1 allows attackers to obtain root privileges via shell metacharacters in a symbolic link. | |
| Modificada | Crítica (9.1) | 1.9% | — | Elecom File Manager | 12/2/2021 | 17/6/2026 | Directory traversal vulnerability in ELECOM File Manager all versions allows remote attackers to create an arbitrary file or overwrite an existing file in a directory which can be accessed with the application privileges via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.3% | — | Veno File Manager Project Veno File Manager | 4/1/2021 | 17/6/2026 | Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to download sensitive files from the server. | |
| Modificada | Crítica (9.8) | 1.7% | — | Amaze File Manager Project Amaze File Manager | 30/12/2020 | 17/6/2026 | The Amaze File Manager application before 3.4.2 for Android does not properly restrict intents for controlling the FTP server (aka services.ftpservice.FTPReceiver.ACTION_START_FTPSERVER and services.ftpservice.FTPReceiver.ACTION_STOP_FTPSERVER). | |
| Modificada | Alta (8.8) | 18% | — | Themexa Secure File Manager | 14/12/2020 | 17/6/2026 | vendor/elfinder/php/connector.minimal.php in the secure-file-manager plugin through 2.5 for WordPress loads elFinder code without proper access control. Thus, any authenticated user can run the elFinder upload command to achieve remote code execution. NOTE: This vulnerability only affects products that are no longer… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Filemanagerpro File Manager | 9/9/2020 | 17/6/2026 | The File Manager (wp-file-manager) plugin before 6.9 for WordPress allows remote attackers to upload and execute arbitrary PHP code because it renames an unsafe example elFinder connector file to have the .php extension. This, for example, allows attackers to run the elFinder upload (or mkfile and put) command to… | |
| Modificada | Alta (7.5) | 16% | 💥 Exploit | Filemanagerpro File Manager | 26/8/2020 | 17/6/2026 | mndpsingh287 WP File Manager v6.4 and lower fails to restrict external access to the fm_backups directory with a .htaccess file. This results in the ability for unauthenticated users to browse and download any site backups, which sometimes include full database backups, that the plugin has taken. | |
| Modificada | Alta (7.7) | 1.5% | — | Prasathmani Tiny File Manager | 28/4/2020 | 17/6/2026 | In Tiny File Manager 2.4.1 there is a vulnerability in the ajax file backup copy functionality which allows authenticated users to create backup copies of files (with .bak extension) outside the scope in the same directory in which they are stored. | |
| Modificada | Alta (7.7) | 1.8% | — | Prasathmani Tiny File Manager | 28/4/2020 | 17/6/2026 | In Tiny File Manager 2.4.1, there is a Path Traversal vulnerability in the ajax recursive directory listing functionality. This allows authenticated users to enumerate directories and files on the filesystem (outside of the application scope). | |
| Modificada | Crítica (9.9) | 1.6% | — | Easytimestudio Easy File Manager | 24/1/2020 | 16/6/2026 | Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass | |
| Modificada | Alta (8.8) | 1.2% | — | Prasathmani Tiny File Manager | 30/12/2019 | 17/6/2026 | In Tiny File Manager before 2.3.9, there is a remote code execution via Upload from URL and Edit/Rename files. Only authenticated users are impacted. | |
| Modificada | Alta (7.5) | 1.6% | — | Estrongs ES File Explorer File Manager | 5/9/2019 | 17/6/2026 | The master-password feature in the ES File Explorer File Manager application 4.2.0.1.3 for Android can be bypassed via a com.estrongs.android.pop.ftp.ESFtpShortcut intent, leading to remote FTP access to the entirety of local storage. | |
| Modificada | Media (6.1) | 1.4% | — | Filemanagerpro File Manager | 15/4/2019 | 17/6/2026 | There is an XSS vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. | |
| Modificada | Alta (8.8) | 0.92% | — | Filemanagerpro File Manager | 15/4/2019 | 17/6/2026 | There is a CSRF vulnerability in the mndpsingh287 File Manager plugin 3.0 for WordPress via the page=wp_file_manager_root public_path parameter. | |
| Modificada | Media (4.2) | 0.39% | — | Estrongs ES File Explorer File Manager | 15/2/2019 | 17/6/2026 | The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a WebView with no information about the URL. | |
| Modificada | Media (5.3) | 10% | 💥 Exploit | Media File Manager Project Media File Manager | 31/1/2019 | 17/6/2026 | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal in the dir parameter of an mrelocator_rename action to the wp-admin/admin-ajax.php URI. | |
| Modificada | Media (5.3) | 10% | 💥 Exploit | Media File Manager Project Media File Manager | 31/1/2019 | 17/6/2026 | The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to the wp-admin/admin-ajax.php URI. | |
| Modificada | Media (6.1) | 2.6% | 💥 Exploit | Media File Manager Project Media File Manager | 31/1/2019 | 17/6/2026 | The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI. | |
| Modificada | Media (5.3) | 12% | 💥 Exploit | Media File Manager Project Media File Manager | 31/1/2019 | 17/6/2026 | The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI. | |
| Modificada | Media (6.1) | 1.1% | — | Oracle Peoplesoft Enterprise Human Capital Management Eprofile Manager Desktop | 16/1/2019 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM eProfile Manager Desktop component of Oracle PeopleSoft Products (subcomponent: Guided Self Service). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft… | |
| Modificada | Alta (8.1) | 64% | 💥 Exploit | Estrongs ES File Explorer File Manager | 16/1/2019 | 17/6/2026 | The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated… |