Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
–

304 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.40%—M-files AinoAI20/11/202417/6/2026
Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorrect evaluation of effective permissions.
ModificadaCrítica (9.2)0.61%—M-files Server20/11/202417/6/2026
Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration.
ModificadaMedia (5.3)0.39%—M-files Server20/11/202417/6/2026
Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview.
AnalizadaCrítica (9.8)1.2%—Vanquish Woocommerce Upload Files13/11/202417/6/2026
The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 84.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may…
AnalizadaMedia (4.8)0.23%—Acronis Cyber Files17/10/202417/6/2026
Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
AnalizadaAlta (7.3)0.14%—Acronis Cyber Files17/10/202417/6/2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
AnalizadaAlta (7.3)0.16%—Acronis Cyber Files17/10/202417/6/2026
Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
AnalizadaAlta (7.8)0.14%—Acronis Cyber Files17/10/202417/6/2026
Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
AnalizadaMedia (5.7)0.25%—Acronis Cyber Files17/10/202417/6/2026
Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24.
AplazadaMedia (4.3)0.34%—Multiline Files Upload FOR Contact Form 7AI16/10/202417/6/2026
The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the mfcf7_zl_custom_handle_deactivation_plugin_form_submission() function in all versions up to, and including, 2.8.1. This makes it possible for authenticated…
AplazadaMedia (4.9)0.56%—Jamesdlow CSS JS FilesAI5/10/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in jamesdlow CSS JS Files css-js-files allows Path Traversal.This issue affects CSS JS Files: from n/a through <= 1.5.0.
AplazadaMedia (5.3)0.42%—M-files Connector FOR CopilotAI2/10/202417/6/2026
Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation
ModificadaMedia (6.9)0.29%—M-files Hubshare2/10/202417/6/2026
Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI
AplazadaCrítica (9.8)0.55%—FilesenderAI2/10/202417/6/2026
FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials.
ModificadaAlta (8.4)0.56%—M-files Server27/8/202417/6/2026
A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files
ModificadaAlta (7.5)0.37%—Sharedfilespro Shared Files26/8/202417/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.28.
AnalizadaMedia (6.5)0.31%—Mediajedi User Private Files22/8/202417/6/2026
The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user controlled key. This makes it possible for authenticated attackers, with…
AnalizadaAlta (8.8)0.62%—Ninjateam Filester3/8/202417/6/2026
The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' function in all versions up to, and including, 1.8.2. This makes it possible for authenticated attackers, with a role that has been granted…
ModificadaMedia (5.3)0.45%—Shopfiles Ebook Store2/8/202417/6/2026
The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001. This is due to the plugin utilizing fpdi-protection and not preventing direct access to test files that have display_errors set to true. This makes it possible for unauthenticated attackers to…
ModificadaMedia (5.3)0.21%—Filestash31/7/202417/6/2026
An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack.
ModificadaMedia (5.9)0.21%—Filestash31/7/202417/6/2026
Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack.
AnalizadaAlta (7.5)0.26%—Filestash31/7/202417/6/2026
filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go.
ModificadaAlta (8.5)0.35%—M-files Hubshare29/7/202417/6/2026
Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session
ModificadaAlta (8.5)0.30%—M-files Hubshare29/7/202417/6/2026
Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session
ModificadaMedia (5.4)0.35%—Kapasias Lottiefiles24/5/202417/6/2026
The LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level…