Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.40% | — | M-files AinoAI | 20/11/2024 | 17/6/2026 | Improper access control vulnerability in M-Files Aino in versions before 24.10 allowed an authenticated user to access object information via incorrect evaluation of effective permissions. | |
| Modificada | Crítica (9.2) | 0.61% | — | M-files Server | 20/11/2024 | 17/6/2026 | Authentication bypass condition in LDAP authentication in M-Files server versions before 24.11 supported usage of OpenLDAP configurations that allowed user authentication without a password when the LDAP server itself had the vulnerable configuration. | |
| Modificada | Media (5.3) | 0.39% | — | M-files Server | 20/11/2024 | 17/6/2026 | Local File Inclusion vulnerability in M-Files Server in versions before 24.11 (excluding 24.8 SR1, 24.2 SR3 and 23.8 SR7) allows an authenticated user to read server local files of a limited set of filetypes via document preview. | |
| Analizada | Crítica (9.8) | 1.2% | — | Vanquish Woocommerce Upload Files | 13/11/2024 | 17/6/2026 | The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 84.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may… | |
| Analizada | Media (4.8) | 0.23% | — | Acronis Cyber Files | 17/10/2024 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability on enrollment invitation page. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. | |
| Analizada | Alta (7.3) | 0.14% | — | Acronis Cyber Files | 17/10/2024 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. | |
| Analizada | Alta (7.3) | 0.16% | — | Acronis Cyber Files | 17/10/2024 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. | |
| Analizada | Alta (7.8) | 0.14% | — | Acronis Cyber Files | 17/10/2024 | 17/6/2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. | |
| Analizada | Media (5.7) | 0.25% | — | Acronis Cyber Files | 17/10/2024 | 17/6/2026 | Sensitive information disclosure due to spell-jacking. The following products are affected: Acronis Cyber Files (Windows) before build 9.0.0x24. | |
| Aplazada | Media (4.3) | 0.34% | — | Multiline Files Upload FOR Contact Form 7AI | 16/10/2024 | 17/6/2026 | The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the mfcf7_zl_custom_handle_deactivation_plugin_form_submission() function in all versions up to, and including, 2.8.1. This makes it possible for authenticated… | |
| Aplazada | Media (4.9) | 0.56% | — | Jamesdlow CSS JS FilesAI | 5/10/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in jamesdlow CSS JS Files css-js-files allows Path Traversal.This issue affects CSS JS Files: from n/a through <= 1.5.0. | |
| Aplazada | Media (5.3) | 0.42% | — | M-files Connector FOR CopilotAI | 2/10/2024 | 17/6/2026 | Permissions bypass in M-Files Connector for Copilot before version 24.9.3 allows authenticated user to access limited amount of documents via incorrect access control list calculation | |
| Modificada | Media (6.9) | 0.29% | — | M-files Hubshare | 2/10/2024 | 17/6/2026 | Stored HTML Injection in Social Module in M-Files Hubshare before version 5.0.8.6 allows authenticated user to spoof UI | |
| Aplazada | Crítica (9.8) | 0.55% | — | FilesenderAI | 2/10/2024 | 17/6/2026 | FileSender before 2.49 allows server-side template injection (SSTI) for retrieving credentials. | |
| Modificada | Alta (8.4) | 0.56% | — | M-files Server | 27/8/2024 | 17/6/2026 | A path traversal issue in API endpoint in M-Files Server before version 24.8.13981.0 and LTS 24.2.13421.15 SR2 and LTS 23.8.12892.0 SR6 allows authenticated user to read files | |
| Modificada | Alta (7.5) | 0.37% | — | Sharedfilespro Shared Files | 26/8/2024 | 17/6/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.28. | |
| Analizada | Media (6.5) | 0.31% | — | Mediajedi User Private Files | 22/8/2024 | 17/6/2026 | The User Private Files – WordPress File Sharing Plugin plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 2.1.0 via the 'dpk_upvf_update_doc' due to missing validation on the 'docid' user controlled key. This makes it possible for authenticated attackers, with… | |
| Analizada | Alta (8.8) | 0.62% | — | Ninjateam Filester | 3/8/2024 | 17/6/2026 | The File Manager Pro – Filester plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'njt_fs_saveSettingRestrictions' function in all versions up to, and including, 1.8.2. This makes it possible for authenticated attackers, with a role that has been granted… | |
| Modificada | Media (5.3) | 0.45% | — | Shopfiles Ebook Store | 2/8/2024 | 17/6/2026 | The Ebook Store plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 5.8001. This is due to the plugin utilizing fpdi-protection and not preventing direct access to test files that have display_errors set to true. This makes it possible for unauthenticated attackers to… | |
| Modificada | Media (5.3) | 0.21% | — | Filestash | 31/7/2024 | 17/6/2026 | An issue was discovered in filestash v0.4. The usage of the ssh.InsecureIgnoreHostKey() disables host key verification, possibly allowing attackers to obtain sensitive information via a man-in-the-middle attack. | |
| Modificada | Media (5.9) | 0.21% | — | Filestash | 31/7/2024 | 17/6/2026 | Default configurations in the ShareProofVerifier function of filestash v0.4 causes the application to skip the TLS certificate verification process when sending out email verification codes, possibly allowing attackers to access sensitive data via a man-in-the-middle attack. | |
| Analizada | Alta (7.5) | 0.26% | — | Filestash | 31/7/2024 | 17/6/2026 | filestash v0.4 is configured to skip TLS certificate verification when using the FTPS protocol, possibly allowing attackers to execute a man-in-the-middle attack via the Init function of index.go. | |
| Modificada | Alta (8.5) | 0.35% | — | M-files Hubshare | 29/7/2024 | 17/6/2026 | Stored XSS in M-Files Hubshare versions before 5.0.6.0 allows an authenticated attacker to execute arbitrary JavaScript in user's browser session | |
| Modificada | Alta (8.5) | 0.30% | — | M-files Hubshare | 29/7/2024 | 17/6/2026 | Reflected XSS in M-Files Hubshare before version 5.0.6.0 allows an attacker to execute arbitrary JavaScript code in the context of the victim's browser session | |
| Modificada | Media (5.4) | 0.35% | — | Kapasias Lottiefiles | 24/5/2024 | 17/6/2026 | The LottieFiles – JSON Based Animation Lottie & Bodymovin for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.10.9 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level… |