Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
158 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 70% | 💥 Exploit | Std42 Elfinder | 14/6/2021 | 17/6/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were… | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Std42 Elfinder | 13/6/2021 | 17/6/2026 | The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP. | |
| Modificada | Alta (8.8) | 1.5% | — | Sunhater Kcfinder | 1/1/2021 | 17/6/2026 | uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy. | |
| Modificada | Media (5.3) | 1.1% | — | Cksource Ckfinder | 26/9/2019 | 17/6/2026 | An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletproof content sniffing protection. | |
| Modificada | Alta (7.5) | 1.5% | — | Cksource Ckfinder | 26/9/2019 | 17/6/2026 | An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP, CKFinder for ASP.NET, CKFinder for ColdFusion,… | |
| Modificada | Crítica (9.8) | 2.4% | — | Cysteme-finder | 13/9/2019 | 17/6/2026 | The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking. | |
| Modificada | Media (6.1) | 1.2% | — | Sunhater Kcfinder | 28/7/2019 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier allows remote attackers to inject arbitrary web script or HTML via the CKEditorFuncNum parameter. | |
| Modificada | Crítica (9.8) | 97% | 💥 Exploit | Std42 Elfinder | 26/2/2019 | 17/6/2026 | elFinder before 2.1.48 has a command injection vulnerability in the PHP connector. | |
| Modificada | Alta (7.7) | 1.1% | — | Std42 Elfinder | 14/1/2019 | 17/6/2026 | A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in php/elFinder.class.php. | |
| Modificada | Media (5.9) | 1.3% | — | Std42 Elfinder | 10/1/2019 | 17/6/2026 | php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set. | |
| Modificada | Alta (7.5) | 1.5% | — | Multitech Faxfinder | 3/10/2018 | 17/6/2026 | Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying database schema to further disclose other fax server information through different injection points. | |
| Modificada | Alta (7.5) | 2.0% | — | Utahcityfinder Project Utahcityfinder | 7/6/2018 | 17/6/2026 | utahcityfinder constructs lists of Utah cities with a certain prefix. utahcityfinder is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Crítica (9.1) | 2.9% | — | Std42 Elfinder | 28/3/2018 | 17/6/2026 | Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process. NOTE: this issue exists because of an… | |
| Modificada | Crítica (9.1) | 2.9% | — | Std42 Elfinder | 28/3/2018 | 17/6/2026 | Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process. | |
| Modificada | Alta (7.5) | 1.3% | — | Qnap Qfinder PRO | 5/3/2018 | 17/6/2026 | QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this may allow attackers to further compromise the device. | |
| Modificada | Alta (7.5) | 0.60% | — | Huawei SmarthomeHuawei HiappHuawei HwparentcontrolHuawei Hwparentcontrolparent+10 | 22/11/2017 | 17/6/2026 | Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawei Pay 8.0.0.300 and earlier versions,Skytone 8.1.2.300 and… | |
| Modificada | Crítica (9.8) | 2.1% | — | Multitech Faxfinder | 30/9/2017 | 17/6/2026 | MultiTech FaxFinder before 4.1.2 stores Passwords unencrypted for maintaining the test connectivity function of its LDAP configuration. These credentials are retrieved by the system when the LDAP configuration page is opened and are embedded directly into the HTML source code in cleartext. | |
| Modificada | Media (5.8) | 1.2% | — | Finder Project Finder | 15/6/2015 | 17/6/2026 | Open redirect vulnerability in the finder_form_goto function in the Finder module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. | |
| Modificada | Media (4.3) | 1.4% | — | Sunhater Kcfinder | 3/12/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in index.php in SunHater KCFinder 3.11 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) file or (2) directory (folder) name of an uploaded file. | |
| Modificada | Media (5.4) | 0.27% | — | NQ Easy Finder & Anti-theft | 9/9/2014 | 17/6/2026 | The Easy Finder & Anti-Theft (aka com.nqmobile.easyfinder) application 2.0.10.08 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.6% | — | Malware Finder Plugin Project Malware Finder | 1/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in process.php in the Malware Finder plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the query parameter. | |
| Modificada | Media (4.3) | 2.7% | — | Danielb Finder | 8/4/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the autocomplete functionality in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via the title of a node, a different vulnerability than CVE-2012-1561. | |
| Modificada | Media (4.3) | 3.0% | — | Danielb Finder | 8/4/2014 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "checkbox and radio button functionalities." | |
| Modificada | Media (4.3) | 1.3% | — | Drinkedin Barfinder | 3/3/2014 | 17/6/2026 | The DrinkedIn BarFinder application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain sensitive fine-geolocation information, by leveraging control over one of a number of adult sites, as demonstrated by (1)… | |
| Modificada | Media (4.3) | 1.4% | — | Alexey Sukhotin Elfinder | 24/6/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the elFinder file manager module 6.x-0.x before 6.x-0.8 and 7.x-0.x before 7.x-0.8 for Drupal allows remote attackers to hijack the authentication of unspecified victims to create, modify, or delete files via unknown vectors. |