Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

158 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)70%💥 ExploitStd42 Elfinder14/6/202117/6/2026
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were…
ModificadaCrítica (9.8)19%💥 ExploitStd42 Elfinder13/6/202117/6/2026
The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP.
ModificadaAlta (8.8)1.5%—Sunhater Kcfinder1/1/202117/6/2026
uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy.
ModificadaMedia (5.3)1.1%—Cksource Ckfinder26/9/201917/6/2026
An issue was discovered in CKFinder through 2.6.2.1 and 3.x through 3.5.0. The documentation has misleading information that could lead to a conclusion that the application has a built-in bulletproof content sniffing protection.
ModificadaAlta (7.5)1.5%—Cksource Ckfinder26/9/201917/6/2026
An issue was discovered in CKFinder through 2.6.2.1. Improper checks of file names allows remote attackers to upload files without any extension (even if the application was configured to accept files only with a defined set of extensions). This affects CKFinder for ASP, CKFinder for ASP.NET, CKFinder for ColdFusion,…
ModificadaCrítica (9.8)2.4%—Cysteme-finder13/9/201917/6/2026
The cysteme-finder plugin before 1.4 for WordPress has unrestricted file upload because of incorrect session tracking.
ModificadaMedia (6.1)1.2%—Sunhater Kcfinder28/7/201917/6/2026
A cross-site scripting (XSS) vulnerability in upload.php in SunHater KCFinder 3.20-test1, 3.20-test2, 3.12, and earlier allows remote attackers to inject arbitrary web script or HTML via the CKEditorFuncNum parameter.
ModificadaCrítica (9.8)97%💥 ExploitStd42 Elfinder26/2/201917/6/2026
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
ModificadaAlta (7.7)1.1%—Std42 Elfinder14/1/201917/6/2026
A Server Side Request Forgery (SSRF) vulnerability in elFinder before 2.1.46 could allow a malicious user to access the content of internal network resources. This occurs in get_remote_contents() in php/elFinder.class.php.
ModificadaMedia (5.9)1.3%—Std42 Elfinder10/1/201917/6/2026
php/elFinder.class.php in elFinder before 2.1.45 leaks information if PHP's curl extension is enabled and safe_mode or open_basedir is not set.
ModificadaAlta (7.5)1.5%—Multitech Faxfinder3/10/201817/6/2026
Multi-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying database schema to further disclose other fax server information through different injection points.
ModificadaAlta (7.5)2.0%—Utahcityfinder Project Utahcityfinder7/6/201817/6/2026
utahcityfinder constructs lists of Utah cities with a certain prefix. utahcityfinder is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaCrítica (9.1)2.9%—Std42 Elfinder28/3/201817/6/2026
Studio 42 elFinder before 2.1.37 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process. NOTE: this issue exists because of an…
ModificadaCrítica (9.1)2.9%—Std42 Elfinder28/3/201817/6/2026
Studio 42 elFinder before 2.1.36 has a directory traversal vulnerability in elFinder.class.php with the zipdl() function that can allow a remote attacker to download files accessible by the web server process and delete files owned by the account running the web server process.
ModificadaAlta (7.5)1.3%—Qnap Qfinder PRO5/3/201817/6/2026
QNAP Qfinder Pro 6.1.0.0317 and earlier may expose sensitive information contained in NAS devices. If exploited, this may allow attackers to further compromise the device.
ModificadaAlta (7.5)0.60%—Huawei SmarthomeHuawei HiappHuawei HwparentcontrolHuawei Hwparentcontrolparent+1022/11/201717/6/2026
Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawei Pay 8.0.0.300 and earlier versions,Skytone 8.1.2.300 and…
ModificadaCrítica (9.8)2.1%—Multitech Faxfinder30/9/201717/6/2026
MultiTech FaxFinder before 4.1.2 stores Passwords unencrypted for maintaining the test connectivity function of its LDAP configuration. These credentials are retrieved by the system when the LDAP configuration page is opened and are embedded directly into the HTML source code in cleartext.
ModificadaMedia (5.8)1.2%—Finder Project Finder15/6/201517/6/2026
Open redirect vulnerability in the finder_form_goto function in the Finder module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (4.3)1.4%—Sunhater Kcfinder3/12/201417/6/2026
Cross-site scripting (XSS) vulnerability in index.php in SunHater KCFinder 3.11 and earlier allows remote attackers to inject arbitrary web script or HTML via (1) file or (2) directory (folder) name of an uploaded file.
ModificadaMedia (5.4)0.27%—NQ Easy Finder & Anti-theft9/9/201417/6/2026
The Easy Finder & Anti-Theft (aka com.nqmobile.easyfinder) application 2.0.10.08 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.6%—Malware Finder Plugin Project Malware Finder1/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in process.php in the Malware Finder plugin 1.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the query parameter.
ModificadaMedia (4.3)2.7%—Danielb Finder8/4/201416/6/2026
Cross-site scripting (XSS) vulnerability in the autocomplete functionality in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via the title of a node, a different vulnerability than CVE-2012-1561.
ModificadaMedia (4.3)3.0%—Danielb Finder8/4/201416/6/2026
Cross-site scripting (XSS) vulnerability in the Finder module 6.x-1.x before 6.x-1.26, 7.x-1.x, and 7.x-2.x before 7.x-2.0-alpha8 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors related to the "checkbox and radio button functionalities."
ModificadaMedia (4.3)1.3%—Drinkedin Barfinder3/3/201417/6/2026
The DrinkedIn BarFinder application for Android, when Adobe PhoneGap 2.9.0 or earlier is used, allows remote attackers to execute arbitrary JavaScript code, and consequently obtain sensitive fine-geolocation information, by leveraging control over one of a number of adult sites, as demonstrated by (1)…
ModificadaMedia (4.3)1.4%—Alexey Sukhotin Elfinder24/6/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the elFinder file manager module 6.x-0.x before 6.x-0.8 and 7.x-0.x before 7.x-0.8 for Drupal allows remote attackers to hijack the authentication of unspecified victims to create, modify, or delete files via unknown vectors.
Orbitaley — Vulnerabilidades