Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.31% | — | M-files Hubshare | 24/5/2024 | 17/6/2026 | Stored Cross-Site Scripting vulnerability in Social Module in M-Files Hubshare before version 5.0.6.0 allows authenticated attacker to run scripts in other users browser | |
| Modificada | Alta (7.5) | 0.77% | — | M-files Server | 26/4/2024 | 17/6/2026 | Denial of service condition in M-Files Server in versions before 24.4.13592.4 and after 23.11 (excluding 24.2 LTS) allows unauthenticated user to consume computing resources. | |
| Aplazada | Media (5.3) | 0.39% | — | Anssi Laitila Shared FilesAI | 23/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Anssi Laitila Shared Files shared-files.This issue affects Shared Files: from n/a through <= 1.7.16. | |
| Modificada | Media (5.4) | 0.44% | — | M-files | 4/3/2024 | 17/6/2026 | Stored XSS Vulnerability in M-Files Web versions before 23.8 allows attacker to execute script on users browser via stored HTML document within limited time period. | |
| Modificada | Media (4.8) | 0.34% | — | Shopfiles Ebook Store | 29/2/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Shopfiles Ltd Ebook Store allows Stored XSS.This issue affects Ebook Store: from n/a through 5.788. | |
| Modificada | Media (6.5) | 0.70% | — | M-files Server | 23/2/2024 | 17/6/2026 | Denial of service condition in M-Files Server in versions before 24.2 (excluding 23.2 SR7 and 23.8 SR5) allows anonymous user to cause denial of service against other anonymous users. | |
| Modificada | Media (5.5) | 0.18% | — | Samsung AndroidSamsung Myfiles | 4/1/2024 | 17/6/2026 | Path traversal vulnerability in ZipCompressor of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file. | |
| Modificada | Media (5.5) | 0.18% | — | Samsung AndroidSamsung Myfiles | 4/1/2024 | 17/6/2026 | Path traversal vulnerability in FileUriConverter of MyFiles prior to SMR Jan-2024 Release 1 in Android 11 and Android 12, and version 14.5.00.21 in Android 13 allows local attackers to write arbitrary file. | |
| Modificada | Alta (8.8) | 2.6% | — | Tj-actions Verify-changed-files | 29/12/2023 | 17/6/2026 | The [`tj-actions/verify-changed-files`](https://github.com/tj-actions/verify-changed-files) action allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. The [`verify-changed-files`](https://github.com/tj-actions/verify-changed-files) workflow… | |
| Modificada | Alta (8.8) | 0.66% | — | Milandinic Rename Media Files | 29/12/2023 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Milan Dinić Rename Media Files.This issue affects Rename Media Files: from n/a through 1.0.1. | |
| Modificada | Crítica (9.8) | 3.4% | — | Tj-actions Changed-files | 27/12/2023 | 17/6/2026 | tj-actions/changed-files is a Github action to retrieve all files and directories. Prior to 41.0.0, the `tj-actions/changed-files` workflow allows for command injection in changed filenames, allowing an attacker to execute arbitrary code and potentially leak secrets. This issue may lead to arbitrary command execution… | |
| Modificada | Crítica (9.8) | 0.97% | — | M-files Server | 20/12/2023 | 17/6/2026 | Lack of protection against brute force attacks in M-Files Server before 23.12.13205.0 allows an attacker unlimited authentication attempts, potentially compromising targeted M-Files user accounts by guessing passwords. | |
| Modificada | Media (6.5) | 0.91% | — | M-files Server | 20/12/2023 | 17/6/2026 | A vulnerable API method in M-Files Server before 23.12.13195.0 allows for uncontrolled resource consumption. Authenticated attacker can exhaust server storage space to a point where the server can no longer serve requests. | |
| Modificada | Media (5.4) | 1.0% | 💥 PoC | Uploading Svg, Webp AND ICO Files Project Uploading Svg, Webp AND ICO Files | 4/12/2023 | 17/6/2026 | The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |
| Modificada | Alta (8.8) | 0.57% | — | M-files Server | 28/11/2023 | 17/6/2026 | Under rare conditions, the effective permissions of an object might be incorrectly calculated if the object has a specific configuration of metadata-driven permissions in M-Files Server versions 23.9, 23.10, and 23.11 before 23.11.13168.7, potentially enabling unauthorized access to the object. | |
| Modificada | Media (5.3) | 0.51% | — | M-files Server | 22/11/2023 | 17/6/2026 | Missing access permissions checks in the M-Files server before 23.11.13156.0 allow attackers to perform data write and export jobs using the M-Files API methods. | |
| Modificada | Alta (7.5) | 0.71% | — | M-files Server | 22/11/2023 | 17/6/2026 | A possibility of unwanted server memory consumption was detected through the obsolete functionalities in the Rest API methods of the M-Files server before 23.11.13156.0 which allows attackers to execute DoS attacks. | |
| Modificada | Media (4.3) | 0.49% | — | Userprivatefiles Wordpress File Sharing Plugin | 31/10/2023 | 17/6/2026 | The WordPress File Sharing Plugin WordPress plugin before 2.0.5 does not check authorization before displaying files and folders, allowing users to gain access to those filed by manipulating IDs which can easily be brute forced | |
| Modificada | Media (6.1) | 0.31% | — | Liquidfiles | 30/10/2023 | 17/6/2026 | HTML and SMTP injections on the registration page of LiquidFiles versions 3.7.13 and below, allow an attacker to perform more advanced phishing attacks against an organization. | |
| Modificada | Crítica (9.8) | 0.75% | — | Wp-plugins Secure Files | 29/10/2023 | 16/6/2026 | A vulnerability, which was classified as critical, was found in almosteffortless secure-files Plugin up to 1.1 on WordPress. Affected is the function sf_downloads of the file secure-files.php. The manipulation of the argument downloadfile leads to path traversal. Upgrading to version 1.2 is able to address this issue.… | |
| Modificada | Alta (7.3) | 0.31% | — | M-files WEB Companion | 20/10/2023 | 17/6/2026 | Insufficient blacklisting in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution via specific file types | |
| Modificada | Alta (7.8) | 0.33% | — | M-files WEB Companion | 20/10/2023 | 17/6/2026 | Execution of downloaded content flaw in M-Files Web Companion before release version 23.10 and LTS Service Release Versions before 23.8 LTS SR1 allows Remote Code Execution | |
| Modificada | Media (5.4) | 0.43% | — | M-files Classic WEB | 20/10/2023 | 17/6/2026 | Stored XSS Vulnerability in M-Files Classic Web versions before 23.10 and LTS Service Release Versions before 23.2 LTS SR4 and 23.8 LTS SR1allows attacker to execute script on users browser via stored HTML document. | |
| Modificada | Media (6.1) | 0.34% | — | Shopfiles Ebook Store | 18/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.785 versions. | |
| Modificada | Media (4.8) | 0.40% | — | Ninjateam Filester | 16/10/2023 | 17/6/2026 | The File Manager Pro WordPress plugin before 1.8.1 does not adequately validate and escape some inputs, leading to XSS by high-privilege users. |