Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.3% | 💥 PoC | Ninjateam Filester | 16/10/2023 | 17/6/2026 | The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of the server, such as a multisite installation. This leads to remote code execution. | |
| Modificada | Media (6.1) | 0.42% | — | Tammersoft Shared Files | 16/10/2023 | 17/6/2026 | The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts. | |
| Modificada | Alta (8.8) | 7.9% | — | Ninjateam Filester | 16/10/2023 | 17/6/2026 | The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users perform unwanted file system actions via CSRF attacks by using GET requests, such as uploading a web shell. | |
| Modificada | Alta (8.8) | 1.6% | — | Afterlogic Aurora Files | 3/10/2023 | 9/7/2026 | A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file. | |
| Modificada | Alta (7.2) | 1.6% | — | Miniorange Prevent Files / Folders Access | 25/9/2023 | 17/6/2026 | The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server. | |
| Modificada | Media (4.8) | 0.99% | 💥 PoC | Userprivatefiles Wordpress File Sharing Plugin | 5/9/2023 | 17/6/2026 | The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,… | |
| Modificada | Media (5.3) | 0.66% | — | M-files Classic WEB | 25/8/2023 | 17/6/2026 | Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory. | |
| Modificada | Media (6.5) | 0.74% | — | M-files Classic WEB | 25/8/2023 | 17/6/2026 | Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server | |
| Modificada | Alta (7.5) | 0.84% | — | M-files Server | 27/6/2023 | 17/6/2026 | Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service | |
| Modificada | Alta (7.8) | 0.18% | — | M-files | 25/5/2023 | 17/6/2026 | Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications | |
| Modificada | Media (4.8) | 0.37% | — | Shopfiles Ebook Store | 15/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.775 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Usbmemorydirect Simple Custom Author Profiles | 9/5/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in USB Memory Direct Simple Custom Author Profiles plugin <= 1.0.0 versions. | |
| Modificada | Alta (7.8) | 0.18% | — | M-files Server | 20/4/2023 | 17/6/2026 | Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0. | |
| Modificada | Alta (7.5) | 0.80% | — | M-files Server | 20/4/2023 | 17/6/2026 | User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a scheduled job. | |
| Modificada | Alta (7.5) | 0.84% | — | M-files Server | 20/4/2023 | 17/6/2026 | User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption. | |
| Modificada | Alta (8.8) | 0.63% | — | Nextcloud Files Automated TaggingNextcloud Server | 17/4/2023 | 17/6/2026 | Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that the Nextcloud Server is upgraded to… | |
| Modificada | Media (6.5) | 0.79% | — | M-files Server | 5/4/2023 | 17/6/2026 | User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption. | |
| Modificada | Alta (7.8) | 0.21% | — | M-files | 29/3/2023 | 17/6/2026 | Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking. | |
| Modificada | Baja (3.3) | 0.15% | — | Samsung Myfiles | 16/3/2023 | 17/6/2026 | Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific conditions. | |
| Modificada | Media (5.4) | 0.40% | — | Themekraft Post Form Registration Form Profile Form FOR User Profiles AND Content Forms | 16/3/2023 | 17/6/2026 | Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions. | |
| Modificada | Alta (7.6) | 0.36% | — | M-files Server | 6/3/2023 | 17/6/2026 | Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information. This issue affects M-Files New Web: before 22.12.12140.3. | |
| Modificada | Alta (7.5) | 0.67% | — | M-files Server | 6/3/2023 | 17/6/2026 | Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0. | |
| Modificada | Crítica (9.8) | 0.68% | — | Weberp D2files | 6/1/2023 | 17/6/2026 | A vulnerability has been found in DBRisinajumi d2files and classified as critical. Affected by this vulnerability is the function actionUpload/actionDownloadFile of the file controllers/D2filesController.php. The manipulation leads to sql injection. Upgrading to version 1.0.0 is able to address this issue. The… | |
| Modificada | Media (4.9) | 0.55% | — | M-files Client | 30/12/2022 | 17/6/2026 | Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource. | |
| Modificada | Alta (7.5) | 0.47% | — | M-files Server | 30/12/2022 | 17/6/2026 | Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set. |