Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

304 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.3%💥 PoCNinjateam Filester16/10/202317/6/2026
The File Manager Pro WordPress plugin before 1.8.1 allows admin users to upload arbitrary files, even in environments where such a user should not be able to gain full control of the server, such as a multisite installation. This leads to remote code execution.
ModificadaMedia (6.1)0.42%—Tammersoft Shared Files16/10/202317/6/2026
The Shared Files WordPress plugin before 1.7.6 does not return the right Content-Type header for the specified uploaded file. Therefore, an attacker can upload an allowed file extension injected with malicious scripts.
ModificadaAlta (8.8)7.9%—Ninjateam Filester16/10/202317/6/2026
The File Manager Pro WordPress plugin before 1.8 does not properly check the CSRF nonce in the `fs_connector` AJAX action. This allows attackers to make highly privileged users perform unwanted file system actions via CSRF attacks by using GET requests, such as uploading a web shell.
ModificadaAlta (8.8)1.6%—Afterlogic Aurora Files3/10/20239/7/2026
A deserialization vulnerability in Afterlogic Aurora Files v9.7.3 allows attackers to execute arbitrary code via supplying a crafted .sabredav file.
ModificadaAlta (7.2)1.6%—Miniorange Prevent Files / Folders Access25/9/202317/6/2026
The Prevent files / folders access WordPress plugin before 2.5.2 does not validate files to be uploaded, which could allow attackers to upload arbitrary files such as PHP on the server.
ModificadaMedia (4.8)0.99%💥 PoCUserprivatefiles Wordpress File Sharing Plugin5/9/202317/6/2026
The WordPress File Sharing Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 2.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above,…
ModificadaMedia (5.3)0.66%—M-files Classic WEB25/8/202317/6/2026
Out-of-bounds read issue in M-Files Server versions below 23.8.12892.6 and LTS Service Release Versions before 23.2 LTS SR3 allows unauthenticated user to read restricted amount of bytes from memory.
ModificadaMedia (6.5)0.74%—M-files Classic WEB25/8/202317/6/2026
Path Traversal issue in M-Files Classic Web versions below 23.6.12695.3 and LTS Service Release Versions before 23.2 LTS SR3 allows authenticated user to read some restricted files on the web server
ModificadaAlta (7.5)0.84%—M-files Server27/6/202317/6/2026
Unchecked parameter value in M-Files Server in versions before 23.6.12695.3 (excluding 23.2 SR2 and newer) allows anonymous user to cause denial of service
ModificadaAlta (7.8)0.18%—M-files25/5/202317/6/2026
Missing access permissions checks in M-Files Client before 23.5.12598.0 (excluding 23.2 SR2 and newer) allows elevation of privilege via UI extension applications
ModificadaMedia (4.8)0.37%—Shopfiles Ebook Store15/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Shopfiles Ltd Ebook Store plugin <= 5.775 versions.
ModificadaMedia (4.8)0.37%—Usbmemorydirect Simple Custom Author Profiles9/5/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in USB Memory Direct Simple Custom Author Profiles plugin <= 1.0.0 versions.
ModificadaAlta (7.8)0.18%—M-files Server20/4/202317/6/2026
Desktop component service allows lateral movement between sessions in M-Files before 23.4.12455.0.
ModificadaAlta (7.5)0.80%—M-files Server20/4/202317/6/2026
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption for a scheduled job.
ModificadaAlta (7.5)0.84%—M-files Server20/4/202317/6/2026
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.
ModificadaAlta (8.8)0.63%—Nextcloud Files Automated TaggingNextcloud Server17/4/202317/6/2026
Nextcloud is a personal home server system. Depending on the set up tags and other workflows this issue can be used to limit access of others or being able to grant them access when there are system tag based files access control or files retention rules. It is recommended that the Nextcloud Server is upgraded to…
ModificadaMedia (6.5)0.79%—M-files Server5/4/202317/6/2026
User-controlled operations could have allowed Denial of Service in M-Files Server before 23.4.12528.1 due to uncontrolled memory consumption.
ModificadaAlta (7.8)0.21%—M-files29/3/202317/6/2026
Elevation of privilege issue in M-Files Installer versions before 22.6 on Windows allows user to gain SYSTEM privileges via DLL hijacking.
ModificadaBaja (3.3)0.15%—Samsung Myfiles16/3/202317/6/2026
Improper access control vulnerability in MyFiles application prior to versions 12.2.09.0 in Android 11, 13.1.03.501 in Android 12 and 14.1.03.0 in Android 13 allows local attacker to get sensitive information of secret mode in Samsung Internet application with specific conditions.
ModificadaMedia (5.4)0.40%—Themekraft Post Form Registration Form Profile Form FOR User Profiles AND Content Forms16/3/202317/6/2026
Stored Cross-Site Scripting (XSS) vulnerability in ThemeKraft Post Form – Registration Form – Profile Form for User Profiles and Content Forms for User Submissions plugin <= 2.7.5 versions.
ModificadaAlta (7.6)0.36%—M-files Server6/3/202317/6/2026
Rendering of HTML provided by another authenticated user is possible in browser on M-Files Web before 22.12.12140.3. This allows the content to steal user sensitive information. This issue affects M-Files New Web: before 22.12.12140.3.
ModificadaAlta (7.5)0.67%—M-files Server6/3/202317/6/2026
Download key for a file in a vault was passed in an insecure way that could easily be logged in M-Files New Web in M-Files before 22.11.12011.0. This issue affects M-Files New Web: before 22.11.12011.0.
ModificadaCrítica (9.8)0.68%—Weberp D2files6/1/202317/6/2026
A vulnerability has been found in DBRisinajumi d2files and classified as critical. Affected by this vulnerability is the function actionUpload/actionDownloadFile of the file controllers/D2filesController.php. The manipulation leads to sql injection. Upgrading to version 1.0.0 is able to address this issue. The…
ModificadaMedia (4.9)0.55%—M-files Client30/12/202217/6/2026
Incorrect implementation in authentication protocol in M-Files Client before 22.5.11356.0 allows high privileged user to get other users tokens to another resource.
ModificadaAlta (7.5)0.47%—M-files Server30/12/202217/6/2026
Insertion of Sensitive Information into Log Files in M-Files Server before 22.10.11846.0 could allow to obtain sensitive tokens from logs, if specific configurations were set.