Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
262 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.7% | — | Elfinder.netcore Project Elfinder.netcore | 1/9/2021 | 17/6/2026 | This affects all versions of package elFinder.NetCore. The Path.Combine(...) method is used to create an absolute file path. Due to missing sanitation of the user input and a missing check of the generated path its possible to escape the Files directory via path traversal | |
| Modificada | Crítica (9.8) | 1.4% | — | Elfinder.netcore Project Elfinder.netcore | 1/9/2021 | 17/6/2026 | This affects all versions of package elFinder.NetCore. The ExtractAsync function within the FileSystem is vulnerable to arbitrary extraction due to insufficient validation. | |
| Modificada | Alta (7.5) | 1.3% | — | Find A Place Ljcms Project Find A Place Ljcms | 18/8/2021 | 17/6/2026 | A SQL injection vulnerability in /oa.php?c=Staff&a=read of Find a Place LJCMS v 1.3 allows attackers to access sensitive database information via a crafted POST request. | |
| Modificada | Alta (7.5) | 1.7% | — | Elfinder.aspnet Project Elfinder.aspnet | 28/7/2021 | 17/6/2026 | This affects the package elFinder.AspNet before 1.1.1. The user-controlled file name is not properly sanitized before it is used to create a file system path. | |
| Modificada | Alta (7.5) | 2.0% | — | Elfinder.net.core Project Elfinder.net.core | 14/7/2021 | 17/6/2026 | This affects the package elFinder.Net.Core from 0 and before 1.2.4. The user-controlled file name is not properly sanitized before it is used to create a file system path. | |
| Modificada | Crítica (9.8) | 70% | 💥 Exploit | Std42 Elfinder | 14/6/2021 | 17/6/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Several vulnerabilities affect elFinder 2.1.58. These vulnerabilities can allow an attacker to execute arbitrary code and commands on the server hosting the elFinder PHP connector, even with minimal configuration. The issues were… | |
| Modificada | Crítica (9.8) | 19% | 💥 Exploit | Std42 Elfinder | 13/6/2021 | 17/6/2026 | The package studio-42/elfinder before 2.1.58 are vulnerable to Remote Code Execution (RCE) via execution of PHP code in a .phar file. NOTE: This only applies if the server parses .phar files as PHP. | |
| Modificada | Media (6.5) | 1.1% | — | Purethemes FindeoPurethemes Realteo | 22/4/2021 | 17/6/2026 | The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not ensure that the requested property to be deleted belong to the user making the request, allowing any authenticated users to delete arbitrary properties by tampering with the property_id parameter. | |
| Modificada | Media (6.1) | 6.3% | 💥 Exploit | Purethemes FindeoPurethemes Realteo | 22/4/2021 | 17/6/2026 | The Realteo WordPress plugin before 1.2.4, used by the Findeo Theme, did not properly sanitise the keyword_search, search_radius. _bedrooms and _bathrooms GET parameters before outputting them in its properties page, leading to an unauthenticated reflected Cross-Site Scripting issue. | |
| Modificada | Media (6.1) | 4.7% | 💥 Exploit | Episerver Find | 31/3/2021 | 17/6/2026 | An Open Redirect vulnerability in EpiServer Find before 13.2.7 allows an attacker to redirect users to untrusted websites via the _t_redirect parameter in a crafted URL, such as a /find_v2/_click URL. | |
| Modificada | Alta (8.8) | 1.5% | — | Sunhater Kcfinder | 1/1/2021 | 17/6/2026 | uploader.php in the KCFinder integration project through 2018-06-01 for Drupal mishandles validation, aka SA-CONTRIB-2018-024. NOTE: This project is not covered by Drupal's security advisory policy. | |
| Modificada | Media (5.5) | 0.33% | — | Oppo Reno3 PRO FirmwareOppo Find X2 PRO Firmware | 31/12/2020 | 17/6/2026 | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_da9313.c, failure to check the parameter buf in the function proc_work_mode_write in proc_work_mode_write causes a vulnerability. | |
| Modificada | Media (5.5) | 0.33% | — | Oppo Reno3 PRO FirmwareOppo Find X2 PRO Firmware | 31/12/2020 | 17/6/2026 | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_vooc.c, the function proc_fastchg_fw_update_write in proc_fastchg_fw_update_write does not check the parameter len, resulting in a vulnerability. | |
| Modificada | Media (5.5) | 0.33% | — | Oppo Reno3 PRO FirmwareOppo Find X2 PRO Firmware | 31/12/2020 | 17/6/2026 | In /SM8250_Q_Master/android/vendor/oppo_charger/oppo/charger_ic/oppo_mp2650.c, the function mp2650_data_log_write in mp2650_data_log_write does not check the parameter len which causes a vulnerability. | |
| Modificada | Media (5.5) | 0.33% | — | Oppo Reno3 PRO FirmwareOppo Find X2 PRO Firmware | 31/12/2020 | 17/6/2026 | In functions charging_limit_current_write and charging_limit_time_write in /SM8250_Q_Master/android/vendor/oppo_charger/oppo/oppo_charger.c have not checked the parameters, which causes a vulnerability. | |
| Modificada | Alta (7.5) | 1.7% | — | Find-my-way Project Find-my-way | 8/11/2020 | 17/6/2026 | This affects the package find-my-way before 2.2.5, from 3.0.0 and before 3.0.5. It accepts the Accept-Version' header by default, and if versioned routes are not being used, this could lead to a denial of service. Accept-Version can be used as an unkeyed header in a cache poisoning attack. | |
| Modificada | Media (5.4) | 0.86% | — | Jenkins Findbugs | 4/11/2020 | 17/6/2026 | Jenkins FindBugs Plugin 5.0.0 and earlier does not escape the annotation message in tooltips, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide report files to Jenkins FindBugs Plugin's post build step. | |
| Modificada | Alta (8.8) | 2.2% | — | Openfind MailauditOpenfind Mailgates | 1/11/2020 | 17/6/2026 | MailGates and MailAudit products contain Command Injection flaw, which can be used to inject and execute system commands from the cgi parameter after attackers obtain the user’s access token. | |
| Modificada | Alta (7.2) | 0.83% | — | Openfind Mail2000 | 1/9/2020 | 17/6/2026 | Openfind Mail2000 contains Broken Access Control vulnerability, which can be used to execute unauthorized commands after attackers obtain the administrator access token or cookie. | |
| Modificada | Crítica (9.8) | 1.9% | — | Openfind MailauditOpenfind Mailgates | 23/6/2020 | 17/6/2026 | Openfind MailGates contains a Command Injection flaw, when receiving email with specific strings, malicious code in the mail attachment will be triggered and gain unauthorized access to system files. | |
| Modificada | Media (5.9) | 0.48% | — | Nutfind | 12/6/2020 | 17/6/2026 | Missing SSL Certificate Validation in the Nutfind.com application through 3.9.12 for Android allows a man-in-the-middle attacker to sniff and manipulate all API requests, including login credentials and location data. | |
| Modificada | Alta (8.8) | 0.81% | — | Infolific Real-time Find AND Replace | 28/5/2020 | 17/6/2026 | An issue was discovered in the Real-Time Find and Replace plugin before 4.0.2 for WordPress. The far_options_page function did not do any nonce verification, allowing for requests to be forged on behalf of an administrator. The find and replace rules could be updated with malicious JavaScript, allowing for that be… | |
| Modificada | Alta (7.1) | 0.88% | — | Jenkins Parasoft Findings | 16/4/2020 | 17/6/2026 | Jenkins Parasoft Findings Plugin 10.4.3 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Media (6.1) | 1.1% | — | Openfind Mail2000 | 20/11/2019 | 17/6/2026 | An Open Redirect vulnerability for all browsers in MAIL2000 through version 6.0 and 7.0, which will redirect to a malicious site without authentication. This vulnerability affects many mail system of governments, organizations, companies and universities. | |
| Modificada | Media (6.1) | 1.5% | — | Openfind Mail2000 | 20/11/2019 | 17/6/2026 | The login feature in "/cgi-bin/portal" in MAIL2000 through version 6.0 and 7.0 has a cross-site scripting (XSS) vulnerability, allowing execution of arbitrary code via any parameter. This vulnerability affects many mail system of governments, organizations, companies and universities. |