Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.25% | — | Simplefilelist Simple File ListAI | 13/7/2026 | 13/7/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Mitchell Bennis Simple File List simple-file-list allows Reflected XSS.This issue affects Simple File List: from n/a through <= 6.3.8. | |
| Aplazada | Baja (2.3) | 0.32% | — | FilebrowserAI | 12/7/2026 | 13/7/2026 | filebrowser versions before 2.63.17 fail to normalize paths before querying the share index in DeleteWithPathPrefix, allowing authenticated users to leave stale public shares behind. Attackers can delete a shared directory using a trailing-slash path, then recreate the same directory to expose new contents through the… | |
| Modificada | Crítica (10) | 2.3% | 💥 Exploit | Rsjoomla Rsfiles! | 11/7/2026 | 23/7/2026 | Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. | |
| Aplazada | Media (5.3) | 0.42% | — | Easy Upload Files During CheckoutAI | 10/7/2026 | 10/7/2026 | The Easy Upload Files During Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 3.0.1. This is due to missing authorization checks in the ufdc_custom_init() function, which processes the 'eufdc-delete' parameter without any nonce verification, capability check, or… | |
| Analizada | Media (4.9) | 0.49% | — | Claris Filemaker Server | 9/7/2026 | 10/7/2026 | An authenticated administrator may be able to achieve arbitrary code execution on the host system by uploading a malicious file through the Open Source LLM setup feature in the Admin Console. This vulnerability has been addressed in FileMaker Server 26.0.1. | |
| Aplazada | Media (4.3) | 0.34% | — | Profilegrid Memberships AND User Profiles FOR WoocommerceAI | 9/7/2026 | 9/7/2026 | The Memberships and User Profiles for WooCommerce – ProfileGrid WooCommerce Integration plugin for WordPress is vulnerable to unauthorized plugin installation and activation in versions up to, and including, 3.4. This is due to a missing capability check and missing nonce validation on the pg_install_profilegrid()… | |
| Aplazada | Alta (7.7) | 3.3% | — | Horde Virtual File SystemAI | 8/7/2026 | 14/7/2026 | Horde Virtual File System (VFS) API before 3.0.1 contains an OS command injection vulnerability in the Horde_Vfs_Smb driver where the _escapeShellCommand() method fails to sanitize command substitution sequences, allowing authenticated attackers to inject arbitrary shell commands through user-controlled filenames.… | |
| Aplazada | Media (6.3) | 0.38% | — | Filebrowser File BrowserAI | 8/7/2026 | 8/7/2026 | File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user with Create and Modify permissions to create attacker-controlled files outside the… | |
| Aplazada | Media (5.4) | 0.24% | — | LiquidfilesAI | 7/7/2026 | 9/7/2026 | An HTML injection vulnerability in the file view endpoint of LiquidFiles v4.2.7 allows authenticated attackers to execute arbitrary JavaScript in the context of the victim's browser via the uploading of and user interaction with a crafted HTML file. | |
| Aplazada | Media (5.4) | 0.24% | — | LiquidfilesAI | 7/7/2026 | 9/7/2026 | An authenticated stored cross-site scripting (XSS) vulnerability in the Upload File Shares API of LiquidFiles v4.2.7 allows attackers to execute arbitrary Javascript or HTML via injecting a crafted payload into the Name parameter. | |
| Aplazada | Alta (8.7) | 0.39% | 💥 PoC | Najeebmedia Frontend File ManagerAI | 7/7/2026 | 7/7/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not validate a file path derived from user input before deleting the referenced file, allowing unauthenticated users to delete arbitrary files on the server (such as wp-config.php) when guest upload mode is enabled. Deleting wp-config.php forces the… | |
| Aplazada | Alta (7.5) | 0.61% | — | ImagerAIImager File JpegAI | 6/7/2026 | 6/7/2026 | Imager::File::JPEG versions before 1.003 for Perl leak heap memory when reading a JPEG with repeated APP13 markers in i_readjpeg_wiol. i_readjpeg_wiol walks the marker list libjpeg returns and, for each APP13 marker, allocates a new buffer with *iptc_itext = mymalloc(...) and overwrites the previous pointer without… | |
| Aplazada | Crítica (9.1) | 1.4% | — | FileorganizerAIFile ManagerAIAdvancedfilemanager Advanced File ManagerAIFilemanagerpro File Manager PROAI | 6/7/2026 | 6/7/2026 | The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing… | |
| Aplazada | Alta (8.8) | 0.73% | — | FileorganizerAI | 6/7/2026 | 6/7/2026 | The FileOrganizer WordPress plugin before 1.2.0 does not validate the file type on several of its file-management operations, allowing authenticated users who have been granted file-manager access — which its premium add-on can extend to sub-administrator roles — to upload arbitrary PHP files and achieve remote code… | |
| Aplazada | Media (5.3) | 0.35% | — | Ninjaforms Ninja Forms File UploadsAI | 3/7/2026 | 6/7/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to read all plugin debug log… | |
| Aplazada | Crítica (9.1) | 0.66% | — | Five Star Business ProfileAISchemaAI | 2/7/2026 | 2/7/2026 | Editor Arbitrary Code Execution in Five Star Business Profile and Schema <= 2.3.19 versions. | |
| Aplazada | Alta (8.8) | 0.20% | — | Metagauss ProfilegridAI | 2/7/2026 | 30/9/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Cross Site Request Forgery.This issue affects ProfileGrid: from n/a through 6.0.0.2. | |
| Aplazada | Alta (7.5) | 0.60% | — | Ninjaforms Ninja Forms File UploadsAI | 2/7/2026 | 2/7/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and including, 3.3.29. This is due to the get_files_for_attachment() function accepting a raw attacker-controlled 'files' array when the process() method returns early due to a… | |
| Aplazada | Crítica (9.8) | 0.53% | — | Metagauss ProfilegridAI | 30/6/2026 | 30/6/2026 | The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 5.9.9.5. This is due to the plugin not validating a `user_login` on registration forms that don't contain this parameter, and not properly… | |
| Aplazada | Crítica (9.1) | 0.66% | 💥 PoC | Alexantr FilemanagerAI | 29/6/2026 | 30/6/2026 | An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component | |
| Aplazada | Alta (8.1) | 0.60% | — | Najeebmedia Frontend File ManagerAI | 28/6/2026 | 29/6/2026 | The Frontend File Manager Plugin plugin for WordPress is vulnerable to Authenticated Arbitrary File Deletion in versions up to and including 23.6. This is due to a case-sensitive bypass of the wpfm_dir_path parameter sanitization in the wpfm_file_meta_update AJAX handler, where supplying WPFM_DIR_PATH in uppercase… | |
| Aplazada | Media (6.5) | 0.47% | 💥 PoC | Najeebmedia Frontend File ManagerAI | 26/6/2026 | 26/6/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not properly verify ownership of every targeted post before permanent deletion, allowing authenticated users with author-level access and above to permanently delete arbitrary posts and pages. When the Frontend File Manager Plugin WordPress plugin… | |
| Aplazada | Alta (8.7) | 0.71% | — | Seafile SeahubAI | 25/6/2026 | 14/7/2026 | Seahub before 13.0.23 does not enforce SHARE_LINK_LOGIN_REQUIRED on GET /api/v2.1/share-link-zip-task/, allowing unauthenticated users to bypass authentication. Attackers with a folder share-link token can call the GET endpoint to obtain a fileserver zip token and download entire shared directory trees. | |
| Aplazada | Alta (8.2) | 0.49% | — | Filebrowser File BrowserAI | 25/6/2026 | 26/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.16, a scoped, non-admin File Browser user holding only the Create permission can delete arbitrary files outside their scope (other tenants' data, and the application's… | |
| Aplazada | Alta (7.2) | 0.45% | — | FilebrowserAI | 25/6/2026 | 26/6/2026 | File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, a low-privileged authenticated user of filebrowser (with create + delete permissions in their own isolated scope) can silently destroy share-link records belonging… |