Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

304 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.54%—Hide Files ON Github Project Hide Files ON Github25/12/202217/6/2026
A vulnerability, which was classified as problematic, has been found in Hide Files on GitHub up to 2.x. This issue affects the function addEventListener of the file extension/options.js. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 3.0.0 is able to address…
ModificadaMedia (4.3)0.53%—M-files9/12/202217/6/2026
Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration.
ModificadaBaja (2.6)0.55%—M-files Server2/12/202217/6/2026
Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally.
ModificadaMedia (5.3)0.62%—M-files Server30/11/202217/6/2026
Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system.
ModificadaMedia (4.3)0.48%—M-files Server30/11/202217/6/2026
Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects.
ModificadaMedia (5.4)0.63%—Jenkins Associated Files15/11/202217/6/2026
Jenkins Associated Files Plugin 0.2.1 and earlier does not escape names of associated files, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaAlta (7.5)0.41%—M-files Hubshare31/10/202217/6/2026
Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server.
ModificadaAlta (7.5)0.43%—M-files Hubshare31/10/202217/6/2026
Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL.
ModificadaMedia (5.4)0.40%—M-files Hubshare31/10/202217/6/2026
Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments.
ModificadaAlta (8.8)0.55%—M-files Hubshare31/10/202217/6/2026
Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload.
ModificadaMedia (4.3)0.57%—Nextcloud Files Access Control15/9/202217/6/2026
Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see file names in certain cases where they do not have privilege to do so. This issue has been addressed and it is recommended that the Nextcloud Files Access Control app is upgraded to 1.12.2, 1.13.1 or…
ModificadaAlta (7.2)1.2%—Uploading Svg, Webp AND ICO Files Project Uploading Svg, Webp AND ICO Files23/8/202217/6/2026
Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.
ModificadaMedia (5.4)0.56%—Uploading Svg, Webp AND ICO Files Project Uploading Svg, Webp AND ICO Files23/8/202217/6/2026
Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress.
ModificadaAlta (8.8)1.0%—Mediajedi User Private Files8/8/202223/6/2026
The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded.
ModificadaCrítica (9.8)25%—Acrontum Filesystem-template5/8/202217/6/2026
The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input.
ModificadaMedia (4.3)0.68%—Jenkins Files Found Trigger27/7/202217/6/2026
Jenkins Files Found Trigger Plugin 1.5 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system.
ModificadaMedia (5.4)0.61%—Allow SVG Files Project Allow SVG Files25/7/202217/6/2026
The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads
ModificadaMedia (6.1)0.39%—Import CSV Files Project Import CSV Files17/7/202217/6/2026
The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resulting in a Reflected Cross-Site Scripting
ModificadaMedia (5.4)0.78%—Jenkins Filesystem List Parameter23/6/202217/6/2026
Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objects list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.
ModificadaAlta (7.2)1.4%—Allow SVG Files Project Allow SVG Files20/6/202217/6/2026
The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to upload PHP files even when they are not allowed to
ModificadaMedia (4.3)0.43%—Private Files Project Private Files13/6/202217/6/2026
The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow attackers to make a logged in admin perform such action via a CSRF attack and make the blog public
ModificadaMedia (6.5)0.42%—Files Download Delay Project Files Download Delay8/6/202217/6/2026
The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action.
ModificadaMedia (5.5)0.19%—Samsung MY Files7/6/202217/6/2026
Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files application.
ModificadaMedia (6.1)0.70%—Wpwham Checkout Files Upload FOR Woocommerce20/5/202217/6/2026
Cross-Site Scripting (XSS) vulnerability in WP Wham's Checkout Files Upload for WooCommerce plugin <= 2.1.2 at WordPress.
ModificadaMedia (4.8)0.60%—Wpsheeteditor Bulk Edit AND Create User Profiles - WP Sheet Editor16/5/202217/6/2026
The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed