Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
304 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.54% | — | Hide Files ON Github Project Hide Files ON Github | 25/12/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Hide Files on GitHub up to 2.x. This issue affects the function addEventListener of the file extension/options.js. The manipulation leads to cross site scripting. The attack may be initiated remotely. Upgrading to version 3.0.0 is able to address… | |
| Modificada | Media (4.3) | 0.53% | — | M-files | 9/12/2022 | 17/6/2026 | Incorrect Privilege Assignment in M-Files Web (Classic) in M-Files before 22.8.11691.0 allows low privilege user to change some configuration. | |
| Modificada | Baja (2.6) | 0.55% | — | M-files Server | 2/12/2022 | 17/6/2026 | Incorrect privilege assignment issue in M-Files Web in M-Files Web versions before 22.5.11436.1 could have changed permissions accidentally. | |
| Modificada | Media (5.3) | 0.62% | — | M-files Server | 30/11/2022 | 17/6/2026 | Error in parser function in M-Files Server versions before 22.6.11534.1 and before 22.6.11505.0 allowed unauthenticated access to some information of the underlying operating system. | |
| Modificada | Media (4.3) | 0.48% | — | M-files Server | 30/11/2022 | 17/6/2026 | Incorrect privilege assignment in M-Files Server versions before 22.3.11164.0 and before 22.3.11237.1 allows user to read unmanaged objects. | |
| Modificada | Media (5.4) | 0.63% | — | Jenkins Associated Files | 15/11/2022 | 17/6/2026 | Jenkins Associated Files Plugin 0.2.1 and earlier does not escape names of associated files, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (7.5) | 0.41% | — | M-files Hubshare | 31/10/2022 | 17/6/2026 | Broken access controls on PDFtron WebviewerUI in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to upload malicious files to the application server. | |
| Modificada | Alta (7.5) | 0.43% | — | M-files Hubshare | 31/10/2022 | 17/6/2026 | Broken access controls on PDFtron data in M-Files Hubshare before 3.3.11.3 allows unauthenticated attackers to access restricted PDF files via a known URL. | |
| Modificada | Media (5.4) | 0.40% | — | M-files Hubshare | 31/10/2022 | 17/6/2026 | Improper input validation and output encoding in all comments fields, in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to introduce cross-site scripting attacks via specially crafted comments. | |
| Modificada | Alta (8.8) | 0.55% | — | M-files Hubshare | 31/10/2022 | 17/6/2026 | Javascript injection in PDFtron in M-Files Hubshare before 3.3.10.9 allows authenticated attackers to perform an account takeover via a crafted PDF upload. | |
| Modificada | Media (4.3) | 0.57% | — | Nextcloud Files Access Control | 15/9/2022 | 17/6/2026 | Nextcloud files access control is a nextcloud app to manage access control for files. Users with limited access can see file names in certain cases where they do not have privilege to do so. This issue has been addressed and it is recommended that the Nextcloud Files Access Control app is upgraded to 1.12.2, 1.13.1 or… | |
| Modificada | Alta (7.2) | 1.2% | — | Uploading Svg, Webp AND ICO Files Project Uploading Svg, Webp AND ICO Files | 23/8/2022 | 17/6/2026 | Authenticated Arbitrary File Upload vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress. | |
| Modificada | Media (5.4) | 0.56% | — | Uploading Svg, Webp AND ICO Files Project Uploading Svg, Webp AND ICO Files | 23/8/2022 | 17/6/2026 | Authenticated (author+) Stored Cross-Site Scripting (XSS) vulnerability in dmitrylitvinov Uploading SVG, WEBP and ICO files plugin <= 1.0.1 at WordPress. | |
| Modificada | Alta (8.8) | 1.0% | — | Mediajedi User Private Files | 8/8/2022 | 23/6/2026 | The Frontend File Manager & Sharing WordPress plugin before 1.1.3 does not filter file extensions when letting users upload files on the server, which may lead to malicious code being uploaded. | |
| Modificada | Crítica (9.8) | 25% | — | Acrontum Filesystem-template | 5/8/2022 | 17/6/2026 | The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input. | |
| Modificada | Media (4.3) | 0.68% | — | Jenkins Files Found Trigger | 27/7/2022 | 17/6/2026 | Jenkins Files Found Trigger Plugin 1.5 and earlier does not perform a permission check in a method implementing form validation, allowing attackers with Overall/Read permission to check for the existence of an attacker-specified file path on the Jenkins controller file system. | |
| Modificada | Media (5.4) | 0.61% | — | Allow SVG Files Project Allow SVG Files | 25/7/2022 | 17/6/2026 | The Allow SVG Files WordPress plugin through 1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads | |
| Modificada | Media (6.1) | 0.39% | — | Import CSV Files Project Import CSV Files | 17/7/2022 | 17/6/2026 | The Import CSV Files WordPress plugin through 1.0 does not sanitise and escaped imported data before outputting them back in a page, and is lacking CSRF check when performing such action as well, resulting in a Reflected Cross-Site Scripting | |
| Modificada | Media (5.4) | 0.78% | — | Jenkins Filesystem List Parameter | 23/6/2022 | 17/6/2026 | Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objects list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (7.2) | 1.4% | — | Allow SVG Files Project Allow SVG Files | 20/6/2022 | 17/6/2026 | The Allow svg files WordPress plugin before 1.1 does not properly validate uploaded files, which could allow high privilege users such as admin to upload PHP files even when they are not allowed to | |
| Modificada | Media (4.3) | 0.43% | — | Private Files Project Private Files | 13/6/2022 | 17/6/2026 | The Private Files WordPress plugin through 0.40 is missing CSRF check when disabling the protection, which could allow attackers to make a logged in admin perform such action via a CSRF attack and make the blog public | |
| Modificada | Media (6.5) | 0.42% | — | Files Download Delay Project Files Download Delay | 8/6/2022 | 17/6/2026 | The Files Download Delay WordPress plugin before 1.0.7 does not have authorisation and CSRF checks when reseting its settings, which could allow any authenticated users, such as subscriber to perform such action. | |
| Modificada | Media (5.5) | 0.19% | — | Samsung MY Files | 7/6/2022 | 17/6/2026 | Improper access control vulnerability in My Files prior to version 13.1.00.193 allows attackers to access arbitrary private files in My Files application. | |
| Modificada | Media (6.1) | 0.70% | — | Wpwham Checkout Files Upload FOR Woocommerce | 20/5/2022 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in WP Wham's Checkout Files Upload for WooCommerce plugin <= 2.1.2 at WordPress. | |
| Modificada | Media (4.8) | 0.60% | — | Wpsheeteditor Bulk Edit AND Create User Profiles - WP Sheet Editor | 16/5/2022 | 17/6/2026 | The Bulk Edit and Create User Profiles WordPress plugin before 1.5.14 does not sanitise and escape the Users Login, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed |