Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2586▼ 297 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
2396 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (6.1) | 0.22% | — | ProfilepressAI | 3/10/2026 | 3/10/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via ppress_billing_address Filename Parameter in all versions up to, and including, 4.17.4 due to insufficient input… | |
| Recibida | Alta (8.8) | 0.63% | — | ProfilepressAI | 3/10/2026 | 3/10/2026 | The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content – ProfilePress plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 4.17.4 via the get_user_profile_structure. This makes it possible for authenticated… | |
| Aplazada | Alta (8.1) | 0.52% | — | Ninjaforms Ninja Forms File UploadsAI | 2/10/2026 | 2/10/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used… | |
| Aplazada | Crítica (9.3) | 0.24% | — | Wordpress File UploadAI | 1/10/2026 | 1/10/2026 | Unauthenticated SQL Injection in WordPress File Upload <= 5.1.10 versions. | |
| Aplazada | Media (5.3) | 0.20% | — | Metagauss ProfilegridAI | 1/10/2026 | 1/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Metagauss ProfileGrid profilegrid-user-profiles-groups-and-communities allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ProfileGrid: from n/a through 6.0.0.2. | |
| Aplazada | Media (4.3) | 0.21% | — | Prevent Files Folders AccessAI | 30/9/2026 | 30/9/2026 | Subscriber Broken Access Control in Prevent files / folders access <= 2.6.7 versions. | |
| Aplazada | Media (6.5) | 0.21% | — | Cozmoslabs Profile BuilderAI | 30/9/2026 | 30/9/2026 | Subscriber Cross Site Scripting (XSS) in Profile Builder <= 4.0.2 versions. | |
| Aplazada | Media (4.3) | 0.15% | — | ALL IN ONE Files UploadAI | 30/9/2026 | 30/9/2026 | The All in One Files Upload WordPress plugin before 2.0.17 does not have any capability check, and does not verify the authenticity of the request, when saving its settings, allowing any authenticated user, such as a subscriber, to change them. | |
| Aplazada | Alta (8.8) | 0.28% | — | Wpeverest ALL IN ONE Files UploadAI | 30/9/2026 | 30/9/2026 | The All in One Files Upload WordPress plugin before 2.0.17 adds SVG to the site's allowed upload types and does not sanitise uploaded files or verify the authenticity of its public upload requests, allowing unauthenticated users to store files containing active content which run in the site's origin when a victim… | |
| Aplazada | Media (5.9) | 0.19% | — | Mark3labs MCP Filesystem ServerAI | 29/9/2026 | 30/9/2026 | mark3labs mcp-filesystem-server v0.11.1 is vulnerable to Directory Traversal due to an improper link resolution in validatePath (filesystemserver/handler/helper.go). When filepath.EvalSymlinks returns os.IsNotExist for a dangling symlink, the fallback validates only the parent directory and returns the unresolved… | |
| Pendiente de análisis | Alta (8.8) | 0.31% | — | NetxAIFilexAI | 29/9/2026 | 29/9/2026 | The TFTP server accepts a DATA datagram of any size. The dispatcher rejects datagrams shorter than four bytes (nxd_tftp_server.c:1037) and nothing anywhere checks an upper bound, in particular not against the protocol maximum of 4 + NX_TFTP_FILE_TRANSFER_MAX. Two things follow from that one missing check, both… | |
| Pendiente de análisis | Media (4.7) | 0.12% | — | Toshiba File ParserAI | 29/9/2026 | 29/9/2026 | Toshiba file parser crash in 4.6.0 to 4.6.8 and 4.4.0 to 4.4.18 allows denial of service | |
| Aplazada | Alta (7.5) | 0.22% | — | File ManagerAIFileorganizerAIFilemanagerpro File Manager PROAI | 26/9/2026 | 28/9/2026 | The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the… | |
| Aplazada | Media (5.9) | 0.22% | — | File ManagerAI | 26/9/2026 | 28/9/2026 | The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on… | |
| Aplazada | Alta (7.8) | 0.09% | — | Seclore Filesecure Desktop ClientAI | 25/9/2026 | 30/9/2026 | Seclore FileSecure Desktop Client before 3.25.1.0 contains improper access control vulnerability in the kernel-mode driver component that allows an authenticated local user to gain elevated privileges to NT AUTHORITY\SYSTEM on affected systems. | |
| Aplazada | Alta (7.2) | 0.26% | — | User Profile BuilderAI | 25/9/2026 | 25/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (6.4) | 0.20% | — | Codeselling User Profile BuilderAI | 25/9/2026 | 25/9/2026 | The User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Avatar Field in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This makes it possible for… | |
| Aplazada | Media (5.5) | 0.10% | — | LibsndfileAI | 24/9/2026 | 25/9/2026 | libsndfile 1.2.2 contains a misaligned memory access issue in psf_binheader_readf() while parsing WAV fmt chunks. A specially crafted WAV file can cause the function to cast an unaligned destination address to unsigned int * and perform a 4-byte store. This results in undefined behavior leading to denial of service. | |
| Pendiente de análisis | Alta (7.5) | 0.39% | — | LibsndfileAI | 24/9/2026 | 24/9/2026 | libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_read_header() when parsing crafted MAT4 (MATLAB v4) files. | |
| Pendiente de análisis | Alta (7.3) | 0.10% | — | Filemaker PROAI | 23/9/2026 | 24/9/2026 | A DLL hijacking vulnerability in the FileMaker Pro installer for Windows allowed a local user to execute arbitrary code with elevated administrator privileges by placing a malicious DLL file in the installer directory. This vulnerability is addressed in FileMaker Pro version 26.0.3. | |
| Pendiente de análisis | Crítica (9.1) | 0.33% | — | Filemaker ServerAI | 23/9/2026 | 24/9/2026 | An authorization bypass vulnerability in the FileMaker Server Web Publishing Engine allowed requests containing an extended privilege header to bypass the disabled Custom Web Publishing with XML setting and access the XML Web Publishing interface. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Pendiente de análisis | Crítica (9.1) | 0.29% | — | Filemaker ServerAI | 23/9/2026 | 24/9/2026 | An out-of-bounds read vulnerability in FileMaker Server for Linux allowed an attacker uploading a specially crafted image file to a container field to disclose process memory during thumbnail generation in FileMaker WebDirect. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Pendiente de análisis | Alta (7.8) | 0.13% | — | Filemaker ServerAI | 23/9/2026 | 24/9/2026 | A heap buffer overflow vulnerability in the FileMaker Server database engine block parsing routine allowed a maliciously crafted .fmp12 database file to cause memory corruption, potentially leading to arbitrary code execution. This vulnerability is addressed in FileMaker Server version 26.0.3. | |
| Aplazada | Media (5.5) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/content leads to unrestricted upload. The attack is possible to be carried out… | |
| Aplazada | Media (6.9) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about… |