Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

25 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.6)0.50%—Filebrowser File BrowserAI14/9/202624/9/2026
File Browser through 2.63.23 applies path rules to the requested lexical path but resolves symbolic links without reapplying rules to the target, allowing authenticated users to bypass deny rules. Attackers can read and overwrite rule-denied files by accessing them through in-scope symbolic link aliases that resolve…
Pendiente de análisisAlta (7.2)0.44%—Filebrowser File BrowserAI14/9/202624/9/2026
File Browser versions >= 2.5.0 and <= 2.63.23 contain an incorrect authorization flaw in the direct-upload endpoint (resourcePostHandler in http/resource.go). Unlike the TUS upload handler, the direct-upload handler does not reject a target that is an existing directory; a POST with ?override=true aimed at a directory…
Pendiente de análisisAlta (7.1)0.44%—Filebrowser File BrowserAI14/9/202624/9/2026
File Browser through 2.63.23 contains a memory exhaustion vulnerability in the subtitle conversion endpoint that loads entire subtitle files into memory without size limits. Authenticated attackers with download permission can request conversion of large .srt, .ass, or .ssa files and exhaust server memory through…
Pendiente de análisisBaja (2.3)0.35%—Filebrowser File BrowserAI28/8/202630/9/2026
File Browser versions from 2.63.6 through 2.63.23 fail to clean up public share links when a privileged user deletes another user's shared file. Attackers can access the surviving share link to retrieve new unrelated content uploaded to the same path without authentication.
AplazadaBaja (2.7)0.43%—Filebrowser File BrowserAI18/8/202618/9/2026
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, the Link storage struct is serialized directly by sharePostHandler, shareListHandler, and shareGetsHandler through renderJSON, causing POST /api/share/{path} and…
AplazadaAlta (8.6)0.48%—Filebrowser File BrowserAI13/8/20268/9/2026
File Browser before v2.63.22 fails to validate access rules for descendants during recursive copy, rename, and delete operations, allowing authenticated users to bypass path-based access controls. Attackers can copy, rename, or delete denied files by operating on their allowed parent directory, defeating rule-based…
AplazadaAlta (7.6)0.43%—Filebrowser File BrowserAI13/8/202630/9/2026
File Browser versions from 2.50.0 through 2.63.21 fail to validate JWT expiration when proxy authentication is configured with a non-default logout page. Attackers with a previously valid token can access protected routes and administrative endpoints indefinitely, and exchange expired tokens for fresh ones via the…
AplazadaMedia (6.8)0.39%—Filebrowser File BrowserAI15/7/202615/7/2026
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. From 2.63.6 to 2.63.16, File Browser's archive builder uses strings.ReplaceAll(nameInArchive, "\", "/"), which turns a POSIX filename such as ..\..\evil.sh into the archive entry…
AplazadaAlta (8.1)0.55%—Filebrowser File BrowserAI15/7/202620/7/2026
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser builds new user scopes from usernames passed through cleanUsername() when Signup=true and CreateUserDir=true, but the many-to-one normalization can…
AplazadaBaja (3.1)0.32%—Filebrowser File BrowserAI15/7/202615/7/2026
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.17, File Browser can leave a public directory share behind when the shared directory is deleted through a path with a trailing slash because the share cleanup path…
AplazadaMedia (6.3)0.38%—Filebrowser File BrowserAI8/7/20268/7/2026
File Browser provides a web file managing interface. Prior to 2.63.16, ScopedFs validates the nearest existing ancestor of a dangling symlink as in scope and then follows the symlink during file creation, allowing an authenticated user with Create and Modify permissions to create attacker-controlled files outside the…
AplazadaAlta (8.2)0.49%—Filebrowser File BrowserAI25/6/202626/6/2026
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.16, a scoped, non-admin File Browser user holding only the Create permission can delete arbitrary files outside their scope (other tenants' data, and the application's…
AplazadaAlta (8.4)0.18%—Filebrowser File BrowserAI25/6/202625/6/2026
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.7, `POST /api/share/<path>` accepts an authenticated request for an arbitrary path and stores a public share record without checking whether the target file currently…
AplazadaAlta (7.5)0.50%—Filebrowser File BrowserAI25/6/202625/6/2026
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.14, it does not stop the HTTP file handlers from following symbolic links before they open, serve, write, share, or list a file. As a result, a scoped user — and in…
AplazadaMedia (6.5)0.55%—Filebrowser File BrowserAI25/6/202626/6/2026
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maximums allow for an arbitrarily large password to be passed into the login API. This spikes CPU and memory, and after testing, crashes, heavily…
AplazadaAlta (7.5)0.52%—Filebrowser File BrowserAI25/6/202626/6/2026
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, File Browser's public share handlers rebase the share owner's filesystem root to the shared directory and then evaluate descendant paths against the owner's global…
AplazadaAlta (8.7)0.44%—Filebrowser File BrowserAI25/6/202626/6/2026
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.33.8, when a shell interpreter is configured (e.g. /bin/sh -c), the command allowlist can be bypassed through shell metacharacters. The allowlist validates only the first…
AplazadaCrítica (9.3)0.76%—Filebrowser File BrowserAI25/6/202625/6/2026
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, the Hook Authentication feature in File Browser allows administrators to delegate login verification to an external shell command. User-supplied credentials…
AplazadaAlta (8.7)0.48%—Ajax File BrowserAI28/1/202617/6/2026
PDW File Browser 1.3 contains a remote code execution vulnerability that allows authenticated users to upload and rename webshell files to arbitrary web server locations. Attackers can upload a .txt webshell, rename it to .php, and move it to accessible directories using double-encoded path traversal techniques.
AplazadaMedia (4.8)0.24%—Ajax File BrowserAI28/1/202617/6/2026
PDW File Browser version 1.3 contains stored and reflected cross-site scripting vulnerabilities that allow authenticated attackers to inject malicious scripts through file rename and path parameters. Attackers can craft malicious URLs or rename files with XSS payloads to execute arbitrary JavaScript in victims'…
AplazadaCrítica (9.9)0.65%—Enrico Sandoli Smallerik File BrowserAI22/1/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Enrico Sandoli Smallerik File Browser smallerik-file-browser allows Upload a Web Shell to a Web Server.This issue affects Smallerik File Browser: from n/a through <= 1.1.
ModificadaMedia (5.3)2.5%—PHP File Browser Script Project PHP File Browser Script5/9/201817/6/2026
HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter.
ModificadaMedia (4)2.6%—David Azoulay WEB File Browser15/12/201116/6/2026
Directory traversal vulnerability in webFileBrowser.php in Web File Browser 0.4b14 allows remote authenticated users to read arbitrary files via a ..%2f (encoded dot dot) in the file parameter in a download action.
ModificadaAlta (7.5)53%—Ajax File Browser17/9/200716/6/2026
PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attackers to execute arbitrary PHP code via a URL in the approot parameter.
ModificadaMedia (5)2.7%—DSM Light WEB File Browser31/12/200416/6/2026
Directory traversal vulnerability in explorer.php in DSM Light Web File Browser 2.0 allows remote attackers to read arbitrary files via .. (dot dot) in the wdir parameter.