Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2567▼ 333 respecto a la semana anterior
Críticas / altas1341▲ 75 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
–

18 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.65%—Ready File ExplorerAI16/4/202517/6/2026
A cross-site scripting (XSS) vulnerability in Ready_'s File Explorer upload functionality allows injection of arbitrary JavaScript code in filename. Injected content is stored on server and is executed every time a user interacts with the uploaded file.
AnalizadaMedia (6.5)0.55%—Dhtmlx File Explorer7/2/202517/6/2026
Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download functionality.
AnalizadaMedia (6.5)0.75%—Dhtmlx File Explorer7/2/202517/6/2026
Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing function.
ModificadaMedia (5.4)0.57%—Wifi File Explorer Project Wifi File Explorer20/7/202317/6/2026
A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed…
ModificadaMedia (4.6)0.42%—File Explorer Project File Explorer22/10/202117/6/2026
An issue in the authentication mechanism in Nong Ge File Explorer v1.4 unauthenticated allows to access sensitive data.
ModificadaAlta (8.8)1.5%—Super File Explorer Project Super File Explorer28/1/202017/6/2026
An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service.
ModificadaAlta (7.5)1.6%—Estrongs ES File Explorer File Manager5/9/201917/6/2026
The master-password feature in the ES File Explorer File Manager application 4.2.0.1.3 for Android can be bypassed via a com.estrongs.android.pop.ftp.ESFtpShortcut intent, leading to remote FTP access to the entirety of local storage.
ModificadaAlta (7.5)2.5%—Webfile Explorer Project Webfile Explorer9/5/201917/6/2026
http://codecanyon.net/user/Endober WebFile Explorer 1.0 is affected by: SQL Injection. The impact is: Arbitrary File Download (remote). The component is: $file = $_GET['id'] in download.php. The attack vector is:…
ModificadaMedia (4.2)0.39%—Estrongs ES File Explorer File Manager15/2/201917/6/2026
The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a WebView with no information about the URL.
ModificadaAlta (8.1)64%—Estrongs ES File Explorer File Manager16/1/201917/6/2026
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated…
ModificadaMedia (5.5)0.40%—X File Explorer Project X File ExplorerDebian Linux16/7/201817/6/2026
X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.
ModificadaAlta (7.5)3.1%—Estrongs ES File Explorer28/8/201717/6/2026
Directory traversal vulnerability in ES File Explorer 3.2.4.1.
ModificadaMedia (5)1.9%—Nextapp File Explorer20/7/201417/6/2026
Directory traversal vulnerability in the NextApp File Explorer application before 2.1.0.3 for Android allows remote attackers to overwrite or create arbitrary files via a crafted filename.
ModificadaMedia (5.8)1.4%—Estrongs ES File Explorer20/3/201417/6/2026
Directory traversal vulnerability in the ES File Explorer File Manager application before 3.0.4 for Android allows remote attackers to overwrite or create arbitrary files via unspecified vectors.
ModificadaMedia (4.3)1.1%—Estrongs ES File Explorer5/3/201216/6/2026
The EStrongs ES File Explorer application 1.6.0.2 through 1.6.1.1 for Android does not properly restrict access, which allows remote attackers to read arbitrary files via vectors involving an unspecified function.
ModificadaMedia (5)2.3%—Webfileexplorer WEB File Explorer1/5/200916/6/2026
Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/db.mdb.
ModificadaAlta (7.5)2.0%—Webfileexplorer WEB File Explorer17/4/200916/6/2026
SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (10)10%—Webfileexplorer WEB File Explorer17/4/200916/6/2026
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file parameter containing a filename that has an executable extension.