Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2541▼ 354 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
158 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.28% | — | Gedelumbung HospitalmanagementAISunhater KcfinderAI | 29/9/2026 | 30/9/2026 | A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the… | |
| Aplazada | Alta (8.6) | 0.45% | — | Album Cover FinderAI | 12/9/2026 | 14/9/2026 | The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks. | |
| Aplazada | Alta (8.1) | 0.90% | — | ElfinderAI | 31/8/2026 | 9/9/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 extensions are absent… | |
| Aplazada | Media (5.4) | 0.18% | — | ElfinderAI | 31/8/2026 | 9/9/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken() is not called for this state-changing operation. In the shipped… | |
| Aplazada | Alta (8.6) | 0.55% | — | ElfinderAI | 31/8/2026 | 9/9/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates $info['ip'], but get_remote_contents() selects… | |
| Aplazada | Alta (7.1) | 0.25% | — | Superstorefinder Super Store FinderAI | 31/8/2026 | 1/9/2026 | Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions. | |
| Aplazada | Alta (8.8) | 0.42% | — | Service Finder BookingAI | 13/8/2026 | 14/8/2026 | Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions. | |
| Aplazada | Media (6.5) | 0.37% | — | Service Finder BookingAI | 13/8/2026 | 14/8/2026 | Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions. | |
| Aplazada | Alta (8.7) | 0.44% | — | FlawfinderAI | 11/8/2026 | 9/9/2026 | Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection. A malicious file whose name contains ANSI escape… | |
| Aplazada | Crítica (9.1) | 0.46% | — | Superstorefinder Super Store FinderAI | 3/8/2026 | 31/8/2026 | The Super Store Finder WordPress plugin before 7.11 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database. | |
| Aplazada | Alta (8.8) | 0.44% | — | ElfinderAI | 27/5/2026 | 17/6/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolumeMySQL) allows any logged-in user, including users with read-only access to the affected volume, to inject SQL through… | |
| Analizada | Alta (8.9) | 2.7% | — | Std42 Elfinder | 23/4/2026 | 17/6/2026 | elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In configurations that… | |
| Aplazada | Media (5.3) | 0.33% | — | Doofinder FOR WoocommerceAI | 8/4/2026 | 24/7/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Doofinder Doofinder for WooCommerce doofinder-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Doofinder for WooCommerce: from n/a through <= 2.10.13. | |
| Aplazada | Alta (8.7) | 0.39% | — | Chamilo LMSAIElfinderAI | 20/2/2026 | 17/6/2026 | Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions, and execute arbitrary code by accessing… | |
| Aplazada | Media (4.6) | 0.35% | — | Office Product KEY FinderAI | 11/2/2026 | 17/6/2026 | Office Product Key Finder 1.5.4 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the registration code input. Attackers can create a specially crafted text file and paste it into the 'Name and Key' field to trigger an application crash. | |
| Aplazada | Media (4.6) | 0.30% | — | Gtalk Password FinderAI | 11/2/2026 | 17/6/2026 | GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash. | |
| Aplazada | Media (4.6) | 0.32% | — | Apkf Product KEY FinderAI | 11/2/2026 | 17/6/2026 | APKF Product Key Finder 2.5.8.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application crash. | |
| Aplazada | Media (4.4) | 0.12% | — | Qnap Qfinder PRO MACAIQnap Qsync MACAIQnap Qvpn Device Client MACAI | 2/1/2026 | 17/6/2026 | A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Qfinder Pro Mac 7.13.0 and… | |
| Modificada | Alta (8.1) | 0.53% | — | Ancorathemes Pathfinder | 18/12/2025 | 25/9/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Pathfinder pathfinder allows PHP Local File Inclusion.This issue affects Pathfinder: from n/a through <= 1.16. | |
| Analizada | Media (6.5) | 0.34% | — | Cksource Ckfinder | 5/12/2025 | 17/6/2026 | In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided. | |
| Analizada | Media (6.1) | 0.25% | — | Cksource Ckfinder | 14/11/2025 | 17/6/2026 | CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content. | |
| Aplazada | Alta (8.8) | 0.30% | — | Service Finder BookingsAI | 1/11/2025 | 17/6/2026 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (8.8) | 0.38% | — | Service Finder BookingsAI | 1/11/2025 | 17/6/2026 | The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to processing a password change request. This makes it possible for authenticated attackers… | |
| Aplazada | Media (4.3) | 0.14% | — | Superstorefinder Super Store FinderAI | 29/10/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site Request Forgery.This issue affects Super Store Finder: from n/a through <= 7.5. | |
| Aplazada | Alta (7.1) | 0.23% | — | Wpinstinct Woo-vehicle-parts-finderAI | 22/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Reflected XSS.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7. |