Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2541▼ 354 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

158 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaBaja (2.1)0.28%—Gedelumbung HospitalmanagementAISunhater KcfinderAI29/9/202630/9/2026
A vulnerability was identified in gedelumbung HospitalManagement up to c2d45543789a3887067d3915f69d44cfc2cf76a8. Affected by this issue is the function app_user_login_model.php::cekUserLogin of the file application/models/app_user_login_model.php of the component KCFinder File Manager. Such manipulation of the…
AplazadaAlta (8.6)0.45%—Album Cover FinderAI12/9/202614/9/2026
The Album Cover Finder WordPress plugin through 0.7.0 does not properly sanitize and escape a parameter before using it in a SQL query, allowing unauthenticated users to perform SQL injection attacks.
AplazadaAlta (8.1)0.90%—ElfinderAI31/8/20269/9/2026
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, checkExtractItems() in php/elFinderVolumeDriver.class.php calls mimetypeInternalDetect() without passing the result through mimeTypeNormalize(). Because the .phtml, .phar, .php5, and .php3 extensions are absent…
AplazadaMedia (5.4)0.18%—ElfinderAI31/8/20269/9/2026
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, the netmount command is omitted from elFinderConnector::$csrfProtectedCmds in php/elFinderConnector.class.php, so validateCsrfToken() is not called for this state-changing operation. In the shipped…
AplazadaAlta (8.6)0.55%—ElfinderAI31/8/20269/9/2026
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.70, elFinder URL uploads in php/elFinder.class.php can bypass server-side request forgery protections when PHP cURL is unavailable because validate_address() validates $info['ip'], but get_remote_contents() selects…
AplazadaAlta (7.1)0.25%—Superstorefinder Super Store FinderAI31/8/20261/9/2026
Unauthenticated Cross Site Scripting (XSS) in Super Store Finder <= 7.10 versions.
AplazadaAlta (8.8)0.42%—Service Finder BookingAI13/8/202614/8/2026
Subscriber Privilege Escalation in Service Finder Booking <= 6.2 versions.
AplazadaMedia (6.5)0.37%—Service Finder BookingAI13/8/202614/8/2026
Subscriber Broken Access Control in Service Finder Booking <= 6.2 versions.
AplazadaAlta (8.7)0.44%—FlawfinderAI11/8/20269/9/2026
Flawfinder is a a static analysis tool for finding vulnerabilities in C/C++ source code. Versions prior to 2.0.20 have an improper input neutralization issue leading to output manipulation, specifically, Terminal/ANSI Escape Sequence Injection and XML Injection. A malicious file whose name contains ANSI escape…
AplazadaCrítica (9.1)0.46%—Superstorefinder Super Store FinderAI3/8/202631/8/2026
The Super Store Finder WordPress plugin before 7.11 does not sanitize a parameter of an unauthenticated AJAX action before using it in a SQL query, allowing unauthenticated attackers to perform SQL injection and extract data from the database.
AplazadaAlta (8.8)0.44%—ElfinderAI27/5/202617/6/2026
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolumeMySQL) allows any logged-in user, including users with read-only access to the affected volume, to inject SQL through…
AnalizadaAlta (8.9)2.7%—Std42 Elfinder23/4/202617/6/2026
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.67, elFinder contains a command injection vulnerability in the resize command. The bg (background color) parameter is accepted from user input and passed through image resize/rotate processing. In configurations that…
AplazadaMedia (5.3)0.33%—Doofinder FOR WoocommerceAI8/4/202624/7/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Doofinder Doofinder for WooCommerce doofinder-for-woocommerce allows Retrieve Embedded Sensitive Data.This issue affects Doofinder for WooCommerce: from n/a through <= 2.10.13.
AplazadaAlta (8.7)0.39%—Chamilo LMSAIElfinderAI20/2/202617/6/2026
Chamilo LMS 1.11.8 contains an arbitrary file upload vulnerability that allows authenticated users to upload and execute PHP files through the elfinder filemanager module. Attackers can upload files with image headers in the social myfiles section, rename them to PHP extensions, and execute arbitrary code by accessing…
AplazadaMedia (4.6)0.35%—Office Product KEY FinderAI11/2/202617/6/2026
Office Product Key Finder 1.5.4 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the registration code input. Attackers can create a specially crafted text file and paste it into the 'Name and Key' field to trigger an application crash.
AplazadaMedia (4.6)0.30%—Gtalk Password FinderAI11/2/202617/6/2026
GTalk Password Finder 2.2.1 contains a denial of service vulnerability that allows attackers to crash the application by supplying an oversized registration key. Attackers can generate a 1000-character payload and paste it into the 'Key' field to trigger an application crash.
AplazadaMedia (4.6)0.32%—Apkf Product KEY FinderAI11/2/202617/6/2026
APKF Product Key Finder 2.5.8.0 contains a denial of service vulnerability that allows attackers to crash the application by overflowing the 'Name' input field. Attackers can generate a 1000-character payload and paste it into the registration name field to trigger an application crash.
AplazadaMedia (4.4)0.12%—Qnap Qfinder PRO MACAIQnap Qsync MACAIQnap Qvpn Device Client MACAI2/1/202617/6/2026
A path traversal vulnerability has been reported to affect several product versions. If a local attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following versions: Qfinder Pro Mac 7.13.0 and…
ModificadaAlta (8.1)0.53%—Ancorathemes Pathfinder18/12/202525/9/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Pathfinder pathfinder allows PHP Local File Inclusion.This issue affects Pathfinder: from n/a through <= 1.16.
AnalizadaMedia (6.5)0.34%—Cksource Ckfinder5/12/202517/6/2026
In CKSource CKFinder before 2.5.0.1 for ASP.NET, authenticated users could download any file from the server if the correct path to a file was provided.
AnalizadaMedia (6.1)0.25%—Cksource Ckfinder14/11/202517/6/2026
CKFinder 1.4.3 is vulnerable to Cross Site Scripting (XSS) in the File Upload function. An attacker can upload a crafted SVG containing active content.
AplazadaAlta (8.8)0.30%—Service Finder BookingsAI1/11/202517/6/2026
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and excluding, 6.1. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with…
AplazadaAlta (8.8)0.38%—Service Finder BookingsAI1/11/202517/6/2026
The Service Finder Bookings plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 6.0. This is due to the plugin not properly validating a user's identity prior to processing a password change request. This makes it possible for authenticated attackers…
AplazadaMedia (4.3)0.14%—Superstorefinder Super Store FinderAI29/10/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in highwarden Super Store Finder superstorefinder-wp allows Cross Site Request Forgery.This issue affects Super Store Finder: from n/a through <= 7.5.
AplazadaAlta (7.1)0.23%—Wpinstinct Woo-vehicle-parts-finderAI22/10/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpinstinct WooCommerce Vehicle Parts Finder woo-vehicle-parts-finder allows Reflected XSS.This issue affects WooCommerce Vehicle Parts Finder: from n/a through <= 3.7.