Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2952▲ 10 respecto a la semana anterior
Críticas / altas1451▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.21%—Keking KkfileviewAI16/9/202622/9/2026
kkFileView >= 4.2.0 is vulnerable to Server-Side Request Forgery (SSRF). The cross-origin file proxy endpoint /getCorsFile is protected by TrustHostFilter against the trust.host whitelist. However, the URL parameter validated by the filter is not the same parameter the controller actually fetches: the filter validates…
AplazadaMedia (6.1)0.25%—Keking KkfileviewAI16/9/202622/9/2026
kkFileView 5.0.0 through 5.0.2 allows reflected XSS via the /onlinePreview endpoint. The OnlinePreviewController passes the user-controlled page and kkagent request parameters to FreeMarker templates without sanitization, and the templates insert these values into raw JavaScript contexts.
AplazadaMedia (5.3)0.44%—Keking KkfileviewAI11/8/20269/9/2026
kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated POST /listFiles endpoint in server/src/main/java/cn/keking/web/controller/FileController.java passes the user-controlled path parameter from FileController#getFiles to Files.newDirectoryStream without…
AplazadaMedia (5.8)0.43%—Keking KkfileviewAI11/8/20269/9/2026
kkFileView is a universal file online preview project based on Spring Boot. Prior to 5.0.1, the unauthenticated GET /addTask endpoint in kkFileView is omitted from TrustHostFilter and TrustDirFilter in server/src/main/java/cn/keking/config/WebConfig.java, allowing FileConvertQueueTask to fetch an attacker-selected URL…
AnalizadaBaja (2.1)0.76%—Yijiusmile Kkfileviewofficeedit14/7/202517/6/2026
A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. It has been classified as critical. This affects the function deleteFile of the file /deleteFile. The manipulation of the argument fileName leads to path traversal. It is possible to initiate the attack…
AnalizadaBaja (2.1)0.49%—Yijiusmile Kkfileviewofficeedit14/7/202517/6/2026
A vulnerability was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this issue is the function fileUpload of the file /fileUpload. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The…
AnalizadaBaja (2.1)0.60%—Yijiusmile Kkfileviewofficeedit14/7/202517/6/2026
A vulnerability has been found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd and classified as critical. Affected by this vulnerability is the function onlinePreview of the file /onlinePreview. The manipulation of the argument url leads to path traversal. The attack can be launched…
AnalizadaBaja (2.1)0.52%—Yijiusmile Kkfileviewofficeedit14/7/202517/6/2026
A vulnerability, which was classified as critical, was found in YiJiuSmile kkFileViewOfficeEdit up to 5fbc57c48e8fe6c1b91e0e7995e2d59615f37abd. Affected is the function Download of the file /download. The manipulation of the argument url leads to path traversal. It is possible to launch the attack remotely. The…
AnalizadaMedia (5.3)0.40%—Keking Kkfileview11/5/202517/6/2026
A vulnerability was found in kkFileView 4.4.0. It has been classified as critical. This affects an unknown part of the file /fileUpload. The manipulation of the argument File leads to unrestricted upload. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The…
ModificadaMedia (6.1)0.46%—Keking Kkfileview4/12/202317/6/2026
kkFileView v4.3.0 is vulnerable to Incorrect Access Control.
ModificadaMedia (6.1)1.1%—Keking Kkfileview1/2/202317/6/2026
kkFileView v4.1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.
ModificadaMedia (6.1)0.56%—Keking Kkfileview25/12/202217/6/2026
A vulnerability, which was classified as problematic, has been found in kkFileView. Affected by this issue is the function setWatermarkAttribute of the file /picturesPreview. The manipulation leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be…
ModificadaAlta (7.5)2.0%—Keking Kkfileview17/11/202217/6/2026
kkFileView v4.1.0 was discovered to contain a Server-Side Request Forgery (SSRF) via the component cn.keking.web.controller.OnlinePreviewController#getCorsFile. This vulnerability allows attackers to force the application to make arbitrary requests via injection of crafted URLs into the url parameter.
ModificadaMedia (6.1)0.44%—Keking Kkfileview17/10/202217/6/2026
kkFileView 4.0 is vulnerable to Cross Site Scripting (XSS) via controller\ Filecontroller.java.
ModificadaCrítica (9.8)2.4%—Keking Kkfileview17/10/202217/6/2026
kkFileView 4.0 is vulnerable to Server-side request forgery (SSRF) via controller\OnlinePreviewController.java.
ModificadaMedia (6.1)1.3%—Keking Kkfileview29/9/202217/6/2026
kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.'
ModificadaMedia (6.5)0.91%—Keking Kkfileview2/9/202217/6/2026
kkFileView v4.0.0 was discovered to contain an arbitrary file deletion vulnerability via the fileName parameter at /controller/FileController.java.
ModificadaMedia (6.1)1.4%—Keking Kkfileview17/8/202217/6/2026
kkFileView v4.1.0 was discovered to contain multiple cross-site scripting (XSS) vulnerabilities via the urls and currentUrl parameters at /controller/OnlinePreviewController.java.
ModificadaMedia (6.1)1.8%—Keking Kkfileview25/5/202217/6/2026
kkFileView v4.0.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the url parameter at /controller/OnlinePreviewController.java.
ModificadaAlta (7.5)11%—Keking Kkfileview15/2/202217/6/2026
kkFileview v4.0.0 has arbitrary file read through a directory traversal vulnerability which may lead to sensitive file leak on related host.