Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2523▼ 417 respecto a la semana anterior
Críticas / altas1297▲ 13 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.8)0.43%—M-files WEBAI19/8/202631/8/2026
CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other vault users.
AplazadaMedia (5.1)0.40%—M-files WEBAI19/8/202631/8/2026
HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users.
ModificadaMedia (5.1)0.27%—M-files WEB4/4/202517/6/2026
Stored XSS in M-Files Web versions from 25.1.14445.5 to 25.2.14524.4 allows an authenticated user to run scripts
ModificadaCrítica (9.8)1.1%—M-files ServerM-files WEB18/1/202217/6/2026
Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier.
ModificadaAlta (7.5)2.9%—M-files WEB5/12/202117/6/2026
M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of the web server, not the responsibility of the individual web application
ModificadaAlta (7.5)1.3%—M-files WEB28/10/202117/6/2026
In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server.