Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2523▼ 417 respecto a la semana anterior
Críticas / altas1297▲ 13 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.8) | 0.43% | — | M-files WEBAI | 19/8/2026 | 31/8/2026 | CSS injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated vault administrator to inject arbitrary CSS, affecting the web user interface displayed to other vault users. | |
| Aplazada | Media (5.1) | 0.40% | — | M-files WEBAI | 19/8/2026 | 31/8/2026 | HTML injection vulnerability in M-Files Web before 26.8.16330.2 allows an authenticated attacker to affect web user interface contents displayed to other users. | |
| Modificada | Media (5.1) | 0.27% | — | M-files WEB | 4/4/2025 | 17/6/2026 | Stored XSS in M-Files Web versions from 25.1.14445.5 to 25.2.14524.4 allows an authenticated user to run scripts | |
| Modificada | Crítica (9.8) | 1.1% | — | M-files ServerM-files WEB | 18/1/2022 | 17/6/2026 | Lack of rate limiting in M-Files Server and M-Files Web products with versions before 21.12.10873.0 in certain type of user accounts allows unlimited amount of attempts and therefore makes brute-forcing login accounts easier. | |
| Modificada | Alta (7.5) | 2.9% | — | M-files WEB | 5/12/2021 | 17/6/2026 | M-Files Web before 20.10.9524.1 allows a denial of service via overlapping ranges (in HTTP requests with crafted Range or Request-Range headers). NOTE: this is disputed because the range behavior is the responsibility of the web server, not the responsibility of the individual web application | |
| Modificada | Alta (7.5) | 1.3% | — | M-files WEB | 28/10/2021 | 17/6/2026 | In M-Files Web product with versions before 20.10.9524.1 and 20.10.9445.0, a remote attacker could use a flaw to obtain unauthenticated access to 3rd party component license key information on server. |