Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.32% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 1/9/2026 | Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the application via making a POST request to the endpoint with needed parameters and header. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application… | |
| Aplazada | Media (6.5) | 0.35% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint. | |
| Aplazada | Media (5.3) | 0.36% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint. | |
| Aplazada | Alta (8.1) | 0.53% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint. | |
| Aplazada | Media (5.3) | 0.34% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 9/9/2026 | Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request. | |
| Aplazada | Media (6.5) | 0.54% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=. | |
| Aplazada | Media (5.3) | 0.36% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 1/9/2026 | User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists. | |
| Modificada | Alta (7.5) | 2.3% | — | Veno File Manager Project Veno File Manager | 4/1/2021 | 17/6/2026 | Veno File Manager 3.5.6 is affected by a directory traversal vulnerability. Using the traversal allows an attacker to download sensitive files from the server. |