Vulnerabilities

Summary — last 7 days

New vulnerabilities2,494▼ 451 vs. last week
Critical / high1,280▼ 7 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)64▼ 463 vs. last week
–

18 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredMedium (5.1)0.65%—Ready File ExplorerAI4/16/20256/17/2026
A cross-site scripting (XSS) vulnerability in Ready_'s File Explorer upload functionality allows injection of arbitrary JavaScript code in filename. Injected content is stored on server and is executed every time a user interacts with the uploaded file.
AnalyzedMedium (6.5)0.55%—Dhtmlx File Explorer2/7/20256/17/2026
Local File Inclusion vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the file download functionality.
AnalyzedMedium (6.5)0.75%—Dhtmlx File Explorer2/7/20256/17/2026
Directory Traversal vulnerability in dhtmlxFileExplorer v.8.4.6 allows a remote attacker to obtain sensitive information via the File Listing function.
ModifiedMedium (5.4)0.57%—Wifi File Explorer Project Wifi File Explorer7/20/20236/17/2026
A vulnerability was found in Dooblou WiFi File Explorer 1.13.3. It has been declared as problematic. Affected by this vulnerability is an unknown functionality. The manipulation of the argument search/order/download/mode leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed…
ModifiedMedium (4.6)0.42%—File Explorer Project File Explorer10/22/20216/17/2026
An issue in the authentication mechanism in Nong Ge File Explorer v1.4 unauthenticated allows to access sensitive data.
ModifiedHigh (8.8)1.5%—Super File Explorer Project Super File Explorer1/28/20206/17/2026
An arbitrary file upload vulnerability has been discovered in the Super File Explorer app 1.0.1 for iOS. The vulnerability is located in the developer path that is accessible and hidden next to the root path. By default, there is no password set for the FTP or Web UI service.
ModifiedHigh (7.5)1.6%—Estrongs ES File Explorer File Manager9/5/20196/17/2026
The master-password feature in the ES File Explorer File Manager application 4.2.0.1.3 for Android can be bypassed via a com.estrongs.android.pop.ftp.ESFtpShortcut intent, leading to remote FTP access to the entirety of local storage.
ModifiedHigh (7.5)2.5%—Webfile Explorer Project Webfile Explorer5/9/20196/17/2026
http://codecanyon.net/user/Endober WebFile Explorer 1.0 is affected by: SQL Injection. The impact is: Arbitrary File Download (remote). The component is: $file = $_GET['id'] in download.php. The attack vector is:…
ModifiedMedium (4.2)0.39%—Estrongs ES File Explorer File Manager2/15/20196/17/2026
The Help feature in the ES File Explorer File Manager application 4.1.9.7.4 for Android allows session hijacking by a Man-in-the-middle attacker on the local network because HTTPS is not used, and an attacker's web site is displayed in a WebView with no information about the URL.
ModifiedHigh (8.1)64%—Estrongs ES File Explorer File Manager1/16/20196/17/2026
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary files or execute applications via TCP port 59777 requests on the local Wi-Fi network. This TCP port remains open after the ES application has been launched once, and responds to unauthenticated…
ModifiedMedium (5.5)0.40%—X File Explorer Project X File ExplorerDebian Linux7/16/20186/17/2026
X File Explorer (aka xfe) might allow local users to bypass intended access restrictions and gain access to arbitrary files by leveraging failure to use directory masks when creating files on Samba and NFS shares.
ModifiedHigh (7.5)3.1%—Estrongs ES File Explorer8/28/20176/17/2026
Directory traversal vulnerability in ES File Explorer 3.2.4.1.
ModifiedMedium (5)1.9%—Nextapp File Explorer7/20/20146/17/2026
Directory traversal vulnerability in the NextApp File Explorer application before 2.1.0.3 for Android allows remote attackers to overwrite or create arbitrary files via a crafted filename.
ModifiedMedium (5.8)1.4%—Estrongs ES File Explorer3/20/20146/17/2026
Directory traversal vulnerability in the ES File Explorer File Manager application before 3.0.4 for Android allows remote attackers to overwrite or create arbitrary files via unspecified vectors.
ModifiedMedium (4.3)1.1%—Estrongs ES File Explorer3/5/20126/16/2026
The EStrongs ES File Explorer application 1.6.0.2 through 1.6.1.1 for Android does not properly restrict access, which allows remote attackers to read arbitrary files via vectors involving an unspecified function.
ModifiedMedium (5)2.3%—Webfileexplorer WEB File Explorer5/1/20096/16/2026
Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database via a direct request for data/db.mdb.
ModifiedHigh (7.5)2.0%—Webfileexplorer WEB File Explorer4/17/20096/16/2026
SQL injection vulnerability in body.asp in Web File Explorer 3.1 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModifiedHigh (10)10%—Webfileexplorer WEB File Explorer4/17/20096/16/2026
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the savefile action with a file parameter containing a filename that has an executable extension.