Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2774▲ 13 respecto a la semana anterior
Críticas / altas1465▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
186 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.22% | — | File ManagerAIFileorganizerAIFilemanagerpro File Manager PROAI | 26/9/2026 | 28/9/2026 | The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the… | |
| Aplazada | Media (5.9) | 0.22% | — | File ManagerAI | 26/9/2026 | 28/9/2026 | The File Manager WordPress plugin before 8.0.5 does not prevent unauthenticated users from downloading its database backup archives, and in some cases writes them under a fixed filename, allowing unauthenticated attackers to retrieve a full database dump including every user's email address and password hash on… | |
| Aplazada | Media (5.5) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A vulnerability has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. Impacted is the function file_put_contents of the file codeEditor.php of the component Save Handler. The manipulation of the argument filename/content leads to unrestricted upload. The attack is possible to be carried out… | |
| Aplazada | Media (6.9) | 0.47% | — | Josephchuks Php-file-manager-with-code-editorAI | 22/9/2026 | 22/9/2026 | A flaw has been found in JosephChuks php-file-manager-with-code-editor up to 3.0. This issue affects the function move_uploaded_file of the file filemanager.php. Executing a manipulation of the argument files can lead to unrestricted upload. The attack can be executed remotely. The vendor was contacted early about… | |
| Aplazada | Alta (8.5) | 0.16% | — | Ekia File ManagerAI | 14/9/2026 | 18/9/2026 | Ekia File Manager 1.2.7 exposes com.ekia.filecontrolmanager.OpenFileProvider as an exported Android ContentProvider without requiring caller permissions. The provider maps the caller-controlled URI path directly to a filesystem path and passes it to new File(...). It then supports query(), openFile(), and delete()… | |
| Aplazada | Alta (8.4) | 0.10% | — | Lenovo File ManagerAI | 10/9/2026 | 11/9/2026 | A potential improper authorization vulnerability was reported in the Lenovo File Manager Android Application, distributed exclusively in the Chinese market, that could allow a local authenticated user to read or modify protected files within the application. | |
| Aplazada | Media (5.3) | 0.32% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 1/9/2026 | Incorrect access control in /vfm-admin/ajax/sendfiles.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to send emails from the configured SMPT server on the application via making a POST request to the endpoint with needed parameters and header. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Veno File Manager Project Veno File Manager Project 4.4.9 is vulnerable to Incorrect Access Control in admin-head-updates.php. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Arbitrary File Rename Leading to Privilege Escalation in Actions::renameFile() function in Veno File Manager Project 4.4.9 allows an authenticated attacker with 'reanme' permission to take over the super administrator account via a specially crafted POST request to the affected endpoint renaming the application… | |
| Aplazada | Media (6.5) | 0.35% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Incorrect access control in /vfm-admin/ajax/streamvid.php in Veno File Manager Project in 4.4.9 allows an authenticated attacker to read any uploaded files by other users as long as it knows the path and filename via a specially crafted GET request to the affected endpoint. | |
| Aplazada | Media (5.3) | 0.36% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Absolute Path Disclosure in /vfm-admin/assets/zipstream/grandt/relativepath/RelativePath.Example1.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to know in which system directory the application code is running by sending a GET request to the endpoint. | |
| Aplazada | Alta (8.1) | 0.53% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Arbitrary file write in /vfm-admin/index.php?section=translations&action=update in Veno File Manager Project 4.4.9 allows an authenticated user with the role of super administrator to overwrite any php file in the application via a specially crafted POST request to the affected endpoint. | |
| Aplazada | Media (5.3) | 0.34% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 9/9/2026 | Incorrect access control in /vfm-admin/admin-panel/view/save-cvs.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to extract all application logs from a desired date forwards via a specially crafted POST request. | |
| Aplazada | Media (6.5) | 0.54% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Path traversal leading to Arbitrary File Read in /vfm-admin/index.php and /vfm-admin/ajax/streamvid.php in Veno File Manager Project 4.4.9 allows and authenticated attacker with super administrator role to disclose sensitive information via two specially crafted http requests (POST and GET) to the affected endpoints. | |
| Aplazada | Crítica (9.1) | 0.50% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 2/9/2026 | Veno File Manager Project 4.4.9 is vulnerable to Arbitrary File Deletion in /vfm-admin/index.php?section=translations&action=update&remove=. | |
| Aplazada | Media (5.3) | 0.36% | — | Veno File Manager Project Veno File ManagerAI | 27/8/2026 | 1/9/2026 | User enumeration in /vfm-admin/ajax/usr-check.php in Veno File Manager Project 4.4.9 allows an unauthenticated attacker to enumerate the application users via sending a specially crafted POST request to the affected endpoint with a chosen 'user_name' parameter to test if the user exists. | |
| Aplazada | Alta (8.5) | 0.32% | — | Advancedfilemanager Advanced File ManagerAI | 19/8/2026 | 26/8/2026 | The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive… | |
| Aplazada | Media (6.1) | 0.39% | — | Advancedfilemanager Advanced File ManagerAI | 16/8/2026 | 20/8/2026 | The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'soundFile' parameter in all versions up to, and including, 5.4.12 due to insufficient input sanitization and output escaping. This makes it possible… | |
| Aplazada | Alta (7.5) | 0.42% | — | File ManagerAI | 10/8/2026 | 26/8/2026 | The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector endpoints, allowing any authenticated user, such as a subscriber, to browse the entire WordPress installation directory and download files of certain types from it, including archives and documents… | |
| Aplazada | Alta (7.5) | 0.43% | — | File ManagerAI | 10/8/2026 | 26/8/2026 | The File Manager WordPress plugin before 6.9.1 does not have authorisation checks on one of its REST API routes, allowing unauthenticated users to read its file activity log, disclosing the file operations performed on the site, the paths involved and the name of the user who performed them. | |
| Aplazada | Alta (8.8) | 0.42% | — | File ManagerAI | 10/8/2026 | 26/8/2026 | The File Manager WordPress plugin before 6.9.1 does not properly authorise its file management commands, allowing any authenticated user, such as a subscriber, to read and delete arbitrary files under the WordPress installation directory, which could lead to the disclosure of the site's configuration secrets and to… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpide File Manager AND Code EditorAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WPIDE – File Manager & Code Editor <= 3.5.7 versions. | |
| Aplazada | Alta (8.8) | 1.1% | — | File ManagerAI | 6/8/2026 | 12/8/2026 | The File Manager plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the connector function in all versions from 6.0 - 6.9. This makes it possible for authenticated attackers, with subscriber-level access and above, to read and delete arbitrary files on the server,… | |
| Aplazada | Media (5.4) | 0.13% | — | Najeebmedia Frontend File ManagerAI | 2/8/2026 | 26/8/2026 | The Frontend File Manager Plugin WordPress plugin through 23.6 does not perform nonce validation on one of its file-metadata update actions, allowing an attacker to modify the metadata of a logged-in user's uploaded file via a CSRF attack, which can be leveraged to download that file. When guest uploads are enabled,… | |
| Aplazada | Baja (1.8) | 0.20% | — | ZTE File ManagerAI | 27/7/2026 | 28/7/2026 | The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity within ZTE File Manager is designed to preview compressed files. Third-party applications can launch this Activity and supply arbitrary file paths (e.g., content://zte.com.cn.filer.fileprovider/root_path), enabling file access with the privilege level… |