Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 86 respecto a la semana anterior
Críticas / altas1460▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)91▼ 420 respecto a la semana anterior
–

95 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.22%—File ManagerAIFileorganizerAIFilemanagerpro File Manager PROAI26/9/202628/9/2026
The File Manager WordPress plugin before 8.0.5, FileOrganizer WordPress plugin before 1.2.1, File Manager Pro WordPress plugin before 2.1.3 do not correctly validate the origin of window messages received by the file browser they load on their admin screens, accepting any origin that is a leading string prefix of the…
AplazadaAlta (8.5)0.32%—Advancedfilemanager Advanced File ManagerAI19/8/202626/8/2026
The Advanced File Manager WordPress plugin before 5.4.13 does not perform capability checks in several of its file management AJAX actions, allowing users with any role to which an administrator has granted file-manager access (as low as Subscriber) to read arbitrary files on the server — including sensitive…
AplazadaMedia (6.1)0.39%—Advancedfilemanager Advanced File ManagerAI16/8/202620/8/2026
The Advanced File Manager – Ultimate File Manager for WordPress And Document Library Solution plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'soundFile' parameter in all versions up to, and including, 5.4.12 due to insufficient input sanitization and output escaping. This makes it possible…
AplazadaMedia (5.5)0.50%—ResponsivefilemanagerAI4/8/202612/8/2026
A security flaw has been discovered in Trippo ResponsiveFilemanager up to 9.14.0. The impacted element is an unknown function of the file filemanager/dialog.php. The manipulation results in unrestricted upload. The attack may be performed from remote. The exploit has been released to the public and may be used for…
AplazadaCrítica (9.1)1.4%—FileorganizerAIFile ManagerAIAdvancedfilemanager Advanced File ManagerAIFilemanagerpro File Manager PROAI6/7/20266/7/2026
The FileOrganizer WordPress plugin before 1.1.9, Advanced File Manager WordPress plugin before 5.4.12, File Manager Pro WordPress plugin before 2.1.1, File Manager WordPress plugin before 8.0.4 do not properly escape a parameter before passing it to a shell command when processing image operations, allowing…
AplazadaCrítica (9.1)0.66%—Alexantr FilemanagerAI29/6/202630/6/2026
An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component
AplazadaCrítica (9.3)0.71%—Responsivefilemanager Responsive FilemanagerAI15/6/202617/6/2026
Responsive FileManager's allows an unauthenticated attacker to upload files of any type and extension without restriction using dialog.php endpoint, leading to Remote Code Execution. This project is unmaintained at the time of CVE assignment. The vulnerability was found in the latest release 9.14.0
AplazadaAlta (8)0.61%—Responsivefilemanager Responsive File ManagerAI28/5/202617/6/2026
An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component
AplazadaBaja (2.1)0.35%—Prasathmani TinyfilemanagerAI17/4/202617/6/2026
A vulnerability was determined in prasathmani TinyFileManager up to 2.6. Affected by this vulnerability is an unknown functionality of the file /filemanager.php?p= ajax=true&type=upload of the component File Upload Handler. This manipulation of the argument uploadurl causes server-side request forgery. It is possible…
AplazadaBaja (2.1)0.54%—Prasathmani TinyfilemanagerAI17/4/202617/6/2026
A vulnerability was found in prasathmani TinyFileManager up to 2.6. Affected is an unknown function of the file /filemanager.php of the component POST Parameter Handler. The manipulation of the argument file[] results in path traversal. The attack may be performed from remote. The exploit has been made public and…
AnalizadaMedia (6.9)0.56%—Dulldusk Phpfilemanager24/3/202617/6/2026
phpFileManager 1.7.8 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by manipulating the action, fm_current_dir, and filename parameters. Attackers can send GET requests to index.php with crafted parameter values to access sensitive files like /etc/passwd…
AnalizadaCrítica (9.8)0.64%—Livewire-filemanager Filemanager16/1/202617/6/2026
Livewire Filemanager, commonly used in Laravel applications, contains LivewireFilemanagerComponent.php, which does not perform file type and MIME validation, allowing for RCE through upload of a malicious php file that can then be executed via the /storage/ URL if a commonly performed setup process within Laravel…
AnalizadaCrítica (9.3)0.62%—Dulldusk Phpfilemanager16/12/202517/6/2026
phpfm 1.7.9 contains an authentication bypass vulnerability that allows attackers to log in by exploiting loose type comparison in password hash validation. Attackers can craft specific password hashes beginning with 0e or 00e to bypass authentication and upload malicious PHP files to the server.
RechazadaSin puntuar——Unisharp Laravel-filemanagerAI5/9/20255/9/2025
Rejected reason: The unisharp/laravel-filemanager is a separate project, unrelated to laravel-filemanager.
AnalizadaMedia (6.5)0.47%—Simogeo Filemanager18/7/202517/6/2026
An arbitrary file upload vulnerability in the component /rsc/filemanager.rsc.class.php of Filemanager commit c75b914 v.2.5.0 allows attackers to execute arbitrary code via uploading a crafted SVG file.
AnalizadaMedia (6.5)1.7%—Simogeo Filemanager18/7/202517/6/2026
An issue in Filemanager v2.5.0 and below allows attackers to execute a directory traversal via sending a crafted HTTP request to the filemanager.php endpoint.
AnalizadaCrítica (9.8)0.67%—Simogeo Filemanager18/7/202517/6/2026
An arbitrary file upload vulnerability in the is_allowed_file_type() function of Filemanager v2.3.0 allows attackers to execute arbitrary code via uploading a crafted PHP file.
AplazadaAlta (7.2)0.62%—Filemanagerpro.io File Manager PROAI14/6/202517/6/2026
The File Manager Pro – Filester plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in all versions up to, and including, 1.8.8. This makes it possible for authenticated attackers, with Administrator-level access and above, to upload arbitrary files on the affected site's…
AplazadaAlta (7.2)0.83%—Advanced File Manager PRO PremiumAIAdvancedfilemanager File Manager Advanced ShortcodeAI15/5/202517/6/2026
The File Manager Advanced Shortcode plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.5.4 (file-manager-advanced-shortcode) and 2.5.6 (advanced-file-manager-pro-premium), via the 'file_manager_advanced' shortcode. This makes it possible for authenticated attackers, with…
ModificadaCrítica (9.8)0.35%—Advancedfilemanager Advanced File Manager7/5/202517/6/2026
Missing Authorization vulnerability in Saad Iqbal Advanced File Manager file-manager-advanced allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Advanced File Manager: from n/a through <= 5.3.1.
AnalizadaMedia (5.4)0.27%—Advancedfilemanager Advanced File Manager7/3/202517/6/2026
The Advanced File Manager — Ultimate WordPress File Manager and Document Library Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 5.2.14 due to insufficient input sanitization and output escaping. This makes it possible for…
AnalizadaAlta (7.5)0.90%—Advancedfilemanager Advanced File Manager17/1/202517/6/2026
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'fma_local_file_system' function in versions 5.2.12 to 5.2.13. This makes it possible for authenticated attackers, with Subscriber-level access and above and upload permissions granted by…
AplazadaMedia (6.1)0.30%—Tecrail Responsive FilemanagerAI10/1/202517/6/2026
Trippo Responsive Filemanager 9.14.0 is vulnerable to Cross Site Scripting (XSS) via file upload using the svg and pdf extensions.
AplazadaAlta (8.9)1.3%—Unisharp Laravel-filemanagerAI18/12/202417/6/2026
Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extension. This allows the attacker to execute malicious code.
AnalizadaAlta (7.5)0.70%—Advancedfilemanager Advanced File Manager3/12/202417/6/2026
The Advanced File Manager plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the 'class_fma_connector.php' file in all versions up to, and including, 5.2.10. This makes it possible for authenticated attackers, with Subscriber-level access and above, and granted…