Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
36 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.10% | — | Lenovo Filez ClientAI | 10/9/2026 | 11/9/2026 | A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges. | |
| Analizada | Media (6.9) | 0.17% | — | Filezilla-project Filezilla Client | 5/4/2026 | 24/7/2026 | FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by 'BBBB' and 'CCCC' sequences in… | |
| Analizada | Alta (7.5) | 0.13% | — | Lenovo Filez | 11/3/2026 | 19/8/2026 | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to execute arbitrary code. | |
| Analizada | Media (6) | 0.08% | — | Lenovo Filez | 11/3/2026 | 19/8/2026 | An improper certificate validation vulnerability was reported in the Lenovo Filez application that could allow a user capable of intercepting network traffic to obtain sensitive user data from the application. | |
| Analizada | Baja (2.4) | 0.09% | — | Lenovo Filez | 11/3/2026 | 19/8/2026 | A potential vulnerability was reported in the Lenovo FileZ Android application that, under certain conditions, could allow a local authenticated user to retrieve some sensitive data stored in a log file. | |
| Analizada | Alta (8.7) | 5.1% | ⚠ Explotación activa | Soliton Filezen | 13/2/2026 | 17/6/2026 | FileZen contains an OS command injection vulnerability. When FileZen Antivirus Check Option is enabled, a logged-in user may send a specially crafted HTTP request to execute an arbitrary OS command. | |
| Analizada | Alta (8.5) | 0.85% | — | Filezilla-project Filezilla Client | 19/12/2025 | 17/6/2026 | FileZilla Client 3.63.1 contains a DLL hijacking vulnerability that allows attackers to execute malicious code by placing a crafted TextShaping.dll in the application directory. Attackers can generate a reverse shell payload using msfvenom and replace the missing DLL to achieve remote code execution when the… | |
| Aplazada | Alta (8.4) | 0.16% | — | Lenovo FilezAI | 17/7/2025 | 17/6/2026 | An authentication bypass vulnerability was reported in FileZ client application that could allow a local attacker with elevated permissions access to application data. | |
| Aplazada | Media (5.1) | 0.14% | — | Lenovo FilezAI | 25/4/2025 | 17/6/2026 | An improper XML parsing vulnerability was reported in the FileZ client that could allow arbitrary file reads on the system if a crafted url is visited by a local user. | |
| Aplazada | Media (5.1) | 0.19% | — | Filez ClientAI | 25/4/2025 | 17/6/2026 | A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user. | |
| Aplazada | Media (5.1) | 0.15% | — | Lenovo FilezAI | 25/4/2025 | 17/6/2026 | An open redirect vulnerability was reported in the FileZ client that could allow information disclosure if a crafted url is visited by a local user. | |
| Aplazada | Alta (7.6) | 0.30% | — | Lenovo FilezAI | 16/12/2024 | 17/6/2026 | An improper parsing vulnerability was reported in the FileZ client that could allow a crafted file in the FileZ directory to read arbitrary files on the device due to URL preloading. | |
| Modificada | Media (5.9) | 5.8% | — | PuttyFilezilla-project Filezilla ClientWinscpTortoisegit+2 | 15/4/2024 | 17/6/2026 | In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of… | |
| Modificada | Media (5.9) | 94% | — | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Alta (7.8) | 0.95% | — | Filezilla-project Filezilla Client | 18/7/2022 | 17/6/2026 | A vulnerability has been found in FileZilla Client 3.17.0.0 and classified as problematic. This vulnerability affects unknown code of the file C:\Program Files\FileZilla FTP Client\uninstall.exe of the component Installer. The manipulation leads to unquoted search path. The attack can be initiated remotely. The… | |
| Modificada | Media (4.3) | 0.54% | — | Filezilla-project Filezilla Server | 17/7/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, was found in FileZilla Server up to 0.9.50. This affects an unknown part of the component PORT Handler. The manipulation leads to unintended intermediary. It is possible to initiate the attack remotely. Upgrading to version 0.9.51 is able to address this issue. It… | |
| Modificada | Media (6.5) | 1.9% | — | Filezilla-project Filezilla Client | 7/6/2022 | 17/6/2026 | FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does not consider this a vulnerability | |
| Modificada | Alta (7.2) | 3.5% | — | Soliton Filezen | 17/2/2021 | 17/6/2026 | FileZen (V3.0.0 to V4.2.7 and V5.0.0 to V5.0.2) allows a remote attacker with administrator rights to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Crítica (9.8) | 5.1% | — | Soliton Filezen | 14/12/2020 | 17/6/2026 | Directory traversal vulnerability in FileZen versions from V3.0.0 to V4.2.2 allows remote attackers to upload an arbitrary file in a specific directory via unspecified vectors. As a result, an arbitrary OS command may be executed. | |
| Modificada | Alta (7.8) | 3.0% | — | Filezilla-project Filezilla ClientDebian LinuxFedoraproject Fedora | 29/4/2019 | 17/6/2026 | Untrusted search path in FileZilla before 3.41.0-rc1 allows an attacker to gain privileges via a malicious 'fzsftp' binary in the user's home directory. | |
| Modificada | Crítica (9.8) | 2.4% | — | Soliton Filezen | 15/11/2018 | 17/6/2026 | FileZen V3.0.0 to V4.2.1 allows remote attackers to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.9% | — | Soliton Filezen | 15/11/2018 | 17/6/2026 | Directory traversal vulnerability in FileZen V3.0.0 to V4.2.1 allows remote attackers to upload an arbitrary file in the specific directory in FileZen via unspecified vectors. | |
| Modificada | Alta (7.4) | 95% | — | OpensslRedhat Jboss Enterprise Application PlatformRedhat Jboss Enterprise WEB PlatformRedhat Jboss Enterprise WEB Server+12 | 5/6/2014 | 17/6/2026 | OpenSSL before 0.9.8za, 1.0.0 before 1.0.0m, and 1.0.1 before 1.0.1h does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to trigger use of a zero-length master key in certain OpenSSL-to-OpenSSL communications, and consequently hijack sessions or obtain sensitive… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | OpensslFilezilla-project Filezilla ServerSiemens Application Processing Engine FirmwareSiemens CP 1543-1 Firmware+24 | 7/4/2014 | 17/6/2026 | The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packets, which allows remote attackers to obtain sensitive information from process memory via crafted packets that trigger a buffer over-read, as demonstrated by reading private keys, related to… | |
| Modificada | Media (4.3) | 3.4% | — | Filezilla-project Filezilla Server | 12/3/2009 | 16/6/2026 | Buffer overflow in FileZilla Server before 0.9.31 allows remote attackers to cause a denial of service via unspecified vectors related to SSL/TLS packets. |