Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 26% | 💥 Exploit | Frontend Uploader Project Frontend Uploader | 11/10/2021 | 17/6/2026 | The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly | |
| Modificada | Media (5.3) | 1.0% | — | TAD Uploader Project TAD Uploader | 8/10/2021 | 17/6/2026 | Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in. | |
| Modificada | Media (6.1) | 0.63% | — | TAD Uploader Project TAD Uploader | 8/10/2021 | 17/6/2026 | The new add subject parameter of Tad Uploader view book list function fails to filter special characters. Unauthenticated attackers can remotely inject JavaScript syntax and execute stored XSS attacks. | |
| Modificada | Media (6.1) | 0.89% | — | Johndatserakis File-upload-with-preview | 5/9/2021 | 17/6/2026 | This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file). | |
| Modificada | Alta (8.8) | 1.5% | — | Raonwiz Raon K Upload | 5/8/2021 | 17/6/2026 | A vulnerability in File Transfer Solution of Raonwiz could allow arbitrary command execution as the result of viewing a specially-crafted web page. This vulnerability is due to insufficient validation of the parameter of the specific method. An attacker could exploit this vulnerability by setting the parameter to the… | |
| Modificada | Media (4.3) | 0.70% | — | Wp-upload-restriction Project Wp-upload-restriction | 7/7/2021 | 17/6/2026 | A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior. | |
| Modificada | Media (4.3) | 0.69% | — | Wp-upload-restriction Project Wp-upload-restriction | 7/7/2021 | 17/6/2026 | A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior. | |
| Modificada | Media (5.4) | 0.63% | — | Wp-upload-restriction Project Wp-upload-restriction | 7/7/2021 | 17/6/2026 | A vulnerability in the saveCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to inject arbitrary web scripts. This issue affects versions 2.2.3 and prior. | |
| Modificada | Media (5.4) | 0.66% | — | Connekthq Instant Images - ONE Click Unsplash Uploads | 1/6/2021 | 17/6/2026 | The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site… | |
| Modificada | Crítica (9.8) | 2.2% | — | N5 Upload Form Project N5 Upload Form | 12/4/2021 | 17/6/2026 | The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it's generated with md5(uniqid(rand())), however, in the case of misconfigured servers with Directory… | |
| Modificada | Crítica (9.8) | 1.9% | — | Vanquish Woocommerce Upload Files | 5/4/2021 | 17/6/2026 | The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "blocked" extension in the "wcuf_file_name" parameter. It was also… | |
| Modificada | Alta (7.5) | 1.6% | — | Dext5upload | 26/12/2020 | 17/6/2026 | DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal in the fileVirtualPath parameter (the attacker must provide the correct fileOrgName value). | |
| Modificada | Baja (3.5) | 1.9% | — | Xmpp-http-upload Project Xmpp-http-upload | 6/10/2020 | 17/6/2026 | In xmpp-http-upload before version 0.4.0, when the GET method is attacked, attackers can read files which have a `.data` suffix and which are accompanied by a JSON file with the `.meta` suffix. This can lead to Information Disclosure and in some shared-hosting scenarios also to circumvention of authentication or other… | |
| Modificada | Alta (7.8) | 0.80% | — | Raonwiz Raon Kupload | 2/9/2020 | 17/6/2026 | RAONWIZ v2018.0.2.50 and earlier versions contains a vulnerability that could allow remote files to be downloaded by lack of validation. Vulnerabilities in downloading with Kupload agent allow files to be downloaded to arbitrary paths due to insufficient verification of extensions and download paths. This issue… | |
| Modificada | Alta (7.8) | 0.28% | — | Raonwiz K Upload | 6/8/2020 | 17/6/2026 | MyBrowserPlus downloads the files needed to run the program through the setup file (Setup.inf). At this time, there is a vulnerability in downloading arbitrary files due to insufficient integrity verification of the files. | |
| Modificada | Crítica (9.8) | 4.8% | 💥 PoC | Express-fileupload Project Express-fileuploadNetapp MAX Data | 30/7/2020 | 17/6/2026 | This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution. | |
| Modificada | Crítica (9.8) | 1.2% | — | Raonwiz Raon K Upload | 10/7/2020 | 17/6/2026 | RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and excuted by lack of validation to file extension, witch can used as remote-code-excution attacks by hackers File download & execution vulnerability in ____COMPONENT____ of RAONWIZ RAON KUpload allows… | |
| Modificada | Media (4.3) | 0.69% | — | Jenkins Slack Upload | 2/7/2020 | 17/6/2026 | Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Crítica (9.8) | 79% | 💥 Exploit | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 8/6/2020 | 17/6/2026 | The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file. | |
| Modificada | Crítica (9.8) | 0.69% | — | Raonwiz Raon K Upload | 21/5/2020 | 17/6/2026 | In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it. | |
| Modificada | Alta (7.5) | 1.7% | — | Gwtupload Project Gwtupload | 18/5/2020 | 17/6/2026 | An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) accepts a delay parameter that causes a thread to sleep. It can be abused to cause all of a server's threads to sleep, leading to denial of service. | |
| Modificada | Media (6.1) | 1.1% | — | Open Upload Project Open Upload | 12/4/2020 | 17/6/2026 | Open Upload through 0.4.3 allows XSS via index.php?action=u and the filename field. | |
| Modificada | Crítica (9.8) | 8.6% | — | Iptanus Wordpress File Upload | 13/3/2020 | 17/6/2026 | An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call. | |
| Modificada | Media (6.1) | 0.76% | — | Gwtupload Project Gwtupload | 28/2/2020 | 17/6/2026 | There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can upload a file with a malicious filename, which contains JavaScript code, which would result in XSS. Cross-site scripting enables attackers to steal data, change the appearance of a website, and perform… | |
| Modificada | Crítica (9.8) | 92% | 💥 Exploit | Creative-solutions Creative Contact FormJquery File Upload Project Jquery File Upload | 8/2/2020 | 17/6/2026 | Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by… |