Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)26%💥 ExploitFrontend Uploader Project Frontend Uploader11/10/202117/6/2026
The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
ModificadaMedia (5.3)1.0%—TAD Uploader Project TAD Uploader8/10/202117/6/2026
Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in.
ModificadaMedia (6.1)0.63%—TAD Uploader Project TAD Uploader8/10/202117/6/2026
The new add subject parameter of Tad Uploader view book list function fails to filter special characters. Unauthenticated attackers can remotely inject JavaScript syntax and execute stored XSS attacks.
ModificadaMedia (6.1)0.89%—Johndatserakis File-upload-with-preview5/9/202117/6/2026
This affects the package file-upload-with-preview before 4.2.0. A file containing malicious JavaScript code in the name can be uploaded (a user needs to be tricked into uploading such a file).
ModificadaAlta (8.8)1.5%—Raonwiz Raon K Upload5/8/202117/6/2026
A vulnerability in File Transfer Solution of Raonwiz could allow arbitrary command execution as the result of viewing a specially-crafted web page. This vulnerability is due to insufficient validation of the parameter of the specific method. An attacker could exploit this vulnerability by setting the parameter to the…
ModificadaMedia (4.3)0.70%—Wp-upload-restriction Project Wp-upload-restriction7/7/202117/6/2026
A vulnerability in the getSelectedMimeTypesByRole function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to view custom extensions added by administrators. This issue affects versions 2.2.3 and prior.
ModificadaMedia (4.3)0.69%—Wp-upload-restriction Project Wp-upload-restriction7/7/202117/6/2026
A vulnerability in the deleteCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to delete custom extensions added by administrators. This issue affects versions 2.2.3 and prior.
ModificadaMedia (5.4)0.63%—Wp-upload-restriction Project Wp-upload-restriction7/7/202117/6/2026
A vulnerability in the saveCustomType function of the WP Upload Restriction WordPress plugin allows low-level authenticated users to inject arbitrary web scripts. This issue affects versions 2.2.3 and prior.
ModificadaMedia (5.4)0.66%—Connekthq Instant Images - ONE Click Unsplash Uploads1/6/202117/6/2026
The Instant Images – One Click Unsplash Uploads WordPress plugin before 4.4.0.1 did not properly validate and sanitise its unsplash_download_w and unsplash_download_h parameter settings (/wp-admin/upload.php?page=instant-images), only validating them client side before saving them, leading to a Stored Cross-Site…
ModificadaCrítica (9.8)2.2%—N5 Upload Form Project N5 Upload Form12/4/202117/6/2026
The N5 Upload Form WordPress plugin through 1.0 suffers from an arbitrary file upload issue in page where a Form from the plugin is embed, as any file can be uploaded. The uploaded filename might be hard to guess as it's generated with md5(uniqid(rand())), however, in the case of misconfigured servers with Directory…
ModificadaCrítica (9.8)1.9%—Vanquish Woocommerce Upload Files5/4/202117/6/2026
The WooCommerce Upload Files WordPress plugin before 59.4 ran a single sanitization pass to remove blocked extensions such as .php. It was possible to bypass this and upload a file with a PHP extension by embedding a "blocked" extension within another "blocked" extension in the "wcuf_file_name" parameter. It was also…
ModificadaAlta (7.5)1.6%—Dext5upload26/12/202017/6/2026
DEXT5Upload 2.7.1262310 and earlier is affected by Directory Traversal in handler/dext5handler.jsp. This could allow remote files to be downloaded via a dext5CMD=downloadRequest action with traversal in the fileVirtualPath parameter (the attacker must provide the correct fileOrgName value).
ModificadaBaja (3.5)1.9%—Xmpp-http-upload Project Xmpp-http-upload6/10/202017/6/2026
In xmpp-http-upload before version 0.4.0, when the GET method is attacked, attackers can read files which have a `.data` suffix and which are accompanied by a JSON file with the `.meta` suffix. This can lead to Information Disclosure and in some shared-hosting scenarios also to circumvention of authentication or other…
ModificadaAlta (7.8)0.80%—Raonwiz Raon Kupload2/9/202017/6/2026
RAONWIZ v2018.0.2.50 and earlier versions contains a vulnerability that could allow remote files to be downloaded by lack of validation. Vulnerabilities in downloading with Kupload agent allow files to be downloaded to arbitrary paths due to insufficient verification of extensions and download paths. This issue…
ModificadaAlta (7.8)0.28%—Raonwiz K Upload6/8/202017/6/2026
MyBrowserPlus downloads the files needed to run the program through the setup file (Setup.inf). At this time, there is a vulnerability in downloading arbitrary files due to insufficient integrity verification of the files.
ModificadaCrítica (9.8)4.8%💥 PoCExpress-fileupload Project Express-fileuploadNetapp MAX Data30/7/202017/6/2026
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
ModificadaCrítica (9.8)1.2%—Raonwiz Raon K Upload10/7/202017/6/2026
RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and excuted by lack of validation to file extension, witch can used as remote-code-excution attacks by hackers File download & execution vulnerability in ____COMPONENT____ of RAONWIZ RAON KUpload allows…
ModificadaMedia (4.3)0.69%—Jenkins Slack Upload2/7/202017/6/2026
Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system.
ModificadaCrítica (9.8)79%💥 ExploitCodedropz Drag AND Drop Multiple File Upload - Contact Form 78/6/202017/6/2026
The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file.
ModificadaCrítica (9.8)0.69%—Raonwiz Raon K Upload21/5/202017/6/2026
In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it.
ModificadaAlta (7.5)1.7%—Gwtupload Project Gwtupload18/5/202017/6/2026
An issue was discovered in Manolo GWTUpload 1.0.3. server/UploadServlet.java (the servlet for handling file upload) accepts a delay parameter that causes a thread to sleep. It can be abused to cause all of a server's threads to sleep, leading to denial of service.
ModificadaMedia (6.1)1.1%—Open Upload Project Open Upload12/4/202017/6/2026
Open Upload through 0.4.3 allows XSS via index.php?action=u and the filename field.
ModificadaCrítica (9.8)8.6%—Iptanus Wordpress File Upload13/3/202017/6/2026
An issue was discovered in the File Upload plugin before 4.13.0 for WordPress. A directory traversal can lead to remote code execution by uploading a crafted txt file into the lib directory, because of a wfu_include_lib call.
ModificadaMedia (6.1)0.76%—Gwtupload Project Gwtupload28/2/202017/6/2026
There is an XSS (cross-site scripting) vulnerability in GwtUpload 1.0.3 in the file upload functionality. Someone can upload a file with a malicious filename, which contains JavaScript code, which would result in XSS. Cross-site scripting enables attackers to steal data, change the appearance of a website, and perform…
ModificadaCrítica (9.8)92%💥 ExploitCreative-solutions Creative Contact FormJquery File Upload Project Jquery File Upload8/2/202017/6/2026
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by…
Orbitaley — Vulnerabilidades