Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)3.9%—1UP Oneupuploaderbundle5/2/202017/6/2026
Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to BlueimpController.php; the (2) dzchunkindex, (3) dzuuid, or…
ModificadaAlta (8.8)1.9%—Codecov Nodejs Uploader25/1/202017/6/2026
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
ModificadaCrítica (9.8)2.6%—Abcprintf Upload-image-with-ajax23/12/201917/6/2026
Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution.
ModificadaCrítica (9.8)1.9%—Maleck Image Uploader AND Browser FOR Ckeditor2/12/201917/6/2026
Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.
ModificadaMedia (6.1)0.92%—Awesomemotive Easy Digital DownloadsEasydigitaldownloads Upload File23/10/201917/6/2026
The Easy Digital Downloads (EDD) Upload File extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused.
ModificadaAlta (7.2)1.9%—Zx-csv-upload Project Zx-csv-upload13/9/201917/6/2026
The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter.
ModificadaMedia (6.1)0.93%—Easy PDF Restaurant Menu Upload Project Easy PDF Restaurant Menu Upload30/8/201917/6/2026
The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS.
ModificadaMedia (6.1)1.3%—Webcraftic Simple 301 Redirects-addon-bulk Uploader29/8/201917/6/2026
The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.
ModificadaAlta (7.5)1.4%—Iptanus Wordpress File Upload22/8/201917/6/2026
The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files.
ModificadaAlta (7.5)1.4%—Iptanus Wordpress File Upload22/8/201917/6/2026
The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files.
ModificadaAlta (7.5)1.4%—Iptanus Wordpress File Upload22/8/201917/6/2026
The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files.
ModificadaAlta (7.5)1.4%—Iptanus Wordpress File Upload22/8/201917/6/2026
The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files.
ModificadaAlta (8.1)8.0%💥 PoCNinjaforms Ninja Forms File Uploads7/5/201917/8/2026
Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters.
ModificadaAlta (8.8)1.7%—Jenkins Diawi Upload4/4/201917/6/2026
Jenkins Diawi Upload Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
ModificadaMedia (6.5)1.2%—Jenkins Upload TO Pgyer4/4/201917/6/2026
Jenkins Upload to pgyer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
ModificadaMedia (6.5)1.5%—Jenkins Fortify ON Demand Uploader28/3/201917/6/2026
A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
ModificadaMedia (6.5)1.3%—Jenkins Fortify ON Demand Uploader28/3/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers to initiate a connection to an attacker-specified server.
ModificadaCrítica (9.8)2.3%—Dextsolution Dextuploadx528/12/201817/6/2026
DEXTUploadX5 version Between 1.0.0.0 and 2.2.0.0 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. this can be leveraged for code execution.
ModificadaCrítica (9.8)1.8%—Fineuploader Php-traditional-server19/11/201817/6/2026
Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2
ModificadaCrítica (9.8)3.5%💥 PoCHayageek Jquery Upload File19/11/201817/6/2026
Arbitrary file upload in jQuery Upload File <= 4.0.2
ModificadaCrítica (9.8)3.5%—PrestashopMypresta Customer Files Upload19/11/201817/6/2026
modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations under modules/productfiles), order (for…
ModificadaCrítica (9.8)97%💥 ExploitJquery File Upload Project Jquery File Upload11/10/201812/8/2026
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0
ModificadaCrítica (9.8)3.5%—Tinywebgallery Wordpress Flash Uploader25/4/201817/6/2026
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.
ModificadaMedia (6.1)3.6%💥 ExploitIptanus Wordpress File Upload7/4/201817/6/2026
The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.
ModificadaAlta (7.5)55%💥 ExploitDrupal Avatar Uploader4/4/201817/6/2026
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
Orbitaley — Vulnerabilidades