Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 3.9% | — | 1UP Oneupuploaderbundle | 5/2/2020 | 17/6/2026 | Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to BlueimpController.php; the (2) dzchunkindex, (3) dzuuid, or… | |
| Modificada | Alta (8.8) | 1.9% | — | Codecov Nodejs Uploader | 25/1/2020 | 17/6/2026 | Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument. | |
| Modificada | Crítica (9.8) | 2.6% | — | Abcprintf Upload-image-with-ajax | 23/12/2019 | 17/6/2026 | Due to a logic error in the code, upload-image-with-ajax v1.0 allows arbitrary files to be uploaded to the web root allowing code execution. | |
| Modificada | Crítica (9.8) | 1.9% | — | Maleck Image Uploader AND Browser FOR Ckeditor | 2/12/2019 | 17/6/2026 | Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code. | |
| Modificada | Media (6.1) | 0.92% | — | Awesomemotive Easy Digital DownloadsEasydigitaldownloads Upload File | 23/10/2019 | 17/6/2026 | The Easy Digital Downloads (EDD) Upload File extension for WordPress, as used with EDD 1.8.x before 1.8.7, 1.9.x before 1.9.10, 2.0.x before 2.0.5, 2.1.x before 2.1.11, 2.2.x before 2.2.9, and 2.3.x before 2.3.7, has XSS because add_query_arg is misused. | |
| Modificada | Alta (7.2) | 1.9% | — | Zx-csv-upload Project Zx-csv-upload | 13/9/2019 | 17/6/2026 | The zx-csv-upload plugin 1 for WordPress has SQL injection via the id parameter. | |
| Modificada | Media (6.1) | 0.93% | — | Easy PDF Restaurant Menu Upload Project Easy PDF Restaurant Menu Upload | 30/8/2019 | 17/6/2026 | The easy-pdf-restaurant-menu-upload plugin before 1.1.2 for WordPress has XSS. | |
| Modificada | Media (6.1) | 1.3% | — | Webcraftic Simple 301 Redirects-addon-bulk Uploader | 29/8/2019 | 17/6/2026 | The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file. | |
| Modificada | Alta (7.5) | 1.4% | — | Iptanus Wordpress File Upload | 22/8/2019 | 17/6/2026 | The wp-file-upload plugin before 3.0.0 for WordPress has insufficient restrictions on upload of php, js, pht, php3, php4, php5, phtml, htm, html, and htaccess files. | |
| Modificada | Alta (7.5) | 1.4% | — | Iptanus Wordpress File Upload | 22/8/2019 | 17/6/2026 | The wp-file-upload plugin before 2.7.1 for WordPress has insufficient restrictions on upload of .js files. | |
| Modificada | Alta (7.5) | 1.4% | — | Iptanus Wordpress File Upload | 22/8/2019 | 17/6/2026 | The wp-file-upload plugin before 2.5.0 for WordPress has insufficient restrictions on upload of .php files. | |
| Modificada | Alta (7.5) | 1.4% | — | Iptanus Wordpress File Upload | 22/8/2019 | 17/6/2026 | The wp-file-upload plugin before 3.4.1 for WordPress has insufficient restrictions on upload of .php.js files. | |
| Modificada | Alta (8.1) | 8.0% | 💥 PoC | Ninjaforms Ninja Forms File Uploads | 7/5/2019 | 17/8/2026 | Path Traversal and Unrestricted File Upload exists in the Ninja Forms plugin before 3.0.23 for WordPress (when the Uploads add-on is activated). This allows an attacker to traverse the file system to access files and execute code via the includes/fields/upload.php (aka upload/submit page) name and tmp_name parameters. | |
| Modificada | Alta (8.8) | 1.7% | — | Jenkins Diawi Upload | 4/4/2019 | 17/6/2026 | Jenkins Diawi Upload Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (6.5) | 1.2% | — | Jenkins Upload TO Pgyer | 4/4/2019 | 17/6/2026 | Jenkins Upload to pgyer Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (6.5) | 1.5% | — | Jenkins Fortify ON Demand Uploader | 28/3/2019 | 17/6/2026 | A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | |
| Modificada | Media (6.5) | 1.3% | — | Jenkins Fortify ON Demand Uploader | 28/3/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers to initiate a connection to an attacker-specified server. | |
| Modificada | Crítica (9.8) | 2.3% | — | Dextsolution Dextuploadx5 | 28/12/2018 | 17/6/2026 | DEXTUploadX5 version Between 1.0.0.0 and 2.2.0.0 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. this can be leveraged for code execution. | |
| Modificada | Crítica (9.8) | 1.8% | — | Fineuploader Php-traditional-server | 19/11/2018 | 17/6/2026 | Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2 | |
| Modificada | Crítica (9.8) | 3.5% | 💥 PoC | Hayageek Jquery Upload File | 19/11/2018 | 17/6/2026 | Arbitrary file upload in jQuery Upload File <= 4.0.2 | |
| Modificada | Crítica (9.8) | 3.5% | — | PrestashopMypresta Customer Files Upload | 19/11/2018 | 17/6/2026 | modules/orderfiles/ajax/upload.php in the Customer Files Upload addon 2018-08-01 for PrestaShop (1.5 through 1.7) allows remote attackers to execute arbitrary code by uploading a php file via modules/orderfiles/upload.php with auptype equal to product (for upload destinations under modules/productfiles), order (for… | |
| Modificada | Crítica (9.8) | 97% | 💥 Exploit | Jquery File Upload Project Jquery File Upload | 11/10/2018 | 12/8/2026 | Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0 | |
| Modificada | Crítica (9.8) | 3.5% | — | Tinywebgallery Wordpress Flash Uploader | 25/4/2018 | 17/6/2026 | The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path. | |
| Modificada | Media (6.1) | 3.6% | 💥 Exploit | Iptanus Wordpress File Upload | 7/4/2018 | 17/6/2026 | The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS. | |
| Modificada | Alta (7.5) | 55% | 💥 Exploit | Drupal Avatar Uploader | 4/4/2018 | 17/6/2026 | Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. |