Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 3.1% | 💥 Exploit | Iptanus Wordpress File Upload | 1/4/2018 | 17/6/2026 | The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes. | |
| Modificada | Crítica (9.8) | 4.7% | — | Ajax Upload FOR Gravity Forms Project Ajax Upload FOR Gravity Forms | 8/1/2018 | 17/6/2026 | Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under wp-content/uploads/gravity_forms. | |
| Modificada | Alta (7.8) | 0.45% | — | Synology Photo Station Uploader | 23/8/2017 | 17/6/2026 | Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current… | |
| Modificada | Crítica (9.8) | 34% | — | Apache Commons Fileupload | 25/10/2016 | 7/10/2026 | Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution | |
| Modificada | Alta (7.5) | 36% | — | HP Icewall Identity ManagerHP Icewall SSO Agent OptionApache TomcatDebian Linux+2 | 4/7/2016 | 7/10/2026 | The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string. | |
| Modificada | Media (6.1) | 6.0% | — | WordpressPlupload | 22/5/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack. | |
| Modificada | Alta (7.5) | 2.2% | — | Frontend User Upload Project Frontend User Upload | 16/6/2015 | 17/6/2026 | Unrestricted file upload vulnerability in the Frontend User Upload (feupload) extension 0.5.0 and earlier for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension using a frontend form, then accessing it via a direct request to the file in the fileadmin folder. | |
| Modificada | Media (6.8) | 0.73% | — | Webform Multiple File Upload Project Webform Multiple File Upload | 15/6/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Webform Multiple File Upload module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of certain users for requests that delete files via unspecified vectors. | |
| Modificada | Media (6.5) | 1.8% | — | Avatar Uploader Project Avatar Uploader | 26/2/2015 | 17/6/2026 | Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors. | |
| Modificada | Media (6.8) | 0.61% | — | Maianscriptworld Maian Uploader | 13/1/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Maian Uploader 4.0 allow remote attackers to hijack the authentication of unspecified users for requests that conduct cross-site scripting (XSS) attacks via the width parameter to (1) uploader/admin/js/load_flv.js.php or (2) uploader/js/load_flv.js.php. | |
| Modificada | Media (5) | 1.8% | — | Maianscriptworld Maian Uploader | 13/1/2015 | 17/6/2026 | Maian Uploader 4.0 allows remote attackers to obtain sensitive information via a request without the height parameter to load_flv.js.php, which reveals the installation path in an error message. | |
| Modificada | Alta (7.5) | 2.1% | — | Maianscriptworld Maian Uploader | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in admin/data_files/move.php in Maian Uploader 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Maian Script World Maian Uploader | 13/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the width parameter to (1) uploader/admin/js/load_flv.js.php or (2) uploader/js/load_flv.js.php. | |
| Modificada | Media (4.3) | 6.5% | 💥 Exploit | Frontend Uploader Project Frontend Uploader | 2/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI. | |
| Modificada | Media (4) | 1.5% | — | Avatar Uploader Project Avatar Uploader | 1/12/2014 | 17/6/2026 | Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel. | |
| Modificada | Media (6.5) | 1.7% | — | Najeebmedia N-media File Uploader | 26/9/2014 | 17/6/2026 | Unrestricted file upload vulnerability in the N-Media file uploader plugin before 3.4 for WordPress allows remote authenticated users to execute arbitrary PHP code by leveraging Author privileges to store a file. | |
| Modificada | Media (6.8) | 0.97% | — | Wordpress File Upload Project Wordpress File Upload | 12/8/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors. NOTE: some of these details are obtained from third… | |
| Modificada | Alta (7.5) | 2.7% | 💥 Exploit | Megalab THE Uploader | 12/8/2014 | 16/6/2026 | SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (4.3) | 9.2% | 💥 Exploit | Roberta Bramski Uploader | 4/4/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter. | |
| Modificada | Alta (7.5) | 83% | 💥 Exploit | Oracle Retail ApplicationsApache Commons FileuploadApache Tomcat | 1/4/2014 | 7/10/2026 | MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions. | |
| Modificada | Media (6.8) | 4.2% | — | Cdsincdesign Simple Dropbox Upload Form | 30/9/2013 | 16/6/2026 | Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/. | |
| Modificada | Media (4.3) | 9.1% | 💥 Exploit | Swfupload Project SwfuploadTinymce Image ManagerWordpress | 19/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function. | |
| Modificada | Media (4.3) | 3.1% | — | Moxiecode PluploadWordpressFedoraproject Fedora | 8/7/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter. | |
| Modificada | Media (6.8) | 0.68% | — | Apache Commons Fileupload | 15/3/2013 | 7/10/2026 | The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack. | |
| Modificada | Media (6.8) | 4.8% | 💥 Exploit | Wasen MOD Simplefileupload | 31/8/2012 | 16/6/2026 | Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code by uploading a file with a (1) php5, (2) php6, or (3) double (e.g. .php.jpg) extension, then accessing it via a direct request to the file… |