Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)3.1%💥 ExploitIptanus Wordpress File Upload1/4/201817/6/2026
The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.
ModificadaCrítica (9.8)4.7%—Ajax Upload FOR Gravity Forms Project Ajax Upload FOR Gravity Forms8/1/201817/6/2026
Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under wp-content/uploads/gravity_forms.
ModificadaAlta (7.8)0.45%—Synology Photo Station Uploader23/8/201717/6/2026
Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current…
ModificadaCrítica (9.8)34%—Apache Commons Fileupload25/10/20167/10/2026
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
ModificadaAlta (7.5)36%—HP Icewall Identity ManagerHP Icewall SSO Agent OptionApache TomcatDebian Linux+24/7/20167/10/2026
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
ModificadaMedia (6.1)6.0%—WordpressPlupload22/5/201617/6/2026
Cross-site scripting (XSS) vulnerability in plupload.flash.swf in Plupload before 2.1.9, as used in WordPress before 4.5.2, allows remote attackers to inject arbitrary web script or HTML via a Same-Origin Method Execution (SOME) attack.
ModificadaAlta (7.5)2.2%—Frontend User Upload Project Frontend User Upload16/6/201517/6/2026
Unrestricted file upload vulnerability in the Frontend User Upload (feupload) extension 0.5.0 and earlier for TYPO3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension using a frontend form, then accessing it via a direct request to the file in the fileadmin folder.
ModificadaMedia (6.8)0.73%—Webform Multiple File Upload Project Webform Multiple File Upload15/6/201517/6/2026
Cross-site request forgery (CSRF) vulnerability in the Webform Multiple File Upload module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to hijack the authentication of certain users for requests that delete files via unspecified vectors.
ModificadaMedia (6.5)1.8%—Avatar Uploader Project Avatar Uploader26/2/201517/6/2026
Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.
ModificadaMedia (6.8)0.61%—Maianscriptworld Maian Uploader13/1/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Maian Uploader 4.0 allow remote attackers to hijack the authentication of unspecified users for requests that conduct cross-site scripting (XSS) attacks via the width parameter to (1) uploader/admin/js/load_flv.js.php or (2) uploader/js/load_flv.js.php.
ModificadaMedia (5)1.8%—Maianscriptworld Maian Uploader13/1/201517/6/2026
Maian Uploader 4.0 allows remote attackers to obtain sensitive information via a request without the height parameter to load_flv.js.php, which reveals the installation path in an error message.
ModificadaAlta (7.5)2.1%—Maianscriptworld Maian Uploader13/1/201517/6/2026
SQL injection vulnerability in admin/data_files/move.php in Maian Uploader 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.9%—Maian Script World Maian Uploader13/1/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the width parameter to (1) uploader/admin/js/load_flv.js.php or (2) uploader/js/load_flv.js.php.
ModificadaMedia (4.3)6.5%💥 ExploitFrontend Uploader Project Frontend Uploader2/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI.
ModificadaMedia (4)1.5%—Avatar Uploader Project Avatar Uploader1/12/201417/6/2026
Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel.
ModificadaMedia (6.5)1.7%—Najeebmedia N-media File Uploader26/9/201417/6/2026
Unrestricted file upload vulnerability in the N-Media file uploader plugin before 3.4 for WordPress allows remote authenticated users to execute arbitrary PHP code by leveraging Author privileges to store a file.
ModificadaMedia (6.8)0.97%—Wordpress File Upload Project Wordpress File Upload12/8/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors. NOTE: some of these details are obtained from third…
ModificadaAlta (7.5)2.7%💥 ExploitMegalab THE Uploader12/8/201416/6/2026
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaMedia (4.3)9.2%💥 ExploitRoberta Bramski Uploader4/4/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.
ModificadaAlta (7.5)83%💥 ExploitOracle Retail ApplicationsApache Commons FileuploadApache Tomcat1/4/20147/10/2026
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
ModificadaMedia (6.8)4.2%—Cdsincdesign Simple Dropbox Upload Form30/9/201316/6/2026
Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/.
ModificadaMedia (4.3)9.1%💥 ExploitSwfupload Project SwfuploadTinymce Image ManagerWordpress19/7/201316/6/2026
Cross-site scripting (XSS) vulnerability in swfupload.swf in SWFUpload 2.2.0.1 and earlier, as used in WordPress before 3.3.2, TinyMCE Image Manager 1.1, and other products, allows remote attackers to inject arbitrary web script or HTML via the movieName parameter, related to the "ExternalInterface.call" function.
ModificadaMedia (4.3)3.1%—Moxiecode PluploadWordpressFedoraproject Fedora8/7/201316/6/2026
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web script or HTML via the id parameter.
ModificadaMedia (6.8)0.68%—Apache Commons Fileupload15/3/20137/10/2026
The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
ModificadaMedia (6.8)4.8%💥 ExploitWasen MOD Simplefileupload31/8/201216/6/2026
Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code by uploading a file with a (1) php5, (2) php6, or (3) double (e.g. .php.jpg) extension, then accessing it via a direct request to the file…
Orbitaley — Vulnerabilidades