Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)10%💥 ExploitPippin Williamson Font Uploader27/6/201216/6/2026
Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a .php.ttf extension, then accessing it via a direct request to the file in font-uploader/fonts.
ModificadaMedia (5)3.4%—Moxiecode PluploadWordpress21/4/201216/6/2026
Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content.
ModificadaAlta (7.5)25%💥 ExploitAlanft Relocate-upload24/2/201216/6/2026
PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.
ModificadaMedia (6.8)0.59%—Skyarc AutotaggingSkyarc DuplicateentrySkyarc MailpackSkyarc Mtcms+13/11/201116/6/2026
Cross-site request forgery (CSRF) vulnerability in SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, allows remote attackers to hijack the authentication of arbitrary users for…
ModificadaMedia (5.5)1.1%—Skyarc AutotaggingSkyarc DuplicateentrySkyarc MailpackSkyarc Mtcms+13/11/201116/6/2026
SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, uses weak permissions, which allows remote authenticated users to modify files and settings via unspecified vectors.
ModificadaAlta (7.5)1.4%—Jerome Schneider Ameos Dragndropupload4/10/201116/6/2026
Unspecified vulnerability in the Drag Drop Mass Upload (ameos_dragndropupload) extension 2.0.2 and earlier for TYPO3 allows remote attackers to upload arbitrary files via unknown vectors.
ModificadaMedia (6.8)4.2%💥 ExploitPhpsimplicity Simplicity OF Upload27/4/201016/6/2026
Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif.
ModificadaMedia (6.8)3.4%💥 ExploitElement-it Ultimate Uploader27/4/201016/6/2026
Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/.
ModificadaMedia (5)2.7%💥 ExploitAndy Stedemos THE Uploader27/4/201016/6/2026
Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
ModificadaBaja (3.5)1.0%—Ilya Ivanchenko Itweak Upload23/2/201016/6/2026
Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML via the file name of an uploaded file.
ModificadaMedia (6.8)3.3%💥 ExploitPhpf1 Max's Image Uploader26/1/201016/6/2026
Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it…
ModificadaAlta (9.3)4.8%—Larts Uploader Activex Control3/12/200916/6/2026
Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreateURL, (5) ErrorURL, or (6) httpsinglehost property value.
ModificadaAlta (9.3)42%💥 ExploitPersits XuploadHP Loadrunner13/10/200916/6/2026
Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \.. (backwards slash dot dot) sequences in the third argument to the MakeHttpRequest method.
ModificadaAlta (7.5)2.2%💥 ExploitXoops Uploader8/9/200916/6/2026
Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a downloadfile action to index.php.
ModificadaAlta (7.5)2.6%💥 ExploitPowerupload14/8/200916/6/2026
PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname cookie.
ModificadaMedia (5)6.1%💥 ExploitPc4arb PC4 Uploader23/6/200916/6/2026
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the file parameter.
ModificadaAlta (9.3)4.1%—Ebay Enhanced Picture Uploader Activex Control9/6/200916/6/2026
eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property.
ModificadaAlta (7.5)4.3%💥 ExploitNewearthpt Imgupload4/6/200916/6/2026
Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader) 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a modified content type, then accessing this file via a direct request, as demonstrated by…
ModificadaAlta (7.5)1.3%💥 ExploitPc4arb PC4 Uploader20/5/200916/6/2026
code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via the "UNIunionON" string, which is collapsed into "UNION" by the filter_sql…
ModificadaAlta (8.8)1.7%—Versalsoft Http File Upload Activex Control7/4/200916/6/2026
Insecure method vulnerability in the Versalsoft HTTP Image Uploader ActiveX control (UUploaderSvrD.dll 6.0.0.35) allows remote attackers to delete arbitrary files via the RemoveFileOrDir method.
ModificadaMedia (4.3)1.5%💥 ExploitCelerondude Uploader4/3/200916/6/2026
Cross-site scripting (XSS) vulnerability in account.php in Celerondude Uploader 6.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information.
ModificadaAlta (8.5)2.1%—Phpg Upload20/2/200916/6/2026
Unrestricted file upload vulnerability in form_upload.php in PHPG Upload 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. NOTE: the provenance of this information is unknown; the details are obtained…
ModificadaAlta (7.5)2.0%💥 ExploitFascript Faupload30/12/200816/6/2026
SQL injection vulnerability in download.php in Farsi Script Faupload allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaAlta (9.3)33%💥 ExploitFacebook Photouploader24/12/200816/6/2026
Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary code via a long FileMask property value.
ModificadaMedia (6.4)1.8%💥 ExploitGHH Google Hack Honeypot File Upload Manager29/11/200816/6/2026
Google Hack Honeypot (GHH) File Upload Manager 1.3 allows remote attackers to delete uploaded files via unknown vectors related to the delall action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. CVE analysis suggests that the most…
Orbitaley — Vulnerabilidades