Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 10% | 💥 Exploit | Pippin Williamson Font Uploader | 27/6/2012 | 16/6/2026 | Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a .php.ttf extension, then accessing it via a direct request to the file in font-uploader/fonts. | |
| Modificada | Media (5) | 3.4% | — | Moxiecode PluploadWordpress | 21/4/2012 | 16/6/2026 | Plupload before 1.5.4, as used in wp-includes/js/plupload/ in WordPress before 3.3.2 and other products, enables scripting regardless of the domain from which the SWF content was loaded, which allows remote attackers to bypass the Same Origin Policy via crafted content. | |
| Modificada | Alta (7.5) | 25% | 💥 Exploit | Alanft Relocate-upload | 24/2/2012 | 16/6/2026 | PHP remote file inclusion vulnerability in relocate-upload.php in Relocate Upload plugin before 0.20 for WordPress allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter. | |
| Modificada | Media (6.8) | 0.59% | — | Skyarc AutotaggingSkyarc DuplicateentrySkyarc MailpackSkyarc Mtcms+1 | 3/11/2011 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, allows remote attackers to hijack the authentication of arbitrary users for… | |
| Modificada | Media (5.5) | 1.1% | — | Skyarc AutotaggingSkyarc DuplicateentrySkyarc MailpackSkyarc Mtcms+1 | 3/11/2011 | 16/6/2026 | SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, uses weak permissions, which allows remote authenticated users to modify files and settings via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.4% | — | Jerome Schneider Ameos Dragndropupload | 4/10/2011 | 16/6/2026 | Unspecified vulnerability in the Drag Drop Mass Upload (ameos_dragndropupload) extension 2.0.2 and earlier for TYPO3 allows remote attackers to upload arbitrary files via unknown vectors. | |
| Modificada | Media (6.8) | 4.2% | 💥 Exploit | Phpsimplicity Simplicity OF Upload | 27/4/2010 | 16/6/2026 | Unrestricted file upload vulnerability in upload.php in PHPSimplicity Simplicity oF Upload 1.3.2 allows remote attackers to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. | |
| Modificada | Media (6.8) | 3.4% | 💥 Exploit | Element-it Ultimate Uploader | 27/4/2010 | 16/6/2026 | Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Andy Stedemos THE Uploader | 27/4/2010 | 16/6/2026 | Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter. | |
| Modificada | Baja (3.5) | 1.0% | — | Ilya Ivanchenko Itweak Upload | 23/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML via the file name of an uploaded file. | |
| Modificada | Media (6.8) | 3.3% | 💥 Exploit | Phpf1 Max's Image Uploader | 26/1/2010 | 16/6/2026 | Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it… | |
| Modificada | Alta (9.3) | 4.8% | — | Larts Uploader Activex Control | 3/12/2009 | 16/6/2026 | Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreateURL, (5) ErrorURL, or (6) httpsinglehost property value. | |
| Modificada | Alta (9.3) | 42% | 💥 Exploit | Persits XuploadHP Loadrunner | 13/10/2009 | 16/6/2026 | Directory traversal vulnerability in the Persits.XUpload.2 ActiveX control (XUpload.ocx) in HP LoadRunner 9.5 allows remote attackers to create arbitrary files via \.. (backwards slash dot dot) sequences in the third argument to the MakeHttpRequest method. | |
| Modificada | Alta (7.5) | 2.2% | 💥 Exploit | Xoops Uploader | 8/9/2009 | 16/6/2026 | Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a downloadfile action to index.php. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Powerupload | 14/8/2009 | 16/6/2026 | PowerUpload 2.4 allows remote attackers to bypass authentication and gain administrative access via a MIME encoded value of admin for the myadminname cookie. | |
| Modificada | Media (5) | 6.1% | 💥 Exploit | Pc4arb PC4 Uploader | 23/6/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the file parameter. | |
| Modificada | Alta (9.3) | 4.1% | — | Ebay Enhanced Picture Uploader Activex Control | 9/6/2009 | 16/6/2026 | eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property. | |
| Modificada | Alta (7.5) | 4.3% | 💥 Exploit | Newearthpt Imgupload | 4/6/2009 | 16/6/2026 | Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader) 1.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension and a modified content type, then accessing this file via a direct request, as demonstrated by… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Pc4arb PC4 Uploader | 20/5/2009 | 16/6/2026 | code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via the "UNIunionON" string, which is collapsed into "UNION" by the filter_sql… | |
| Modificada | Alta (8.8) | 1.7% | — | Versalsoft Http File Upload Activex Control | 7/4/2009 | 16/6/2026 | Insecure method vulnerability in the Versalsoft HTTP Image Uploader ActiveX control (UUploaderSvrD.dll 6.0.0.35) allows remote attackers to delete arbitrary files via the RemoveFileOrDir method. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Celerondude Uploader | 4/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in account.php in Celerondude Uploader 6.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (8.5) | 2.1% | — | Phpg Upload | 20/2/2009 | 16/6/2026 | Unrestricted file upload vulnerability in form_upload.php in PHPG Upload 1.0 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file. NOTE: the provenance of this information is unknown; the details are obtained… | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Fascript Faupload | 30/12/2008 | 16/6/2026 | SQL injection vulnerability in download.php in Farsi Script Faupload allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Alta (9.3) | 33% | 💥 Exploit | Facebook Photouploader | 24/12/2008 | 16/6/2026 | Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary code via a long FileMask property value. | |
| Modificada | Media (6.4) | 1.8% | 💥 Exploit | GHH Google Hack Honeypot File Upload Manager | 29/11/2008 | 16/6/2026 | Google Hack Honeypot (GHH) File Upload Manager 1.3 allows remote attackers to delete uploaded files via unknown vectors related to the delall action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. CVE analysis suggests that the most… |