Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Scriptsfrenzy E-uploader PRO | 14/11/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in E-Uploader Pro 1.0 (aka Uploader PRO), when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) img.php, (b) file.php, (c) mail.php, (d) thumb.php, (e) zip.php, and (f) zipit.php, and (2) the view parameter to… | |
| Modificada | Media (5.5) | 1.4% | — | DrupalDrupal Upload Module | 27/8/2008 | 16/6/2026 | The Upload module in Drupal 6.x before 6.4 allows remote authenticated users to edit nodes, delete files, and download unauthorized attachments via unspecified vectors. | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Maian Script World Maian Uploader | 25/7/2008 | 16/6/2026 | admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary uploader_cookie cookie. | |
| Modificada | Alta (7.5) | 2.0% | 💥 Exploit | Wordpress Upload File Plugin | 29/5/2008 | 16/6/2026 | SQL injection vulnerability in wp-uploadfile.php in the Upload File plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the f_id parameter. | |
| Modificada | Media (6.8) | 3.1% | — | Photostockplus Uploader Tool | 20/5/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the PhotoStockPlus Uploader Tool ActiveX control (PSPUploader.ocx) allow remote attackers to execute arbitrary code via unspecified initialization parameters. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Maianscriptworld Maian Uploader | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to upload/admin/index.php in a search action, the (2) msg_charset and (3) msg_header9 parameters to admin/inc/header.php, and the (4) keywords parameter… | |
| Modificada | Alta (9.3) | 4.0% | — | Aurigma Image Uploader Activex ControlPiczo Imageuploader4 | 25/3/2008 | 16/6/2026 | Buffer overflow in a certain Aurigma ActiveX control in ImageUploader4.ocx 4.1.36.0, as used with Piczo (aka Pizco) and possibly other online services, allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long Action property, a different CLSID than CVE-2008-0659. | |
| Modificada | Alta (10) | 16% | 💥 Exploit | Sony Axruploadserver Activex ControlSony Imagestation | 13/2/2008 | 16/6/2026 | Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyISUpload.cab 1.0.0.38 for Sony ImageStation allows remote attackers to execute arbitrary code via a long argument to the SetLogging method. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (10) | 56% | 💥 Exploit | Aurigma Image Uploader Activex ControlMyspaceuploader | 8/2/2008 | 16/6/2026 | Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property. | |
| Modificada | Alta (9.3) | 38% | 💥 Exploit | Aurigma Image Uploader Activex ControlFacebookFacebook Photouploader | 8/2/2008 | 16/6/2026 | Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties. | |
| Modificada | Media (6.4) | 2.5% | — | Drupal Comment Upload Module | 5/2/2008 | 16/6/2026 | The Comment Upload 4.7.x before 4.7.x-0.1 and 5.x before 5.x-0.1 module for Drupal does not properly use functions in the upload module, which allows remote attackers to bypass upload validation, and upload arbitrary files and possibly execute arbitrary code, via unspecified vectors. | |
| Modificada | Media (6.8) | 30% | 💥 Exploit | Persits Xupload | 30/1/2008 | 16/6/2026 | Stack-based buffer overflow in the Persits.XUpload.2 ActiveX control in XUpload.ocx 3.0.0.4 and earlier in Persits XUpload 3.0 allows remote attackers to execute arbitrary code via a long argument to the AddFile method. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | Lycos Fileuploader.dll | 25/1/2008 | 16/6/2026 | Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUploader Module allows remote attackers to execute arbitrary code via a long HandwriterFilename property value. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.2% | — | PHP F1 Maxs File Uploader | 22/1/2008 | 16/6/2026 | Unrestricted file upload vulnerability in PHP F1 Max's File Uploader allows remote attackers to upload and execute arbitrary PHP files. | |
| Modificada | Alta (10) | 3.5% | 💥 Exploit | Uploadscript UploadimageUploadscript | 12/1/2008 | 16/6/2026 | admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Uploadscript UploadimageUploadscript | 12/1/2008 | 16/6/2026 | admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which allows remote attackers to gain administrator privileges via the pass parameter in a nopass (Set Password) action. | |
| Modificada | Media (5) | 1.2% | — | Uber Uploader | 8/1/2008 | 16/6/2026 | The default configuration of Uber Uploader (UU) 5.3.6 and earlier does not block uploads of (1) .html, (2) .asp, and other possibly dangerous extensions, which allows remote attackers to use these extensions in uploads via (a) uu_file_upload.php, related to uu_file_upload.js and (b) uber_uploader_file.php, related to… | |
| Modificada | Alta (9.3) | 37% | 💥 Exploit | Groove Virtual OfficeHP LoadrunnerPersits Xupload | 27/12/2007 | 16/6/2026 | Buffer overflow in the XUpload.ocx ActiveX control in Persits Software XUpload 2.1.0.1, and probably other versions before 3.0, as used by HP Mercury LoadRunner and Groove Virtual Office, allows remote attackers to execute arbitrary code via a long argument to the AddFolder function. | |
| Modificada | Media (6.8) | 38% | 💥 Exploit | JoomlaMichael Dempfle Joomla Flash Uploader | 14/10/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Michael Dempfle Joomla Flash Uploader (com_jfu or com_joomla_flash_uploader) 2.5.1 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) install.joomla_flash_uploader.php and (2)… | |
| Modificada | Alta (7.8) | 1.6% | — | Javaatwork Myftpuploader ModuleScottmanktelow Stride | 12/10/2007 | 16/6/2026 | include/imageupload.js in the MyFTPUploader module in Stride 1.0 contains sensitive information including FTP login credentials, which might allow remote attackers to gain unauthorized access to the FTP server being used by the module by viewing the source code. | |
| Modificada | Alta (9.3) | 6.7% | — | Photochannel PNI Digital Media Upload Plugin Activex Control | 18/9/2007 | 16/6/2026 | Multiple stack-based buffer overflows in the PhotoChannel Networks PNI Digital Media Photo Upload Plugin ActiveX control before 2.0.0.10, as used by multiple retailers, allow remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Phphq Phuploader | 25/8/2007 | 16/6/2026 | Unrestricted file upload vulnerability in phUploader.php in phphq.Net phUploader 1.2 allows remote attackers to upload and execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 1.9% | — | American Financing Email Image Upload | 23/8/2007 | 16/6/2026 | Unrestricted file upload vulnerability in output.php in American Financing eMail Image Upload 4.1 allows remote attackers to upload and execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 3.1% | 💥 Exploit | Mapos Scripts File Uploader | 14/8/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php or (2) datei.php. | |
| Modificada | Media (6.8) | 2.2% | — | Mapos Scripts Bilder Uploader | 14/8/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Bilder Uploader 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) gruppen.php, (2) bild.php, (3) feed.php, (4) mitglieder.php, (5) online.php, (6) profil.php, and possibly other unspecified PHP scripts. |