Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)7.2%💥 ExploitVersalsoft Http File Upload Activex Control9/5/200716/6/2026
Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remote attackers to execute arbitrary code via a long argument.
ModificadaMedia (5)1.2%—Brettle Development Neatupload24/4/200716/6/2026
Race condition in the NeatUpload ASP.NET component 1.2.11 through 1.2.16, 1.1.18 through 1.1.23, and trunk.379 through trunk.445 allows remote attackers to obtain other clients' HTTP responses via multiple simultaneous requests, which triggers multiple calls to HttpWorkerRequest.FlushResponse for the same…
ModificadaMedia (5)2.9%💥 ExploitPHP Upload Tool6/3/200716/6/2026
Directory traversal vulnerability in upload/bin/download.php in Upload Tool for PHP 1.0 allows remote attackers to read arbitrary files via (1) ".." sequences or (2) absolute pathnames in the filename parameter.
ModificadaAlta (10)3.6%💥 ExploitNoah Spurrier Upload Tool FOR PHP6/3/200716/6/2026
Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote attackers to upload and execute arbitrary files with executable extensions such as .php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.
ModificadaMedia (5)1.3%—Tuan DO Uploader26/1/200716/6/2026
Tuan Do Uploader (aka php-uploader) 6 beta 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrator password hash via a direct request for userdata/user_1.txt.
ModificadaMedia (6.8)3.0%💥 ExploitUpload-service25/1/200716/6/2026
PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the maindir parameter.
ModificadaMedia (6.8)1.3%—Uber Uploader9/1/200716/6/2026
Unrestricted file upload vulnerability in Uber Uploader 4.2 allows remote attackers to upload and execute arbitrary PHP scripts by naming them with a .phtml extension, which bypasses the .php extension check but is still executable on some server configurations.
ModificadaAlta (7.5)1.2%💥 ExploitMxmania File Upload Manager29/12/200616/6/2026
SQL injection vulnerability in detail.asp in Mxmania File Upload Manager (FUM) 1.0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
ModificadaAlta (7.5)1.1%💥 ExploitEric Guillaume Upload Download DE Fichiers23/12/200616/6/2026
SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote attackers to execute arbitrary SQL commands via the id_user parameter.
ModificadaAlta (7.5)2.5%💥 ExploitScriptsfrenzy.com E-uploader PRO21/12/200616/6/2026
Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a .. (dot dot) in the language parameter, as demonstrated by uploading a .JPG file containing PHP code, then accessing the file via config.php.
ModificadaAlta (7.5)1.4%—RAD Inks RAD Upload14/12/200616/6/2026
PHP remote file inclusion vulnerability in upload.php in Rad Upload 3.02 allows remote attackers to execute arbitrary PHP code via a URL in the save_path parameter. NOTE: CVE disputes this vulnerability because save_path is originally defined as "" before use, and the nearby instructions say "SET THE SAVE PATH by…
ModificadaAlta (7.5)3.1%💥 ExploitUploadscript7/12/200616/6/2026
Uploadscript 1.2 and earlier stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain the admin password hash via a direct request for /password.txt.
ModificadaAlta (7.5)3.8%💥 ExploitSergey Korostel PHP Upload Center7/12/200616/6/2026
PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the footerpage parameter.
ModificadaAlta (10)6.0%—Bitflux Upload Progress Meter7/12/200616/6/2026
Heap-based buffer overflow in the uploadprogress_php_rfc1867_file function in uploadprogress.c in Bitflux Upload Progress Meter before 8276 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted HTTP POST fileupload requests.
ModificadaAlta (7.5)1.7%—Thepeak File Upload Manager31/10/200616/6/2026
Directory traversal vulnerability in index.php in Thepeak File Upload Manager 1.3 allows remote attackers to read or download arbitrary files via a base64-encoded file path containing a .. (dot dot) sequence in the file parameter.
ModificadaAlta (7.5)1.6%—Scriptscenter Ezupload PRO31/7/200616/6/2026
ScriptsCenter ezUpload Pro 2.2.0 allows remote attackers to perform administrative activities without authentication in (1) filter.php, which permits changing the Extensions Mode file type; (2) access.php, which permits changing the Protection Method; (3) edituser.php, which permits adding upload capabilities to user…
ModificadaAlta (7.5)2.6%💥 ExploitSturgeon Upload6/7/200616/6/2026
SturGeoN Upload allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension, then directly accessing the file. NOTE: It is uncertain whether this is a vulnerability or a feature of the product.
ModificadaAlta (7.5)1.6%—Scriptscenter Ezupload PRO31/5/200616/6/2026
Multiple PHP remote file inclusion vulnerabilities in EzUpload Pro 2.10 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) form.php, (2) customize.php, and (3) initialize.php.
ModificadaMedia (5)1.5%—Sergey Korostel PHP Upload Center14/3/200616/6/2026
PHP Upload Center stores password hashes under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for the upload/users/[USERNAME] file.
ModificadaAlta (7.5)2.0%—Sergey Korostel PHP Upload Center14/3/200616/6/2026
Sergey Korostel PHP Upload Center allows remote attackers to execute arbitrary PHP code by uploading a file whose name ends in a .php.li extension, which can be accessed from the upload directory.
ModificadaMedia (4.3)1.7%💥 ExploitCitypost Simple PHP Upload31/12/200516/6/2026
Cross-site scripting (XSS) vulnerability in simple-upload-53.php in CityPost Simple PHP Upload 5.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
ModificadaAlta (7.5)1.5%—Scriptscenter Ezupload PRO17/12/200516/6/2026
index.php in ezUpload Pro 2.2 and earlier allows remote attackers to include files via the mode parameter.
ModificadaAlta (7.5)1.3%—Scriptscenter Ezupload PRO17/12/200516/6/2026
SQL injection vulnerability in ezUpload Pro 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters.
ModificadaMedia (5)3.1%💥 ExploitSergey Korostel PHP Upload CenterAI1/12/200516/6/2026
Directory traversal vulnerability in index.php in PHP Upload Center allows remote attackers to read arbitrary files via "../" sequences in the filename parameter.
ModificadaAlta (7.5)11%💥 ExploitEzupload17/8/200516/6/2026
Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php.
Orbitaley — Vulnerabilidades