Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 7.2% | 💥 Exploit | Versalsoft Http File Upload Activex Control | 9/5/2007 | 16/6/2026 | Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remote attackers to execute arbitrary code via a long argument. | |
| Modificada | Media (5) | 1.2% | — | Brettle Development Neatupload | 24/4/2007 | 16/6/2026 | Race condition in the NeatUpload ASP.NET component 1.2.11 through 1.2.16, 1.1.18 through 1.1.23, and trunk.379 through trunk.445 allows remote attackers to obtain other clients' HTTP responses via multiple simultaneous requests, which triggers multiple calls to HttpWorkerRequest.FlushResponse for the same… | |
| Modificada | Media (5) | 2.9% | 💥 Exploit | PHP Upload Tool | 6/3/2007 | 16/6/2026 | Directory traversal vulnerability in upload/bin/download.php in Upload Tool for PHP 1.0 allows remote attackers to read arbitrary files via (1) ".." sequences or (2) absolute pathnames in the filename parameter. | |
| Modificada | Alta (10) | 3.6% | 💥 Exploit | Noah Spurrier Upload Tool FOR PHP | 6/3/2007 | 16/6/2026 | Unrestricted file upload vulnerability in main_user.php in Upload Tool for PHP 1.0 allows remote attackers to upload and execute arbitrary files with executable extensions such as .php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (5) | 1.3% | — | Tuan DO Uploader | 26/1/2007 | 16/6/2026 | Tuan Do Uploader (aka php-uploader) 6 beta 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrator password hash via a direct request for userdata/user_1.txt. | |
| Modificada | Media (6.8) | 3.0% | 💥 Exploit | Upload-service | 25/1/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in upload/top.php in Upload-Service 1.0, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the maindir parameter. | |
| Modificada | Media (6.8) | 1.3% | — | Uber Uploader | 9/1/2007 | 16/6/2026 | Unrestricted file upload vulnerability in Uber Uploader 4.2 allows remote attackers to upload and execute arbitrary PHP scripts by naming them with a .phtml extension, which bypasses the .php extension check but is still executable on some server configurations. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Mxmania File Upload Manager | 29/12/2006 | 16/6/2026 | SQL injection vulnerability in detail.asp in Mxmania File Upload Manager (FUM) 1.0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Eric Guillaume Upload Download DE Fichiers | 23/12/2006 | 16/6/2026 | SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote attackers to execute arbitrary SQL commands via the id_user parameter. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Scriptsfrenzy.com E-uploader PRO | 21/12/2006 | 16/6/2026 | Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a .. (dot dot) in the language parameter, as demonstrated by uploading a .JPG file containing PHP code, then accessing the file via config.php. | |
| Modificada | Alta (7.5) | 1.4% | — | RAD Inks RAD Upload | 14/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in upload.php in Rad Upload 3.02 allows remote attackers to execute arbitrary PHP code via a URL in the save_path parameter. NOTE: CVE disputes this vulnerability because save_path is originally defined as "" before use, and the nearby instructions say "SET THE SAVE PATH by… | |
| Modificada | Alta (7.5) | 3.1% | 💥 Exploit | Uploadscript | 7/12/2006 | 16/6/2026 | Uploadscript 1.2 and earlier stores sensitive data under the web root with insufficient access control, which allows remote attackers to obtain the admin password hash via a direct request for /password.txt. | |
| Modificada | Alta (7.5) | 3.8% | 💥 Exploit | Sergey Korostel PHP Upload Center | 7/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbitrary PHP code via a URL in the footerpage parameter. | |
| Modificada | Alta (10) | 6.0% | — | Bitflux Upload Progress Meter | 7/12/2006 | 16/6/2026 | Heap-based buffer overflow in the uploadprogress_php_rfc1867_file function in uploadprogress.c in Bitflux Upload Progress Meter before 8276 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via crafted HTTP POST fileupload requests. | |
| Modificada | Alta (7.5) | 1.7% | — | Thepeak File Upload Manager | 31/10/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in Thepeak File Upload Manager 1.3 allows remote attackers to read or download arbitrary files via a base64-encoded file path containing a .. (dot dot) sequence in the file parameter. | |
| Modificada | Alta (7.5) | 1.6% | — | Scriptscenter Ezupload PRO | 31/7/2006 | 16/6/2026 | ScriptsCenter ezUpload Pro 2.2.0 allows remote attackers to perform administrative activities without authentication in (1) filter.php, which permits changing the Extensions Mode file type; (2) access.php, which permits changing the Protection Method; (3) edituser.php, which permits adding upload capabilities to user… | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Sturgeon Upload | 6/7/2006 | 16/6/2026 | SturGeoN Upload allows remote attackers to execute arbitrary PHP code by uploading a file with a .php extension, then directly accessing the file. NOTE: It is uncertain whether this is a vulnerability or a feature of the product. | |
| Modificada | Alta (7.5) | 1.6% | — | Scriptscenter Ezupload PRO | 31/5/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in EzUpload Pro 2.10 allow remote attackers to execute arbitrary PHP code via a URL in the path parameter to (1) form.php, (2) customize.php, and (3) initialize.php. | |
| Modificada | Media (5) | 1.5% | — | Sergey Korostel PHP Upload Center | 14/3/2006 | 16/6/2026 | PHP Upload Center stores password hashes under the web root with insufficient access control, which allows remote attackers to download each password hash via a direct request for the upload/users/[USERNAME] file. | |
| Modificada | Alta (7.5) | 2.0% | — | Sergey Korostel PHP Upload Center | 14/3/2006 | 16/6/2026 | Sergey Korostel PHP Upload Center allows remote attackers to execute arbitrary PHP code by uploading a file whose name ends in a .php.li extension, which can be accessed from the upload directory. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Citypost Simple PHP Upload | 31/12/2005 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in simple-upload-53.php in CityPost Simple PHP Upload 5.3 allows remote attackers to inject arbitrary web script or HTML via the message parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Scriptscenter Ezupload PRO | 17/12/2005 | 16/6/2026 | index.php in ezUpload Pro 2.2 and earlier allows remote attackers to include files via the mode parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Scriptscenter Ezupload PRO | 17/12/2005 | 16/6/2026 | SQL injection vulnerability in ezUpload Pro 2.2 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified search module parameters. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Sergey Korostel PHP Upload CenterAI | 1/12/2005 | 16/6/2026 | Directory traversal vulnerability in index.php in PHP Upload Center allows remote attackers to read arbitrary files via "../" sequences in the filename parameter. | |
| Modificada | Alta (7.5) | 11% | 💥 Exploit | Ezupload | 17/8/2005 | 16/6/2026 | Multiple PHP file include vulnerabilities in ezUpload 2.2 allow remote attackers to execute arbitrary code via the path parameter to (1) initialize.php, (2) customize.php, (3) form.php, or (4) index.php. |