Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 1.6% | — | Phpsimplicity Simplicity OF Upload | 17/8/2005 | 16/6/2026 | PHP file include vulnerability in download.php in PHPSimplicity Simplicity oF Upload before 1.3.1 allows remote attackers to include arbitrary local and remote files via the language parameter and a terminating null ("%00") characters. | |
| Modificada | Alta (7.5) | 1.6% | — | Adam Mmedici File Upload Manager | 12/6/2005 | 16/6/2026 | mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action. | |
| Modificada | Media (5) | 1.4% | — | File Upload Manager | 12/6/2005 | 16/6/2026 | File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of '~~~~~~' (six tildes), which bypasses the file extension checks. | |
| Modificada | Alta (7.5) | 1.2% | — | Jiro Upload SystemAI | 9/6/2005 | 16/6/2026 | SQL injection vulnerability in login.asp in JiRo's Upload System (JUS) 1 allows remote attackers to execute arbitrary SQL commands via the password parameter. | |
| Modificada | Media (6.4) | 1.4% | — | Raditha Dissanayake Mega Upload Progress BAR | 31/12/2004 | 16/6/2026 | upload.cgi in Mega Upload Progress Bar before 1.45 allows remote attackers to copy or overwrite arbitrary files via unspecified parameters related to names of uploaded files. | |
| Modificada | Media (6.8) | 2.1% | — | Graeme Uploader | 31/12/2003 | 16/6/2026 | Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/. | |
| Modificada | Alta (7.5) | 2.7% | — | Frederic Tyndiuk Eupload | 31/7/2002 | 16/6/2026 | eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt. | |
| Modificada | Media (6.4) | 3.2% | — | Persits Aspupload | 30/11/2001 | 16/6/2026 | Directory traversal vulnerability in AspUpload 2.1, in certain configurations, allows remote attackers to upload and read arbitrary files, and list arbitrary directories, via a .. (dot dot) in the Filename parameter in (1) UploadScript11.asp or (2) DirectoryListing.asp. | |
| Modificada | Alta (10) | 3.7% | — | Persits Aspupload | 20/7/1999 | 16/6/2026 | Buffer overflow in AspUpload.dll in Persits Software AspUpload before 1.4.0.2 allows remote attackers to cause a denial of service, and possibly execute arbitrary commands, via a long argument in the HTTP request. |