Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
33 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.46% | — | Wpexperts User Avatar-reloaded | 16/10/2023 | 17/6/2026 | The User Avatar WordPress plugin before 1.2.2 does not properly sanitize and escape certain of its shortcodes attributes, which could allow relatively low-privileged users like contributors to conduct Stored XSS attacks. | |
| Modificada | Media (6.5) | 0.57% | — | Onedesigns ONE User Avatar | 18/10/2021 | 17/6/2026 | The One User Avatar WordPress plugin before 2.3.7 does not check for CSRF when updating the Avatar in page where the [avatar_upload] shortcode is embed. As a result, attackers could make logged in user change their avatar via a CSRF attack | |
| Modificada | Media (5.4) | 0.65% | — | Onedesigns ONE User Avatar | 18/10/2021 | 17/6/2026 | The One User Avatar WordPress plugin before 2.3.7 does not escape the link and target attributes of its shortcode, allowing users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks | |
| Modificada | Media (4.3) | 0.69% | — | Jenkins Avatar | 7/8/2019 | 17/6/2026 | A missing permission check in Jenkins Avatar Plugin 1.2 and earlier allows attackers with Overall/Read access to change the avatar of any user of Jenkins. | |
| Modificada | Alta (7.5) | 55% | — | Drupal Avatar Uploader | 4/4/2018 | 17/6/2026 | Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. | |
| Modificada | Media (6.5) | 1.8% | — | Avatar Uploader Project Avatar Uploader | 26/2/2015 | 17/6/2026 | Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors. | |
| Modificada | Media (4) | 1.5% | — | Avatar Uploader Project Avatar Uploader | 1/12/2014 | 17/6/2026 | Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel. | |
| Modificada | Media (5) | 1.6% | — | Snitz Communications Avatar MOD | 22/5/2006 | 16/6/2026 | avatar_upload.asp in Avatar MOD 1.3 for Snitz Forums 3.4, and possibly other versions, allows remote attackers to bypass file type checks and upload arbitrary files via a null byte in the file name, as discovered by the Codescan product. |