Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

99 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.39%—Avif SVG UploaderAI1/10/202417/6/2026
The AVIF & SVG Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages…
ModificadaMedia (6.1)0.40%—Xiebruce Picuploader26/8/20245/7/2026
A cross-site scripting (XSS) vulnerability in the component /auth/AzureRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter.
ModificadaMedia (6.1)0.29%—Xiebruce Picuploader26/8/20245/7/2026
A cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter.
AnalizadaAlta (8.7)0.37%—Avtecinc Outpost Uploader UtilityAvtecinc Outpost 0810 Firmware22/8/202417/6/2026
Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information.
AnalizadaAlta (8.7)0.39%—Avtecinc Outpost Uploader UtilityAvtecinc Outpost 0810 Firmware22/8/202417/6/2026
Avtec Outpost stores sensitive information in an insecure location without proper access controls in place.
ModificadaMedia (4.3)0.45%—Wbcomdesigns Custom Font Uploader6/6/202417/6/2026
The Wbcom Designs – Custom Font Uploader plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'cfu_delete_customfont' function in all versions up to, and including, 2.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to…
AplazadaMedia (4.3)0.17%—Uploadcare File UploaderAIUploadcare Adaptive DeliveryAI1/6/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uploadcare.This issue affects Uploadcare File Uploader and Adaptive Delivery (beta): from n/a through 3.0.11.
AplazadaCrítica (10)0.81%—Mainwp File Uploader ExtensionAI26/3/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in MainWP MainWP File Uploader Extension.This issue affects MainWP File Uploader Extension: from n/a through 4.1.
ModificadaMedia (5.4)0.45%—Codedropz Drag AND Drop Multiple File Uploader16/10/202317/6/2026
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.
ModificadaAlta (8.3)0.49%—Troplo Privateuploader14/8/202317/6/2026
PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did not correctly verify whether the user was an administrator (High Level) or moderator (Low Level) causing the request to continue processing. The response would be a 403…
ModificadaMedia (6.1)0.56%—Picuploader Project Picuploader7/10/202217/6/2026
PicUploader v2.6.3 was discovered to contain cross-site scripting (XSS) vulnerability via the setStorageParams function in SettingController.php.
ModificadaCrítica (9.8)1.4%—Creativedream File Uploader Project Creativedream File Uploader3/10/202217/6/2026
Arbitrary file upload vulnerability in php uploader
ModificadaMedia (6.1)0.45%—Picuploader Project Picuploader30/8/202217/6/2026
PicUploader v2.6.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /master/index.php.
ModificadaMedia (4.8)0.61%—Thinkific Uploader8/8/202217/6/2026
The Thinkific Uploader WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks against other administrators.
ModificadaCrítica (9.8)3.1%—S3-uploader Project S3-uploader2/6/202217/6/2026
OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function.
ModificadaAlta (8.8)16%—Advanced Uploader Project Advanced Uploader16/5/202217/6/2026
The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE
ModificadaMedia (4.3)0.75%—Jenkins Incapptic Connect Uploader15/3/202217/6/2026
Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system.
ModificadaMedia (6.1)0.95%—Phpuploader Project Phpuploader24/2/202217/6/2026
Cross-site scripting vulnerability in phpUploader v1.2 and earlier allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors.
ModificadaAlta (7.5)1.7%—Phpuploader Project Phpuploader24/2/202217/6/2026
SQL injection vulnerability in the phpUploader v1.2 and earlier allows a remote unauthenticated attacker to obtain the information in the database via unspecified vectors.
ModificadaMedia (6.1)26%—Frontend Uploader Project Frontend Uploader11/10/202117/6/2026
The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly
ModificadaMedia (5.3)1.0%—TAD Uploader Project TAD Uploader8/10/202117/6/2026
Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in.
ModificadaMedia (6.1)0.63%—TAD Uploader Project TAD Uploader8/10/202117/6/2026
The new add subject parameter of Tad Uploader view book list function fails to filter special characters. Unauthenticated attackers can remotely inject JavaScript syntax and execute stored XSS attacks.
ModificadaAlta (8.8)3.9%—1UP Oneupuploaderbundle5/2/202017/6/2026
Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to BlueimpController.php; the (2) dzchunkindex, (3) dzuuid, or…
ModificadaAlta (8.8)1.9%—Codecov Nodejs Uploader25/1/202017/6/2026
Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument.
ModificadaCrítica (9.8)1.9%—Maleck Image Uploader AND Browser FOR Ckeditor2/12/201917/6/2026
Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.