Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
99 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.39% | — | Avif SVG UploaderAI | 1/10/2024 | 17/6/2026 | The AVIF & SVG Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages… | |
| Modificada | Media (6.1) | 0.40% | — | Xiebruce Picuploader | 26/8/2024 | 5/7/2026 | A cross-site scripting (XSS) vulnerability in the component /auth/AzureRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter. | |
| Modificada | Media (6.1) | 0.29% | — | Xiebruce Picuploader | 26/8/2024 | 5/7/2026 | A cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter. | |
| Analizada | Alta (8.7) | 0.37% | — | Avtecinc Outpost Uploader UtilityAvtecinc Outpost 0810 Firmware | 22/8/2024 | 17/6/2026 | Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information. | |
| Analizada | Alta (8.7) | 0.39% | — | Avtecinc Outpost Uploader UtilityAvtecinc Outpost 0810 Firmware | 22/8/2024 | 17/6/2026 | Avtec Outpost stores sensitive information in an insecure location without proper access controls in place. | |
| Modificada | Media (4.3) | 0.45% | — | Wbcomdesigns Custom Font Uploader | 6/6/2024 | 17/6/2026 | The Wbcom Designs – Custom Font Uploader plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'cfu_delete_customfont' function in all versions up to, and including, 2.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… | |
| Aplazada | Media (4.3) | 0.17% | — | Uploadcare File UploaderAIUploadcare Adaptive DeliveryAI | 1/6/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uploadcare.This issue affects Uploadcare File Uploader and Adaptive Delivery (beta): from n/a through 3.0.11. | |
| Aplazada | Crítica (10) | 0.81% | — | Mainwp File Uploader ExtensionAI | 26/3/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in MainWP MainWP File Uploader Extension.This issue affects MainWP File Uploader Extension: from n/a through 4.1. | |
| Modificada | Media (5.4) | 0.45% | — | Codedropz Drag AND Drop Multiple File Uploader | 16/10/2023 | 17/6/2026 | The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts. | |
| Modificada | Alta (8.3) | 0.49% | — | Troplo Privateuploader | 14/8/2023 | 17/6/2026 | PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did not correctly verify whether the user was an administrator (High Level) or moderator (Low Level) causing the request to continue processing. The response would be a 403… | |
| Modificada | Media (6.1) | 0.56% | — | Picuploader Project Picuploader | 7/10/2022 | 17/6/2026 | PicUploader v2.6.3 was discovered to contain cross-site scripting (XSS) vulnerability via the setStorageParams function in SettingController.php. | |
| Modificada | Crítica (9.8) | 1.4% | — | Creativedream File Uploader Project Creativedream File Uploader | 3/10/2022 | 17/6/2026 | Arbitrary file upload vulnerability in php uploader | |
| Modificada | Media (6.1) | 0.45% | — | Picuploader Project Picuploader | 30/8/2022 | 17/6/2026 | PicUploader v2.6.3 was discovered to contain a cross-site scripting (XSS) vulnerability via the component /master/index.php. | |
| Modificada | Media (4.8) | 0.61% | — | Thinkific Uploader | 8/8/2022 | 17/6/2026 | The Thinkific Uploader WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks against other administrators. | |
| Modificada | Crítica (9.8) | 3.1% | — | S3-uploader Project S3-uploader | 2/6/2022 | 17/6/2026 | OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function. | |
| Modificada | Alta (8.8) | 16% | — | Advanced Uploader Project Advanced Uploader | 16/5/2022 | 17/6/2026 | The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE | |
| Modificada | Media (4.3) | 0.75% | — | Jenkins Incapptic Connect Uploader | 15/3/2022 | 17/6/2026 | Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system. | |
| Modificada | Media (6.1) | 0.95% | — | Phpuploader Project Phpuploader | 24/2/2022 | 17/6/2026 | Cross-site scripting vulnerability in phpUploader v1.2 and earlier allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.7% | — | Phpuploader Project Phpuploader | 24/2/2022 | 17/6/2026 | SQL injection vulnerability in the phpUploader v1.2 and earlier allows a remote unauthenticated attacker to obtain the information in the database via unspecified vectors. | |
| Modificada | Media (6.1) | 26% | — | Frontend Uploader Project Frontend Uploader | 11/10/2021 | 17/6/2026 | The Frontend Uploader WordPress plugin through 1.3.2 does not prevent HTML files from being uploaded via its form, allowing unauthenticated user to upload a malicious HTML file containing JavaScript for example, which will be triggered when someone access the file directly | |
| Modificada | Media (5.3) | 1.0% | — | TAD Uploader Project TAD Uploader | 8/10/2021 | 17/6/2026 | Tad Uploader edit book list function is vulnerable to authorization bypass, thus remote attackers can use the function to amend the folder names in the book list without logging in. | |
| Modificada | Media (6.1) | 0.63% | — | TAD Uploader Project TAD Uploader | 8/10/2021 | 17/6/2026 | The new add subject parameter of Tad Uploader view book list function fails to filter special characters. Unauthenticated attackers can remotely inject JavaScript syntax and execute stored XSS attacks. | |
| Modificada | Alta (8.8) | 3.9% | — | 1UP Oneupuploaderbundle | 5/2/2020 | 17/6/2026 | Multiple relative path traversal vulnerabilities in the oneup/uploader-bundle before 1.9.3 and 2.1.5 allow remote attackers to upload, copy, and modify files on the filesystem (potentially leading to arbitrary code execution) via the (1) filename parameter to BlueimpController.php; the (2) dzchunkindex, (3) dzuuid, or… | |
| Modificada | Alta (8.8) | 1.9% | — | Codecov Nodejs Uploader | 25/1/2020 | 17/6/2026 | Codecov npm module before 3.6.2 allows remote attackers to execute arbitrary commands via the "gcov-args" argument. | |
| Modificada | Crítica (9.8) | 1.9% | — | Maleck Image Uploader AND Browser FOR Ckeditor | 2/12/2019 | 17/6/2026 | Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code. |