Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

99 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.3%—Webcraftic Simple 301 Redirects-addon-bulk Uploader29/8/201917/6/2026
The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file.
ModificadaMedia (6.5)1.5%—Jenkins Fortify ON Demand Uploader28/3/201917/6/2026
A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server.
ModificadaMedia (6.5)1.3%—Jenkins Fortify ON Demand Uploader28/3/201917/6/2026
A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers to initiate a connection to an attacker-specified server.
ModificadaCrítica (9.8)1.8%—Fineuploader Php-traditional-server19/11/201817/6/2026
Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2
ModificadaCrítica (9.8)3.5%—Tinywebgallery Wordpress Flash Uploader25/4/201817/6/2026
The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path.
ModificadaAlta (7.5)55%—Drupal Avatar Uploader4/4/201817/6/2026
Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.
ModificadaAlta (7.8)0.45%—Synology Photo Station Uploader23/8/201717/6/2026
Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current…
ModificadaMedia (6.5)1.8%—Avatar Uploader Project Avatar Uploader26/2/201517/6/2026
Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.
ModificadaMedia (6.8)0.61%—Maianscriptworld Maian Uploader13/1/201517/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Maian Uploader 4.0 allow remote attackers to hijack the authentication of unspecified users for requests that conduct cross-site scripting (XSS) attacks via the width parameter to (1) uploader/admin/js/load_flv.js.php or (2) uploader/js/load_flv.js.php.
ModificadaMedia (5)1.8%—Maianscriptworld Maian Uploader13/1/201517/6/2026
Maian Uploader 4.0 allows remote attackers to obtain sensitive information via a request without the height parameter to load_flv.js.php, which reveals the installation path in an error message.
ModificadaAlta (7.5)2.1%—Maianscriptworld Maian Uploader13/1/201517/6/2026
SQL injection vulnerability in admin/data_files/move.php in Maian Uploader 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.9%—Maian Script World Maian Uploader13/1/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the width parameter to (1) uploader/admin/js/load_flv.js.php or (2) uploader/js/load_flv.js.php.
ModificadaMedia (4.3)6.5%—Frontend Uploader Project Frontend Uploader2/1/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI.
ModificadaMedia (4)1.5%—Avatar Uploader Project Avatar Uploader1/12/201417/6/2026
Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel.
ModificadaMedia (6.5)1.7%—Najeebmedia N-media File Uploader26/9/201417/6/2026
Unrestricted file upload vulnerability in the N-Media file uploader plugin before 3.4 for WordPress allows remote authenticated users to execute arbitrary PHP code by leveraging Author privileges to store a file.
ModificadaAlta (7.5)2.7%—Megalab THE Uploader12/8/201416/6/2026
SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter.
ModificadaMedia (4.3)9.2%—Roberta Bramski Uploader4/4/201416/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter.
ModificadaAlta (7.5)10%—Pippin Williamson Font Uploader27/6/201216/6/2026
Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a .php.ttf extension, then accessing it via a direct request to the file in font-uploader/fonts.
ModificadaMedia (6.8)0.59%—Skyarc AutotaggingSkyarc DuplicateentrySkyarc MailpackSkyarc Mtcms+13/11/201116/6/2026
Cross-site request forgery (CSRF) vulnerability in SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, allows remote attackers to hijack the authentication of arbitrary users for…
ModificadaMedia (5.5)1.1%—Skyarc AutotaggingSkyarc DuplicateentrySkyarc MailpackSkyarc Mtcms+13/11/201116/6/2026
SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, uses weak permissions, which allows remote authenticated users to modify files and settings via unspecified vectors.
ModificadaMedia (6.8)3.4%—Element-it Ultimate Uploader27/4/201016/6/2026
Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/.
ModificadaMedia (5)2.7%—Andy Stedemos THE Uploader27/4/201016/6/2026
Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter.
ModificadaMedia (6.8)3.3%—Phpf1 Max's Image Uploader26/1/201016/6/2026
Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it…
ModificadaAlta (9.3)4.8%—Larts Uploader Activex Control3/12/200916/6/2026
Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreateURL, (5) ErrorURL, or (6) httpsinglehost property value.
ModificadaAlta (7.5)2.2%—Xoops Uploader8/9/200916/6/2026
Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a downloadfile action to index.php.