Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
99 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.3% | — | Webcraftic Simple 301 Redirects-addon-bulk Uploader | 29/8/2019 | 17/6/2026 | The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file. | |
| Modificada | Media (6.5) | 1.5% | — | Jenkins Fortify ON Demand Uploader | 28/3/2019 | 17/6/2026 | A missing permission check in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers with Overall/Read permission to initiate a connection to an attacker-specified server. | |
| Modificada | Media (6.5) | 1.3% | — | Jenkins Fortify ON Demand Uploader | 28/3/2019 | 17/6/2026 | A cross-site request forgery vulnerability in Jenkins Fortify on Demand Uploader Plugin 3.0.10 and earlier allows attackers to initiate a connection to an attacker-specified server. | |
| Modificada | Crítica (9.8) | 1.8% | — | Fineuploader Php-traditional-server | 19/11/2018 | 17/6/2026 | Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2 | |
| Modificada | Crítica (9.8) | 3.5% | — | Tinywebgallery Wordpress Flash Uploader | 25/4/2018 | 17/6/2026 | The WordPress Flash Uploader plugin before 3.1.3 for WordPress allows remote attackers to execute arbitrary commands via vectors related to invalid characters in image_magic_path. | |
| Modificada | Alta (7.5) | 55% | — | Drupal Avatar Uploader | 4/4/2018 | 17/6/2026 | Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path. | |
| Modificada | Alta (7.8) | 0.45% | — | Synology Photo Station Uploader | 23/8/2017 | 17/6/2026 | Multiple untrusted search path vulnerabilities in installer in Synology Photo Station Uploader before 1.4.2-084 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current… | |
| Modificada | Media (6.5) | 1.8% | — | Avatar Uploader Project Avatar Uploader | 26/2/2015 | 17/6/2026 | Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors. | |
| Modificada | Media (6.8) | 0.61% | — | Maianscriptworld Maian Uploader | 13/1/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Maian Uploader 4.0 allow remote attackers to hijack the authentication of unspecified users for requests that conduct cross-site scripting (XSS) attacks via the width parameter to (1) uploader/admin/js/load_flv.js.php or (2) uploader/js/load_flv.js.php. | |
| Modificada | Media (5) | 1.8% | — | Maianscriptworld Maian Uploader | 13/1/2015 | 17/6/2026 | Maian Uploader 4.0 allows remote attackers to obtain sensitive information via a request without the height parameter to load_flv.js.php, which reveals the installation path in an error message. | |
| Modificada | Alta (7.5) | 2.1% | — | Maianscriptworld Maian Uploader | 13/1/2015 | 17/6/2026 | SQL injection vulnerability in admin/data_files/move.php in Maian Uploader 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter. | |
| Modificada | Media (4.3) | 1.9% | — | Maian Script World Maian Uploader | 13/1/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the width parameter to (1) uploader/admin/js/load_flv.js.php or (2) uploader/js/load_flv.js.php. | |
| Modificada | Media (4.3) | 6.5% | — | Frontend Uploader Project Frontend Uploader | 2/1/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI. | |
| Modificada | Media (4) | 1.5% | — | Avatar Uploader Project Avatar Uploader | 1/12/2014 | 17/6/2026 | Directory traversal vulnerability in the Avatar Uploader module 6.x-1.x before 6.x-1.2 and 7.x-1.x before 7.x-1.0-beta6 for Drupal allows remote authenticated users to read arbitrary files via a .. (dot dot) in the path of a cropped picture in the uploader panel. | |
| Modificada | Media (6.5) | 1.7% | — | Najeebmedia N-media File Uploader | 26/9/2014 | 17/6/2026 | Unrestricted file upload vulnerability in the N-Media file uploader plugin before 3.4 for WordPress allows remote authenticated users to execute arbitrary PHP code by leveraging Author privileges to store a file. | |
| Modificada | Alta (7.5) | 2.7% | — | Megalab THE Uploader | 12/8/2014 | 16/6/2026 | SQL injection vulnerability in login.php in MegaLab The Uploader before 2.0.5 allows remote attackers to execute arbitrary SQL commands via the username parameter. | |
| Modificada | Media (4.3) | 9.2% | — | Roberta Bramski Uploader | 4/4/2014 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) notify or (2) blog parameter. | |
| Modificada | Alta (7.5) | 10% | — | Pippin Williamson Font Uploader | 27/6/2012 | 16/6/2026 | Unrestricted file upload vulnerability in font-upload.php in the Font Uploader plugin 1.2.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file with a .php.ttf extension, then accessing it via a direct request to the file in font-uploader/fonts. | |
| Modificada | Media (6.8) | 0.59% | — | Skyarc AutotaggingSkyarc DuplicateentrySkyarc MailpackSkyarc Mtcms+1 | 3/11/2011 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, allows remote attackers to hijack the authentication of arbitrary users for… | |
| Modificada | Media (5.5) | 1.1% | — | Skyarc AutotaggingSkyarc DuplicateentrySkyarc MailpackSkyarc Mtcms+1 | 3/11/2011 | 16/6/2026 | SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, uses weak permissions, which allows remote authenticated users to modify files and settings via unspecified vectors. | |
| Modificada | Media (6.8) | 3.4% | — | Element-it Ultimate Uploader | 27/4/2010 | 16/6/2026 | Unrestricted file upload vulnerability in Element-IT Ultimate Uploader 1.3 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in upload/. | |
| Modificada | Media (5) | 2.7% | — | Andy Stedemos THE Uploader | 27/4/2010 | 16/6/2026 | Directory traversal vulnerability in api/download_checker.php in MegaLab The Uploader 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter. | |
| Modificada | Media (6.8) | 3.3% | — | Phpf1 Max's Image Uploader | 26/1/2010 | 16/6/2026 | Unrestricted file upload vulnerability in maxImageUpload/index.php in PHP F1 Max's Image Uploader 1.0, when Apache is not configured to handle the mime-type for files with pjpeg or jpeg extensions, allows remote attackers to execute arbitrary code by uploading a file with a pjpeg or jpeg extension, then accessing it… | |
| Modificada | Alta (9.3) | 4.8% | — | Larts Uploader Activex Control | 3/12/2009 | 16/6/2026 | Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreateURL, (5) ErrorURL, or (6) httpsinglehost property value. | |
| Modificada | Alta (7.5) | 2.2% | — | Xoops Uploader | 8/9/2009 | 16/6/2026 | Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a downloadfile action to index.php. |