Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (10) | 0.38% | — | Add-ons.org Drag AND Drop File Upload FOR Elementor FormsAI | 28/8/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms drag-and-drop-file-upload-for-elementor-forms allows Upload a Web Shell to a Web Server.This issue affects Drag and Drop File Upload for Elementor Forms: from n/a through <= 1.5.3. | |
| Aplazada | Media (5.3) | 0.71% | — | Drag AND Drop Multiple File Upload FOR Contact Form 7AI | 16/8/2025 | 17/6/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 1.3.9.0 via the wpcf7_guest_user_id cookie. This makes it possible for unauthenticated attackers to upload and delete files outside of the originally intended… | |
| Aplazada | Alta (8.8) | 0.32% | — | Tagfree X-free UploaderAI | 7/8/2025 | 17/6/2026 | : External Control of File Name or Path vulnerability in TAGFREE X-Free Uploader XFU allows : Parameter Injection.This issue affects X-Free Uploader: from 1.0.1.0084 before 1.0.1.0085, from 2.0.1.0034 before 2.0.1.0035. | |
| Aplazada | Alta (8.7) | 0.42% | — | Tagfree X-free UploaderAI | 7/8/2025 | 17/6/2026 | : Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in TAGFREE X-Free Uploader XFU allows Path Traversal.This issue affects X-Free Uploader: from 1.0.1.0084 before 1.0.1.0085, from 2.0.1.0034 before 2.0.1.0035. | |
| Analizada | Baja (2.1) | 0.43% | — | Jingmen Zeyou Large File Upload Control | 26/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Jingmen Zeyou Large File Upload Control up to 6.3. Affected is an unknown function of the file /index.jsp. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Crítica (9.8) | 4.7% | 💥 Exploit | Najeebmedia Website Contact Form With File Upload | 22/7/2025 | 17/6/2026 | The Website Contact Form With File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'upload_file()' function in versions up to, and including, 1.3.4. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected sites server… | |
| Analizada | Crítica (9.8) | 3.6% | 💥 Exploit | Lyntonreed Work THE Flow File Upload | 19/7/2025 | 27/7/2026 | The Work The Flow File Upload plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the jQuery-File-Upload-9.5.0 server and test files in versions up to, and including, 2.5.2. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected… | |
| Aplazada | Crítica (9.3) | 3.6% | 💥 Exploit | BuilderengineAIElfinderAIJquery File UploadAI | 10/7/2025 | 17/6/2026 | An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuery File Upload plugin. The plugin fails to properly validate or restrict file types or locations during upload operations, allowing an attacker to upload a malicious .php… | |
| Aplazada | Media (5.4) | 0.18% | — | Secure-uploadAI | 10/7/2025 | 17/6/2026 | Secure-upload is a data submission service that validates single-use tokens when accepting submissions to channels. The service only installed on a small number of environments. Under specific circumstances, privileged users of secure-upload could have selected email templates not necessarily created for their… | |
| Aplazada | Media (5.4) | 0.18% | — | Mediawiki MsuploadAI | 8/7/2025 | 17/6/2026 | The MsUpload extension for MediaWiki is vulnerable to stored XSS via the msu-continue system message, which is inserted into the DOM without proper sanitization. The vulnerability occurs in the file upload UI when the same filename is uploaded twice. This issue affects Mediawiki - MsUpload extension: from 1.39.X… | |
| Aplazada | Crítica (9.8) | 0.74% | — | Drag AND Drop Multiple File Upload PROAI | 2/7/2025 | 17/6/2026 | The Drag and Drop Multiple File Upload (Pro) - WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the dnd_upload_cf7_upload_chunks() function in version 5.0 - 5.0.5 (when bundled with the PrintSpace theme) and all versions up to, and including, 1.7.1 (in the… | |
| Aplazada | Alta (7.1) | 0.12% | — | Alanft Relocate UploadAI | 27/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in alanft Relocate Upload relocate-upload allows Stored XSS.This issue affects Relocate Upload: from n/a through <= 0.24.1. | |
| Aplazada | Crítica (10) | 0.41% | — | Harutheme Drag AND Drop Multiple File Upload PRO WoocommerceAI | 27/6/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in HaruTheme Drag and Drop Multiple File Upload (Pro) - WooCommerce drag-and-drop-file-upload-wc-pro allows Upload a Web Shell to a Web Server.This issue affects Drag and Drop Multiple File Upload (Pro) - WooCommerce: from n/a through <= 5.0.6. | |
| Aplazada | Media (4.9) | 0.20% | — | ALI Irani Auto Upload ImagesAI | 20/6/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Ali Irani Auto Upload Images auto-upload-images allows Server Side Request Forgery.This issue affects Auto Upload Images: from n/a through <= 3.3.2. | |
| Analizada | Crítica (9.8) | 5.8% | 💥 Exploit | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 17/6/2025 | 17/6/2026 | The Drag and Drop Multiple File Upload for Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in all versions up to, and including, 1.3.8.9. This makes it possible for unauthenticated attackers to bypass the plugin's blacklist and upload .phar or other… | |
| Modificada | Alta (7.5) | 33% | 💥 PoC | Apache Commons Fileupload | 16/6/2025 | 17/6/2026 | Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue. | |
| Aplazada | Alta (8.6) | 1.4% | — | Add-ons.org Drag AND Drop File Upload FOR Elementor FormsAI | 23/5/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in add-ons.org Drag and Drop File Upload for Elementor Forms drag-and-drop-file-upload-for-elementor-forms allows Path Traversal.This issue affects Drag and Drop File Upload for Elementor Forms: from n/a through <= 1.4.3. | |
| Analizada | Media (5.4) | 0.30% | — | Grandplugins Avif Uploader | 15/5/2025 | 17/6/2026 | The AVIF Uploader WordPress plugin before 1.1.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |
| Analizada | Media (5.4) | 0.29% | — | Ablyperu SVG Uploads Support | 15/5/2025 | 17/6/2026 | The SVG Uploads Support WordPress plugin through 2.1.1 does not sanitize uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads. | |
| Aplazada | Media (5.3) | 0.28% | — | Peepso Core File UploadsAI | 14/5/2025 | 17/6/2026 | The PeepSo Core: File Uploads plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 6.4.6.0 via the file_download REST API endpoint due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to download files uploaded… | |
| Aplazada | Crítica (9.8) | 2.3% | 💥 PoC | Codedropz Drag AND Drop Multiple File Upload FOR WoocommerceAI | 9/5/2025 | 17/6/2026 | The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file uploads in all versions up to, and including, 1.1.6 due to accepting a user‐supplied supported_type string and the uploaded filename without enforcing real extension or MIME checks within the upload() function.… | |
| Analizada | Crítica (9.8) | 0.34% | — | Multiple File Upload Project Multiple File Upload | 5/5/2025 | 17/6/2026 | The Multiple File Upload add-on component 3.1.0 for OutSystems is vulnerable to Unrestricted File Upload. This occurs because file extension and size validations are enforced solely on the client side. An attacker can intercept the upload request and modify a parameter to bypass extension restrictions and upload… | |
| Aplazada | Crítica (9.8) | 0.57% | 💥 PoC | AdeptAIGithub Actions Upload ArtifactAI | 21/4/2025 | 17/6/2026 | Adept is a language for general purpose programming. Prior to commit a1a41b7, the remoteBuild.yml workflow file uses actions/upload-artifact@v4 to upload the mac-standalone artifact. This artifact is a zip of the current directory, which includes the automatically generated .git/config file containing the run's… | |
| Aplazada | Media (6.5) | 0.35% | — | Wpwham Checkout Files Upload FOR WoocommerceAI | 16/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WP Wham Checkout Files Upload for WooCommerce checkout-files-upload-woocommerce allows Stored XSS.This issue affects Checkout Files Upload for WooCommerce: from n/a through <= 2.2.0. | |
| Aplazada | Crítica (9.8) | 1.7% | — | Codedropz Drag AND Drop Multiple File Upload FOR WoocommerceAI | 5/4/2025 | 17/6/2026 | The Drag and Drop Multiple File Upload for WooCommerce plugin for WordPress is vulnerable to arbitrary file moving due to insufficient file path validation via the wc-upload-file[] parameter in all versions up to, and including, 1.1.4. This makes it possible for unauthenticated attackers to move arbitrary files on the… |