Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
99 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 6.1% | 💥 Exploit | Pc4arb PC4 Uploader | 23/6/2009 | 16/6/2026 | Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attackers to read arbitrary files via (1) a .. (dot dot) or (2) absolute path in the file parameter. | |
| Modificada | Alta (9.3) | 4.1% | — | Ebay Enhanced Picture Uploader Activex Control | 9/6/2009 | 16/6/2026 | eBay Enhanced Picture Uploader ActiveX control (EPUWALcontrol.dll) before 1.0.27 allows remote attackers to execute arbitrary commands via the PictureUrls property. | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Pc4arb PC4 Uploader | 20/5/2009 | 16/6/2026 | code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks via crafted keyword sequences that are removed from a filter in the id parameter in a banner action, as demonstrated via the "UNIunionON" string, which is collapsed into "UNION" by the filter_sql… | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Celerondude Uploader | 4/3/2009 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in account.php in Celerondude Uploader 6.1 allows remote attackers to inject arbitrary web script or HTML via the username parameter. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 33% | 💥 Exploit | Facebook Photouploader | 24/12/2008 | 16/6/2026 | Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to execute arbitrary code via a long FileMask property value. | |
| Modificada | Media (6.8) | 0.91% | 💥 Exploit | Scriptsfrenzy E-uploader PRO | 14/11/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in E-Uploader Pro 1.0 (aka Uploader PRO), when magic_quotes_gpc is disabled, allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to (a) img.php, (b) file.php, (c) mail.php, (d) thumb.php, (e) zip.php, and (f) zipit.php, and (2) the view parameter to… | |
| Modificada | Alta (7.5) | 7.8% | 💥 Exploit | Maian Script World Maian Uploader | 25/7/2008 | 16/6/2026 | admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrative access by sending an arbitrary uploader_cookie cookie. | |
| Modificada | Media (6.8) | 3.1% | — | Photostockplus Uploader Tool | 20/5/2008 | 16/6/2026 | Multiple stack-based buffer overflows in the PhotoStockPlus Uploader Tool ActiveX control (PSPUploader.ocx) allow remote attackers to execute arbitrary code via unspecified initialization parameters. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Maianscriptworld Maian Uploader | 14/5/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keywords parameter to upload/admin/index.php in a search action, the (2) msg_charset and (3) msg_header9 parameters to admin/inc/header.php, and the (4) keywords parameter… | |
| Modificada | Alta (9.3) | 4.0% | — | Aurigma Image Uploader Activex ControlPiczo Imageuploader4 | 25/3/2008 | 16/6/2026 | Buffer overflow in a certain Aurigma ActiveX control in ImageUploader4.ocx 4.1.36.0, as used with Piczo (aka Pizco) and possibly other online services, allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long Action property, a different CLSID than CVE-2008-0659. | |
| Modificada | Alta (10) | 56% | 💥 Exploit | Aurigma Image Uploader Activex ControlMyspaceuploader | 8/2/2008 | 16/6/2026 | Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property. | |
| Modificada | Alta (9.3) | 38% | 💥 Exploit | Aurigma Image Uploader Activex ControlFacebookFacebook Photouploader | 8/2/2008 | 16/6/2026 | Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0, and 4.5.126.0, and ImageUploader5 5.0.10.0, as used by Facebook PhotoUploader 4.5.57.0, allow remote attackers to execute arbitrary code via long (1) ExtractExif and (2) ExtractIptc properties. | |
| Modificada | Alta (10) | 13% | 💥 Exploit | Lycos Fileuploader.dll | 25/1/2008 | 16/6/2026 | Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUploader Module allows remote attackers to execute arbitrary code via a long HandwriterFilename property value. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 2.2% | — | PHP F1 Maxs File Uploader | 22/1/2008 | 16/6/2026 | Unrestricted file upload vulnerability in PHP F1 Max's File Uploader allows remote attackers to upload and execute arbitrary PHP files. | |
| Modificada | Media (5) | 1.2% | — | Uber Uploader | 8/1/2008 | 16/6/2026 | The default configuration of Uber Uploader (UU) 5.3.6 and earlier does not block uploads of (1) .html, (2) .asp, and other possibly dangerous extensions, which allows remote attackers to use these extensions in uploads via (a) uu_file_upload.php, related to uu_file_upload.js and (b) uber_uploader_file.php, related to… | |
| Modificada | Media (6.8) | 38% | 💥 Exploit | JoomlaMichael Dempfle Joomla Flash Uploader | 14/10/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Michael Dempfle Joomla Flash Uploader (com_jfu or com_joomla_flash_uploader) 2.5.1 component for Joomla! allow remote attackers to execute arbitrary PHP code via a URL in the mosConfig_absolute_path parameter to (1) install.joomla_flash_uploader.php and (2)… | |
| Modificada | Alta (7.8) | 1.6% | — | Javaatwork Myftpuploader ModuleScottmanktelow Stride | 12/10/2007 | 16/6/2026 | include/imageupload.js in the MyFTPUploader module in Stride 1.0 contains sensitive information including FTP login credentials, which might allow remote attackers to gain unauthorized access to the FTP server being used by the module by viewing the source code. | |
| Modificada | Alta (7.5) | 3.2% | 💥 Exploit | Phphq Phuploader | 25/8/2007 | 16/6/2026 | Unrestricted file upload vulnerability in phUploader.php in phphq.Net phUploader 1.2 allows remote attackers to upload and execute arbitrary code via unspecified vectors. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. | |
| Modificada | Media (6.8) | 2.2% | — | Mapos Scripts Bilder Uploader | 14/8/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Bilder Uploader 1.3 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) gruppen.php, (2) bild.php, (3) feed.php, (4) mitglieder.php, (5) online.php, (6) profil.php, and possibly other unspecified PHP scripts. | |
| Modificada | Media (6.8) | 3.1% | 💥 Exploit | Mapos Scripts File Uploader | 14/8/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php or (2) datei.php. | |
| Modificada | Media (5) | 1.3% | — | Tuan DO Uploader | 26/1/2007 | 16/6/2026 | Tuan Do Uploader (aka php-uploader) 6 beta 1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain the administrator password hash via a direct request for userdata/user_1.txt. | |
| Modificada | Media (6.8) | 1.3% | — | Uber Uploader | 9/1/2007 | 16/6/2026 | Unrestricted file upload vulnerability in Uber Uploader 4.2 allows remote attackers to upload and execute arbitrary PHP scripts by naming them with a .phtml extension, which bypasses the .php extension check but is still executable on some server configurations. | |
| Modificada | Alta (7.5) | 2.5% | 💥 Exploit | Scriptsfrenzy.com E-uploader PRO | 21/12/2006 | 16/6/2026 | Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to execute arbitrary PHP code via a .. (dot dot) in the language parameter, as demonstrated by uploading a .JPG file containing PHP code, then accessing the file via config.php. | |
| Modificada | Media (6.8) | 2.1% | — | Graeme Uploader | 31/12/2003 | 16/6/2026 | Unrestricted file upload vulnerability in uploader.php in Uploader 1.1 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in uploads/. |