Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
110 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.8) | 0.97% | — | Wordpress File Upload Project Wordpress File Upload | 12/8/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors. NOTE: some of these details are obtained from third… | |
| Modificada | Alta (8.8) | 1.7% | — | Versalsoft Http File Upload Activex Control | 7/4/2009 | 16/6/2026 | Insecure method vulnerability in the Versalsoft HTTP Image Uploader ActiveX control (UUploaderSvrD.dll 6.0.0.35) allows remote attackers to delete arbitrary files via the RemoveFileOrDir method. | |
| Modificada | Media (6.4) | 1.8% | 💥 Exploit | GHH Google Hack Honeypot File Upload Manager | 29/11/2008 | 16/6/2026 | Google Hack Honeypot (GHH) File Upload Manager 1.3 allows remote attackers to delete uploaded files via unknown vectors related to the delall action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. CVE analysis suggests that the most… | |
| Modificada | Alta (7.5) | 2.2% | — | PHP F1 Maxs File Uploader | 22/1/2008 | 16/6/2026 | Unrestricted file upload vulnerability in PHP F1 Max's File Uploader allows remote attackers to upload and execute arbitrary PHP files. | |
| Modificada | Media (6.8) | 3.1% | 💥 Exploit | Mapos Scripts File Uploader | 14/8/2007 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php or (2) datei.php. | |
| Modificada | Alta (9.3) | 7.2% | 💥 Exploit | Versalsoft Http File Upload Activex Control | 9/5/2007 | 16/6/2026 | Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remote attackers to execute arbitrary code via a long argument. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Mxmania File Upload Manager | 29/12/2006 | 16/6/2026 | SQL injection vulnerability in detail.asp in Mxmania File Upload Manager (FUM) 1.0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter. | |
| Modificada | Alta (7.5) | 1.7% | — | Thepeak File Upload Manager | 31/10/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in Thepeak File Upload Manager 1.3 allows remote attackers to read or download arbitrary files via a base64-encoded file path containing a .. (dot dot) sequence in the file parameter. | |
| Modificada | Media (5) | 1.4% | — | File Upload Manager | 12/6/2005 | 16/6/2026 | File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of '~~~~~~' (six tildes), which bypasses the file extension checks. | |
| Modificada | Alta (7.5) | 1.6% | — | Adam Mmedici File Upload Manager | 12/6/2005 | 16/6/2026 | mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action. |