Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

110 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.8)0.97%—Wordpress File Upload Project Wordpress File Upload12/8/201417/6/2026
Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change plugin settings via unspecified vectors. NOTE: some of these details are obtained from third…
ModificadaAlta (8.8)1.7%—Versalsoft Http File Upload Activex Control7/4/200916/6/2026
Insecure method vulnerability in the Versalsoft HTTP Image Uploader ActiveX control (UUploaderSvrD.dll 6.0.0.35) allows remote attackers to delete arbitrary files via the RemoveFileOrDir method.
ModificadaMedia (6.4)1.8%💥 ExploitGHH Google Hack Honeypot File Upload Manager29/11/200816/6/2026
Google Hack Honeypot (GHH) File Upload Manager 1.3 allows remote attackers to delete uploaded files via unknown vectors related to the delall action to index.php. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. CVE analysis suggests that the most…
ModificadaAlta (7.5)2.2%—PHP F1 Maxs File Uploader22/1/200816/6/2026
Unrestricted file upload vulnerability in PHP F1 Max's File Uploader allows remote attackers to upload and execute arbitrary PHP files.
ModificadaMedia (6.8)3.1%💥 ExploitMapos Scripts File Uploader14/8/200716/6/2026
Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP code via a URL in the config[root_ordner] parameter to (1) index.php or (2) datei.php.
ModificadaAlta (9.3)7.2%💥 ExploitVersalsoft Http File Upload Activex Control9/5/200716/6/2026
Buffer overflow in the AddFile function in VersalSoft HTTP File Upload ActiveX control (UFileUploaderD.dll) allows remote attackers to execute arbitrary code via a long argument.
ModificadaAlta (7.5)1.2%💥 ExploitMxmania File Upload Manager29/12/200616/6/2026
SQL injection vulnerability in detail.asp in Mxmania File Upload Manager (FUM) 1.0.6 and earlier allows remote attackers to execute arbitrary SQL commands via the ID parameter.
ModificadaAlta (7.5)1.7%—Thepeak File Upload Manager31/10/200616/6/2026
Directory traversal vulnerability in index.php in Thepeak File Upload Manager 1.3 allows remote attackers to read or download arbitrary files via a base64-encoded file path containing a .. (dot dot) sequence in the file parameter.
ModificadaMedia (5)1.4%—File Upload Manager12/6/200516/6/2026
File Upload Manager allows remote attackers to upload arbitrary files by modifying the test variable to contain a value of '~~~~~~' (six tildes), which bypasses the file extension checks.
ModificadaAlta (7.5)1.6%—Adam Mmedici File Upload Manager12/6/200516/6/2026
mtnpeak.net File Upload Manager does not properly check user authentication for certain actions, which allows remote attackers to provide a modified base64-encoded file parameter and (1) read arbitrary files via the "view" action or (2) delete arbitrary files via the del action.
Orbitaley — Vulnerabilidades