Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.3) | 0.61% | — | Increase Maximum Upload File Size Increase Execution TimeAI | 23/11/2024 | 17/6/2026 | The Increase Maximum Upload File Size | Increase Execution Time plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 1.1.3. This is due to returning image upload error messages with full path information. This makes it possible for authenticated attackers, with author-level… | |
| Aplazada | Media (6.1) | 0.48% | — | Peprodev Woocommerce Receipt UploaderAI | 16/11/2024 | 17/6/2026 | The PeproDev WooCommerce Receipt Uploader plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.6.9. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in… | |
| Analizada | Crítica (9.8) | 1.2% | — | Vanquish Woocommerce Upload Files | 13/11/2024 | 17/6/2026 | The WooCommerce Upload Files plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the upload_files() function in all versions up to, and including, 84.3. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may… | |
| Analizada | Baja (3.5) | 0.25% | — | Iptanus Wordpress File Upload | 1/11/2024 | 17/6/2026 | Broken Access Control vulnerability in Nickolas Bossinas WordPress File Upload allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WordPress File Upload: from n/a through 4.24.7. | |
| Modificada | Media (5.4) | 0.30% | — | Delowerhossain Easy SVG Upload | 31/10/2024 | 17/6/2026 | The Easy SVG Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary… | |
| Aplazada | Media (6.4) | 0.38% | — | Wpforms File Upload TypesAI | 25/10/2024 | 17/6/2026 | The File Upload Types by WPForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.4.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to… | |
| Aplazada | Alta (8.6) | 0.59% | — | Jamespark Analyse UploadsAI | 16/10/2024 | 17/6/2026 | Relative Path Traversal vulnerability in JamesPark.ninja Analyse Uploads analyse-uploads allows Relative Path Traversal.This issue affects Analyse Uploads: from n/a through <= 0.5. | |
| Aplazada | Media (4.3) | 0.34% | — | Multiline Files Upload FOR Contact Form 7AI | 16/10/2024 | 17/6/2026 | The Multiline files upload for contact form 7 plugin for WordPress is vulnerable to unauthorized plugin deactivation due to a missing capability check on the mfcf7_zl_custom_handle_deactivation_plugin_form_submission() function in all versions up to, and including, 2.8.1. This makes it possible for authenticated… | |
| Analizada | Media (5.3) | 0.58% | — | Rems Drag AND Drop Image Upload | 15/10/2024 | 17/6/2026 | A vulnerability was found in SourceCodester Drag and Drop Image Upload 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /upload.php. The manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and… | |
| Analizada | Crítica (9.8) | 93% | 💥 Exploit | Iptanus Wordpress File Upload | 12/10/2024 | 17/6/2026 | The WordPress File Upload plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 4.24.11 via wfu_file_downloader.php. This makes it possible for unauthenticated attackers to read or delete files outside of the originally intended directory. Successful exploitation requires the… | |
| Aplazada | Crítica (9.8) | 40% | 💥 Exploit | Angular-base64-uploadAI | 11/10/2024 | 17/6/2026 | angular-base64-upload prior to v0.1.21 is vulnerable to unauthenticated remote code execution via demo/server.php. Exploiting this vulnerability allows an attacker to upload arbitrary content to the server, which can subsequently be accessed through demo/uploads. This leads to the execution of previously uploaded… | |
| Aplazada | Media (6.1) | 0.45% | — | Increase Upload File Size Maximum Execution Time LimitAI | 11/10/2024 | 17/6/2026 | The Increase upload file size & Maximum Execution Time limit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.0. This makes it possible for unauthenticated attackers to inject arbitrary… | |
| Aplazada | Media (6.4) | 0.39% | — | Avif SVG UploaderAI | 1/10/2024 | 17/6/2026 | The AVIF & SVG Uploader plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in version 1.1.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject arbitrary web scripts in pages… | |
| Analizada | Media (6.1) | 0.43% | — | Ninjaforms Ninja Forms File Uploads | 7/9/2024 | 17/6/2026 | The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web… | |
| Analizada | Media (4.3) | 0.56% | — | Infiniteuploads BIG File Uploads | 7/9/2024 | 17/6/2026 | The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1.2. This is due the plugin not sanitizing a file path in an error message. This makes it possible for authenticated attackers, with author-level access and above,… | |
| Modificada | Media (6.1) | 0.40% | — | Xiebruce Picuploader | 26/8/2024 | 5/7/2026 | A cross-site scripting (XSS) vulnerability in the component /auth/AzureRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter. | |
| Modificada | Media (6.1) | 0.29% | — | Xiebruce Picuploader | 26/8/2024 | 5/7/2026 | A cross-site scripting (XSS) vulnerability in the component /master/auth/OnedriveRedirect.php of PicUploader commit fcf82ea allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the error_description parameter. | |
| Analizada | Alta (8.7) | 0.37% | — | Avtecinc Outpost Uploader UtilityAvtecinc Outpost 0810 Firmware | 22/8/2024 | 17/6/2026 | Avtec Outpost uses a default cryptographic key that can be used to decrypt sensitive information. | |
| Analizada | Alta (8.7) | 0.39% | — | Avtecinc Outpost Uploader UtilityAvtecinc Outpost 0810 Firmware | 22/8/2024 | 17/6/2026 | Avtec Outpost stores sensitive information in an insecure location without proper access controls in place. | |
| Analizada | Media (6.1) | 0.46% | — | Iptanus Wordpress File Upload | 16/8/2024 | 17/6/2026 | The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 4.24.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that… | |
| Analizada | Media (6.1) | 0.36% | — | Iptanus Wordpress File Upload | 7/8/2024 | 17/6/2026 | The WordPress File Upload WordPress plugin before 4.24.8 does not properly sanitize and escape certain parameters, which could allow unauthenticated users to execute stored cross-site scripting (XSS) attacks. | |
| Analizada | Media (6.1) | 15% | 💥 Exploit | Iptanus Wordpress File Upload | 6/8/2024 | 17/6/2026 | The WordPress File Upload WordPress plugin before 4.24.8 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (4.3) | 0.69% | — | Iptanus Wordpress File Upload | 16/7/2024 | 17/6/2026 | The WordPress File Upload plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 4.24.7 via the 'uploadpath' parameter of the wordpress_file_upload shortcode. This makes it possible for authenticated attackers, with Contributor-level access and above, to upload limited files to… | |
| Modificada | Crítica (9.8) | 0.36% | — | Softlabbd Upload Fields FOR Wpforms | 9/6/2024 | 17/6/2026 | Missing Authorization vulnerability in SoftLab Upload Fields for WPForms.This issue affects Upload Fields for WPForms: from n/a through 1.0.2. | |
| Modificada | Media (4.3) | 0.45% | — | Wbcomdesigns Custom Font Uploader | 6/6/2024 | 17/6/2026 | The Wbcom Designs – Custom Font Uploader plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the 'cfu_delete_customfont' function in all versions up to, and including, 2.3.4. This makes it possible for authenticated attackers, with Subscriber-level access and above, to… |