Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

384 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.17%—Uploadcare File UploaderAIUploadcare Adaptive DeliveryAI1/6/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Uploadcare Uploadcare File Uploader and Adaptive Delivery (beta) uploadcare.This issue affects Uploadcare File Uploader and Adaptive Delivery (beta): from n/a through 3.0.11.
AplazadaCrítica (9)1.0%—Linuxmint MintuploadAI19/5/202417/6/2026
In the mintupload package through 4.2.0 for Linux Mint, service-name mishandling leads to command injection via shell metacharacters in check_connection, drop_data_received_cb, and Service.remove. A user can modify a service name in a ~/.linuxmint/mintUpload/services/service file.
ModificadaAlta (7.5)0.71%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 72/5/202417/6/2026
The Drag and Drop Multiple File Upload – Contact Form 7 plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.3.7.7 via the '/wp-content/uploads/wp_dndcf7_uploads/wpcf7-files' directory. This makes it possible for unauthenticated attackers to extract sensitive…
AplazadaAlta (7.5)0.59%—FME Modules FileuploadsAI30/4/20249/7/2026
An issue in FME Modules fileuploads v.2.0.3 and before and fixed in v2.0.4 allows a remote attacker to obtain sensitive information via the uploadfiles.php component.
AplazadaAlta (7.1)0.35%—Adam Bowen TAX Rate UploadAI17/4/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Adam Bowen Tax Rate Upload allows Reflected XSS.This issue affects Tax Rate Upload: from n/a through 2.4.5.
ModificadaMedia (5.4)0.36%—Iptanus Wordpress File Upload9/4/202417/6/2026
The WordPress File Upload plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's shortcode(s) in all versions up to, and including, 4.24.5 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AplazadaAlta (7.1)0.18%—Adam Bowen TAX Rate UploadAI2/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Adam Bowen Tax Rate Upload allows Reflected XSS.This issue affects Tax Rate Upload: from n/a through 2.4.5.
AplazadaBaja (3.5)0.49%—Wp-file-uploadAI1/4/202417/6/2026
A vulnerability has been found in wp-file-upload Plugin up to 2.4.3 on WordPress and classified as problematic. Affected by this vulnerability is the function wfu_ajax_action_callback of the file lib/wfu_ajaxactions.php. The manipulation leads to cross site scripting. The attack can be launched remotely. Upgrading to…
AplazadaMedia (5.9)0.54%—Mbbhatti Upload ResumeAI26/3/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in mbbhatti Upload Resume.This issue affects Upload Resume: from n/a through 1.2.0.
AplazadaCrítica (10)0.81%—Mainwp File Uploader ExtensionAI26/3/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in MainWP MainWP File Uploader Extension.This issue affects MainWP File Uploader Extension: from n/a through 4.1.
ModificadaMedia (6.5)0.79%—Connekthq Instant Images - ONE Click Unsplash Uploads5/2/202417/6/2026
The Instant Images – One Click Image Uploads from Unsplash, Openverse, Pixabay and Pexels plugin for WordPress is vulnerable to unauthorized arbitrary options update due to an insufficient check that neglects to verify whether the updated option belongs to the plugin on the instant-images/license REST API endpoint in…
ModificadaAlta (8.8)0.23%—Wpzone Inline Image Upload FOR Bbpress5/1/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WP Zone Inline Image Upload for BBPress.This issue affects Inline Image Upload for BBPress: from n/a through 1.1.18.
ModificadaMedia (5.4)0.44%—Verot Class.upload.php4/1/202417/6/2026
As a simple library, class.upload.php does not perform an in-depth check on uploaded files, allowing a stored XSS vulnerability when the default configuration is used. Developers must be aware of that fact and use extension whitelisting accompanied by forcing the server to always provide content-type based on the file…
ModificadaCrítica (9.8)0.60%—Codedropz Drag AND Drop Multiple File Upload FOR Woocommerce21/12/202317/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Glen Don L. Mongaya Drag and Drop Multiple File Upload for WooCommerce.This issue affects Drag and Drop Multiple File Upload for WooCommerce: from n/a through 1.0.8.
ModificadaMedia (5.4)1.0%💥 PoCUploading Svg, Webp AND ICO Files Project Uploading Svg, Webp AND ICO Files4/12/202317/6/2026
The Uploading SVG, WEBP and ICO files WordPress plugin through 1.2.1 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
ModificadaAlta (8.8)0.26%—Infiniteuploads BIG File Uploads22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Infinite Uploads Big File Uploads – Increase Maximum File Upload Size plugin <= 2.1.1 versions.
ModificadaCrítica (9.8)1.8%—Codedropz Drag AND Drop Multiple File Upload - Contact Form 722/11/202317/6/2026
The Drag and Drop Multiple File Upload - Contact Form 7 plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient file type validation in the 'dnd_upload_cf7_upload' function in versions up to, and including, 1.3.7.3. This makes it possible for unauthenticated attackers to upload arbitrary files…
ModificadaMedia (5.4)0.39%—Ashik Cits Support Svg, Webp Media AND Ttf,otf File Upload31/10/202317/6/2026
The CITS Support svg, webp Media and TTF,OTF File Upload WordPress plugin before 3.0 does not sanitise uploaded SVG files, which could allow users with a role as low as Author to upload a malicious SVG containing XSS payloads.
ModificadaMedia (5.4)0.45%—Codedropz Drag AND Drop Multiple File Uploader16/10/202317/6/2026
The Drag and Drop Multiple File Upload for WooCommerce WordPress plugin before 1.1.1 does not filter all potentially dangerous file extensions. Therefore, an attacker can upload unsafe .shtml or .svg files containing malicious scripts.
ModificadaMedia (5.4)0.39%—Iptanus Wordpress File Upload16/10/202317/6/2026
The WordPress File Upload WordPress plugin before 4.23.3 does not sanitise and escape some of its settings, which could allow high privilege users such as contributors to perform Stored Cross-Site Scripting attacks.
ModificadaAlta (8.8)2.0%💥 PoCOpenupload Project Openupload20/9/202317/6/2026
File Upload vulnerability in Openupload Stable v.0.4.3 allows a remote attacker to execute arbitrary code via the action parameter of the compress-inc.php file.
ModificadaMedia (6.5)0.31%—Notetoservices Upload Media BY URL30/8/202317/6/2026
The Upload Media By URL WordPress plugin before 1.0.8 does not have CSRF check when uploading files, which could allow attackers to make logged in admins upload files (including HTML containing JS code for users with the unfiltered_html capability) on their behalf.
ModificadaAlta (8.3)0.49%—Troplo Privateuploader14/8/202317/6/2026
PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did not correctly verify whether the user was an administrator (High Level) or moderator (Low Level) causing the request to continue processing. The response would be a 403…
ModificadaMedia (5.4)0.32%—Ideastocode Enable Svg, Webp & ICO Upload17/7/202317/6/2026
The Enable SVG, WebP & ICO Upload WordPress plugin through 1.0.3 does not sanitize SVG file contents, leading to a Cross-Site Scripting vulnerability.
ModificadaAlta (7.5)1.2%—Microsoft Pandocupload11/7/202317/6/2026
MediaWiki PandocUpload Extension Remote Code Execution Vulnerability
Orbitaley — Vulnerabilidades