Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
384 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.8) | 0.61% | — | Thinkific Uploader | 8/8/2022 | 17/6/2026 | The Thinkific Uploader WordPress plugin through 1.0.0 does not sanitise and escape its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks against other administrators. | |
| Modificada | Media (5.4) | 0.56% | — | Ideastocode Enable Svg, Webp & ICO Upload | 1/8/2022 | 17/6/2026 | Authenticated (author or higher user role) Stored Cross-Site Scripting (XSS) vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress. | |
| Modificada | Alta (8.8) | 1.3% | — | Ideastocode Enable Svg, Webp & ICO Upload | 1/8/2022 | 17/6/2026 | Authenticated (author or higher user role) Arbitrary File Upload vulnerability in ideasToCode Enable SVG, WebP & ICO Upload plugin <= 1.0.1 at WordPress. | |
| Modificada | Crítica (9.8) | 1.0% | — | Swfupload Project Swfupload | 30/6/2022 | 16/6/2026 | There is an object injection vulnerability in swfupload plugin for wordpress. | |
| Modificada | Media (6.5) | 0.77% | — | Change Uploaded File Permissions Project Change Uploaded File Permissions | 13/6/2022 | 17/6/2026 | Due to missing checks the Change Uploaded File Permissions WordPress plugin through 4.0.0 is vulnerable to CSRF attacks. This can be used to change the file and folder permissions of any folder. This could be problematic when specific files like ini files are made readable for everyone due to this. | |
| Modificada | Media (5.4) | 1.2% | — | Friendsofflarum Upload | 2/6/2022 | 17/6/2026 | FriendsofFlarum (FoF) Upload is an extension that handles file uploads intelligently for your forum. If FoF Upload prior to version 1.2.3 is configured to allow the uploading of SVG files ('image/svg+xml'), navigating directly to an SVG file URI could execute arbitrary Javascript code decided by an attacker. This… | |
| Modificada | Crítica (9.8) | 3.1% | — | S3-uploader Project S3-uploader | 2/6/2022 | 17/6/2026 | OS command injection vulnerability in Turistforeningen node-s3-uploader through 2.0.3 for Node.js allows attackers to execute arbitrary commands via the metadata() function. | |
| Modificada | Media (6.1) | 0.70% | — | Wpwham Checkout Files Upload FOR Woocommerce | 20/5/2022 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerability in WP Wham's Checkout Files Upload for WooCommerce plugin <= 2.1.2 at WordPress. | |
| Modificada | Alta (8.8) | 16% | 💥 Exploit | Advanced Uploader Project Advanced Uploader | 16/5/2022 | 17/6/2026 | The Advanced Uploader WordPress plugin through 4.2 allows any authenticated users like subscriber to upload arbitrary files, such as PHP, which could lead to RCE | |
| Modificada | Crítica (9.8) | 1.8% | — | Graphql-upload Project Graphql-upload | 16/5/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the file upload module of Graphql-upload v13.0.0 allows attackers to execute arbitrary code via a crafted filename. | |
| Modificada | Alta (7.5) | 1.4% | — | Express-fileupload Project Express-fileupload | 12/4/2022 | 17/6/2026 | An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite of files in the web application server. | |
| Modificada | Crítica (9.8) | 2.9% | — | Express-fileupload Project Express-fileupload | 12/4/2022 | 17/6/2026 | An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted PHP file. NOTE: the vendor's position is that the observed behavior can only occur with "intentional misusing of the API": the express-fileupload middleware is not… | |
| Modificada | Media (5.4) | 14% | 💥 Exploit | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 28/3/2022 | 17/6/2026 | The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue | |
| Modificada | Alta (8.8) | 2.8% | — | Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO | 28/3/2022 | 17/6/2026 | The WordPress File Upload Free and Pro WordPress plugins before 4.16.3 allow users with a role as low as Contributor to perform path traversal via a shortcode argument, which can then be used to upload a PHP code disguised as an image inside the auto-loaded directory of the plugin, resulting in arbitrary code… | |
| Modificada | Media (6.1) | 0.78% | — | Ninjaforms Ninja Forms File Uploads | 23/3/2022 | 17/6/2026 | The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to reflected cross-site scripting due to missing sanitization of the files filename parameter found in the ~/includes/ajax/controllers/uploads.php file which can be used by unauthenticated attackers to add malicious web scripts to vulnerable… | |
| Modificada | Crítica (9.8) | 39% | — | Ninjaforms Ninja Forms File Uploads | 23/3/2022 | 17/6/2026 | The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to… | |
| Modificada | Media (4.3) | 0.75% | — | Jenkins Incapptic Connect Uploader | 15/3/2022 | 17/6/2026 | Jenkins incapptic connect uploader Plugin 1.15 and earlier stores tokens unencrypted in job config.xml files on the Jenkins controller where they can be viewed by users with Extended Read permission, or access to the Jenkins controller file system. | |
| Modificada | Media (5.4) | 0.67% | — | Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO | 7/3/2022 | 17/6/2026 | The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 does not escape some of its shortcode argument, which could allow users with a role as low as Contributor to perform Cross-Site Scripting attacks | |
| Modificada | Media (5.4) | 0.67% | — | Iptanus Wordpress File UploadIptanus Wordpress File Upload PRO | 7/3/2022 | 17/6/2026 | The WordPress File Upload WordPress plugin before 4.16.3, wordpress-file-upload-pro WordPress plugin before 4.16.3 allows users with a role as low as Contributor to configure the upload form in a way that allows uploading of SVG files, which could be then be used for Cross-Site Scripting attacks | |
| Modificada | Media (6.1) | 0.87% | — | Hayageek Jquery Upload File | 25/2/2022 | 9/7/2026 | A cross-site scripting (XSS) vulnerability in the fileNameStr parameter of jQuery-Upload-File v4.0.11 allows attackers to execute arbitrary web scripts or HTML via a crafted file with a Javascript payload in the file name. | |
| Modificada | Media (6.1) | 0.95% | — | Phpuploader Project Phpuploader | 24/2/2022 | 17/6/2026 | Cross-site scripting vulnerability in phpUploader v1.2 and earlier allows a remote unauthenticated attacker to inject an arbitrary script via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.7% | — | Phpuploader Project Phpuploader | 24/2/2022 | 17/6/2026 | SQL injection vulnerability in the phpUploader v1.2 and earlier allows a remote unauthenticated attacker to obtain the information in the database via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.0% | — | Tiny Plupload | 3/12/2021 | 17/6/2026 | This affects the package plupload before 2.3.9. A file name containing JavaScript code could be uploaded and run. An attacker would need to trick a user to upload this kind of file. | |
| Modificada | Media (6.1) | 0.84% | — | Pekeupload Project Pekeupload | 22/11/2021 | 17/6/2026 | This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed. | |
| Modificada | Alta (8.8) | 0.63% | — | Dext5upload | 28/10/2021 | 17/6/2026 | DEXT5 Upload 5.0.0.117 and earlier versions contain a vulnerability, which could allow remote attacker to download and execute remote file by setting the argument, variable in the activeX module. This can be leveraged for code execution. |