Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
–

24 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.5)0.63%—Palletsprojects FlaskAIJugmac00 Flask-reuploadedAI14/9/202630/9/2026
Flask-Reuploaded provides file uploads for Flask. From 1.5.0 until 1.6.0, UploadSet.save(storage, name=...) in src/flask_uploads/flask_uploads.py applies lowercase_ext to the default upload path but uses the case-preserving extension helper for a caller-supplied name before extension_allowed evaluates an AllExcept…
AnalizadaCrítica (9.8)1.2%—Jugmac00 Flask-reuploaded25/2/202617/6/2026
Flask-Reuploaded provides file uploads for Flask. A critical path traversal and extension bypass vulnerability in versions prior to 1.5.0 allows remote attackers to achieve arbitrary file write and remote code execution through Server-Side Template Injection (SSTI). Flask-Reuploaded has been patched in version 1.5.0.…
ModificadaAlta (7.5)33%—Apache Commons Fileupload16/6/202517/6/2026
Allocation of resources for multipart headers with insufficient limits enabled a DoS vulnerability in Apache Commons FileUpload. This issue affects Apache Commons FileUpload: from 1.0 before 1.6; from 2.0.0-M1 before 2.0.0-M4. Users are recommended to upgrade to versions 1.6 or 2.0.0-M4, which fix the issue.
AnalizadaMedia (4.3)0.56%—Infiniteuploads BIG File Uploads7/9/202417/6/2026
The Big File Uploads – Increase Maximum File Upload Size plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 2.1.2. This is due the plugin not sanitizing a file path in an error message. This makes it possible for authenticated attackers, with author-level access and above,…
AplazadaAlta (7.5)0.59%—FME Modules FileuploadsAI30/4/20249/7/2026
An issue in FME Modules fileuploads v.2.0.3 and before and fixed in v2.0.4 allows a remote attacker to obtain sensitive information via the uploadfiles.php component.
ModificadaAlta (8.8)0.26%—Infiniteuploads BIG File Uploads22/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Infinite Uploads Big File Uploads – Increase Maximum File Upload Size plugin <= 2.1.1 versions.
ModificadaAlta (8.3)0.49%—Troplo Privateuploader14/8/202317/6/2026
PrivateUploader is an open source image hosting server written in Vue and TypeScript. In affected versions `app/routes/v3/admin.controller.ts` did not correctly verify whether the user was an administrator (High Level) or moderator (Low Level) causing the request to continue processing. The response would be a 403…
ModificadaAlta (7.5)49%—Apache Commons FileuploadDebian Linux20/2/202317/6/2026
Apache Commons FileUpload before 1.5 does not limit the number of request parts to be processed resulting in the possibility of an attacker triggering a DoS with a malicious upload or series of uploads.
ModificadaAlta (7.5)1.4%—Express-fileupload Project Express-fileupload12/4/202217/6/2026
An arbitrary file write vulnerability in Express-FileUpload v1.3.1 allows attackers to upload multiple files with the same name, causing an overwrite of files in the web application server.
ModificadaCrítica (9.8)2.9%—Express-fileupload Project Express-fileupload12/4/202217/6/2026
An arbitrary file upload vulnerability in the file upload module of express-fileupload 1.3.1 allows attackers to execute arbitrary code via a crafted PHP file. NOTE: the vendor's position is that the observed behavior can only occur with "intentional misusing of the API": the express-fileupload middleware is not…
ModificadaMedia (6.1)0.84%—Pekeupload Project Pekeupload22/11/202117/6/2026
This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed.
ModificadaCrítica (9.8)4.8%—Express-fileupload Project Express-fileuploadNetapp MAX Data30/7/202017/6/2026
This affects the package express-fileupload before 1.1.8. If the parseNested option is enabled, sending a corrupt HTTP request can lead to denial of service or arbitrary code execution.
ModificadaCrítica (9.8)1.8%—Fineuploader Php-traditional-server19/11/201817/6/2026
Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2
ModificadaCrítica (9.8)34%—Apache Commons Fileupload25/10/201617/6/2026
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution
ModificadaAlta (7.5)36%—HP Icewall Identity ManagerHP Icewall SSO Agent OptionApache TomcatDebian Linux+24/7/201617/6/2026
The MultipartStream class in Apache Commons Fileupload before 1.3.2, as used in Apache Tomcat 7.x before 7.0.70, 8.x before 8.0.36, 8.5.x before 8.5.3, and 9.x before 9.0.0.M7 and other products, allows remote attackers to cause a denial of service (CPU consumption) via a long boundary string.
ModificadaAlta (7.5)83%—Oracle Retail ApplicationsApache Commons FileuploadApache Tomcat1/4/201417/6/2026
MultipartStream.java in Apache Commons FileUpload before 1.3.1, as used in Apache Tomcat, JBoss Web, and other products, allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted Content-Type header that bypasses a loop's intended exit conditions.
ModificadaBaja (3.3)0.68%—Apache Commons Fileupload15/3/201316/6/2026
The default configuration of javax.servlet.context.tempdir in Apache Commons FileUpload 1.0 through 1.2.2 uses the /tmp directory for uploaded files, which allows local users to overwrite arbitrary files via an unspecified symlink attack.
ModificadaMedia (6.8)4.8%—Wasen MOD Simplefileupload31/8/201216/6/2026
Multiple incomplete blacklist vulnerabilities in the Simple File Upload (mod_simplefileuploadv1.3) module before 1.3.5 for Joomla! allow remote attackers to execute arbitrary code by uploading a file with a (1) php5, (2) php6, or (3) double (e.g. .php.jpg) extension, then accessing it via a direct request to the file…
ModificadaMedia (6.8)0.59%—Skyarc AutotaggingSkyarc DuplicateentrySkyarc MailpackSkyarc Mtcms+13/11/201116/6/2026
Cross-site request forgery (CSRF) vulnerability in SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, allows remote attackers to hijack the authentication of arbitrary users for…
ModificadaMedia (5.5)1.1%—Skyarc AutotaggingSkyarc DuplicateentrySkyarc MailpackSkyarc Mtcms+13/11/201116/6/2026
SKYARC MTCMS before 5.252, and the MultiFileUploader 0.44 and earlier, DuplicateEntry 1.2 and earlier, MailPack 1.741 and earlier, and AutoTagging 0.08 and earlier plugins for Movable Type, uses weak permissions, which allows remote authenticated users to modify files and settings via unspecified vectors.
ModificadaAlta (9.3)4.0%—Aurigma Image Uploader Activex ControlPiczo Imageuploader425/3/200816/6/2026
Buffer overflow in a certain Aurigma ActiveX control in ImageUploader4.ocx 4.1.36.0, as used with Piczo (aka Pizco) and possibly other online services, allows remote attackers to execute arbitrary code via unspecified vectors, possibly involving a long Action property, a different CLSID than CVE-2008-0659.
ModificadaAlta (10)56%—Aurigma Image Uploader Activex ControlMyspaceuploader8/2/200816/6/2026
Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used in MySpace MySpaceUploader.ocx 1.0.0.4, allows remote attackers to execute arbitrary code via a long Action property.
ModificadaAlta (10)13%—Lycos Fileuploader.dll25/1/200816/6/2026
Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUploader Module allows remote attackers to execute arbitrary code via a long HandwriterFilename property value. NOTE: some of these details are obtained from third party information.
ModificadaAlta (7.5)2.7%—Frederic Tyndiuk Eupload31/7/200216/6/2026
eUpload 1.0 stores the password.txt password file in plaintext under the web document root, which allows remote attackers to overwrite arbitrary files by reading password.txt.