Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 310 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.29% | — | Wpdeveloper Document Block Upload Embed DocsAI | 4/2/2025 | 17/6/2026 | Missing Authorization vulnerability in WPDeveloper Document Block – Upload & Embed Docs document.This issue affects Document Block – Upload & Embed Docs: from n/a through <= 1.1.0. | |
| Modificada | Crítica (9.8) | 1.2% | — | Ec-cube Product Image Bulk Upload | 27/9/2022 | 17/6/2026 | EC-CUBE plugin 'Product Image Bulk Upload Plugin' 1.0.0 and 4.1.0 contains an insufficient verification vulnerability when uploading files. Exploiting this vulnerability allows a remote unauthenticated attacker to upload arbitrary files other than image files. If a user with an administrative privilege of EC-CUBE… | |
| Modificada | Media (6.1) | 0.84% | — | Pekeupload Project Pekeupload | 22/11/2021 | 17/6/2026 | This affects all versions of package pekeupload. If an attacker induces a user to upload a file whose name contains javascript code, the javascript code will be executed. | |
| Modificada | Alta (8.8) | 1.5% | — | Raonwiz Raon K Upload | 5/8/2021 | 17/6/2026 | A vulnerability in File Transfer Solution of Raonwiz could allow arbitrary command execution as the result of viewing a specially-crafted web page. This vulnerability is due to insufficient validation of the parameter of the specific method. An attacker could exploit this vulnerability by setting the parameter to the… | |
| Modificada | Alta (7.8) | 0.28% | — | Raonwiz K Upload | 6/8/2020 | 17/6/2026 | MyBrowserPlus downloads the files needed to run the program through the setup file (Setup.inf). At this time, there is a vulnerability in downloading arbitrary files due to insufficient integrity verification of the files. | |
| Modificada | Crítica (9.8) | 1.2% | — | Raonwiz Raon K Upload | 10/7/2020 | 17/6/2026 | RAONWIZ v2018.0.2.50 and eariler versions contains a vulnerability that could allow remote files to be downloaded and excuted by lack of validation to file extension, witch can used as remote-code-excution attacks by hackers File download & execution vulnerability in ____COMPONENT____ of RAONWIZ RAON KUpload allows… | |
| Modificada | Media (4.3) | 0.69% | — | Jenkins Slack Upload | 2/7/2020 | 17/6/2026 | Jenkins Slack Upload Plugin 1.7 and earlier stores a secret unencrypted in job config.xml files on the Jenkins master where it can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Crítica (9.8) | 0.69% | — | Raonwiz Raon K Upload | 21/5/2020 | 17/6/2026 | In RAONWIZ K Upload v2018.0.2.51 and prior, automatic update processing without integrity check on update module(web.js) allows an attacker to modify arguments which causes downloading a random DLL and injection on it. | |
| Modificada | Media (6.1) | 1.3% | — | Webcraftic Simple 301 Redirects-addon-bulk Uploader | 29/8/2019 | 17/6/2026 | The simple-301-redirects-addon-bulk-uploader plugin before 1.2.5 for WordPress has no protection against 301 redirect rule injection via a CSV file. | |
| Modificada | Baja (3.5) | 1.0% | — | Ilya Ivanchenko Itweak Upload | 23/2/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the iTweak Upload module 6.x-1.x before 6.x-1.2 and 6.x-2.x before 6.x-2.3 for Drupal allows remote authenticated users, with create content and upload file permissions, to inject arbitrary web script or HTML via the file name of an uploaded file. |