Vulnerabilities
Summary — last 7 days
New vulnerabilities2,541▼ 354 vs. last week
Critical / high1,344▲ 80 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
3 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Deferred | Critical (9.3) | 3.6% | — | BuilderengineAIElfinderAIJquery File UploadAI | 7/10/2025 | 6/17/2026 | An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuery File Upload plugin. The plugin fails to properly validate or restrict file types or locations during upload operations, allowing an attacker to upload a malicious .php… | |
| Modified | Critical (9.8) | 92% | — | Creative-solutions Creative Contact FormJquery File Upload Project Jquery File Upload | 2/8/2020 | 6/17/2026 | Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by… | |
| Modified | Critical (9.8) | 97% | — | Jquery File Upload Project Jquery File Upload | 10/11/2018 | 8/12/2026 | Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0 |