Vulnerabilities

Summary — last 7 days

New vulnerabilities2,541▼ 354 vs. last week
Critical / high1,344▲ 80 vs. last week
New active exploitation (KEV)6▼ 5 vs. last week
Unscored (no CVSS)62▼ 466 vs. last week
–

3 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
DeferredCritical (9.3)3.6%—BuilderengineAIElfinderAIJquery File UploadAI7/10/20256/17/2026
An unrestricted file upload vulnerability exists in BuilderEngine 3.5.0 via the integration of the elFinder 2.0 file manager and its use of the jQuery File Upload plugin. The plugin fails to properly validate or restrict file types or locations during upload operations, allowing an attacker to upload a malicious .php…
ModifiedCritical (9.8)92%—Creative-solutions Creative Contact FormJquery File Upload Project Jquery File Upload2/8/20206/17/2026
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contact Form) before 1.0.0 for WordPress and before 2.0.1 for Joomla!, allows remote attackers to execute arbitrary code by…
ModifiedCritical (9.8)97%—Jquery File Upload Project Jquery File Upload10/11/20188/12/2026
Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0