Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.6) | 0.22% | — | Dropbox SamlyAI | 20/8/2026 | 24/8/2026 | Insufficient Verification of Data Authenticity vulnerability in dropbox samly allows an attacker to establish an authenticated session using a SAML response the service provider never requested. Samly.SPHandler.validate_authresp/3 in lib/samly/sp_handler.ex validates a SAML response for the SP-initiated flow by… | |
| Pendiente de análisis | Crítica (9.1) | 0.60% | — | Dropbox SamlyAI | 20/8/2026 | 24/8/2026 | Authentication Bypass by Capture-replay vulnerability in dropbox samly allows an attacker to authenticate as the subject of a captured SAML assertion by resubmitting it. Samly.Helper.decode_idp_auth_resp/3 in lib/samly/helper.ex calls esaml_sp:validate_assertion/2, whose default duplicate detector is a no-op. The /3… | |
| Aplazada | Crítica (9.3) | 0.35% | — | Easy Integration FOR DropboxAI | 4/8/2026 | 26/8/2026 | The Easy Integration for Dropbox WordPress plugin before 2.2.0 does not perform authorization checks on several of its file-management AJAX actions that it also registers for unauthenticated users, allowing an unauthenticated attacker to list, download and upload arbitrary files across the connected Dropbox account… | |
| Modificada | Media (6.3) | 0.45% | — | Arekinath EsamlDropbox EsamlHandnot2 EsamlJump-app Esaml | 23/3/2026 | 24/7/2026 | XML External Entity (XXE) vulnerability in esaml (and its forks) allows an attacker to cause the system to read local files and incorporate their contents into processed SAML documents, and potentially perform SSRF via crafted SAML messages. esaml parses attacker-controlled SAML messages using xmerl_scan:string/2… | |
| Aplazada | Alta (8.2) | 0.19% | — | Dropbox SignAI | 5/12/2024 | 17/6/2026 | User Interface (UI) Misrepresentation of Critical Information vulnerability in DropBox Sign(HelloSign) allows Content Spoofing. Displayed version does not show the layer flattened version, once download, If printed (e.g. via Google Chrome -> Examine the print preview): Will render the vulnerability only, not all… | |
| Modificada | Crítica (9.8) | 1.0% | 💥 PoC | Redwanhilali WP Dropbox Dropins | 20/10/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in redhopit WP Dropbox Dropins wp-dropbox-dropins allows Upload a Web Shell to a Web Server.This issue affects WP Dropbox Dropins: from n/a through <= 1.0. | |
| Aplazada | Alta (7.3) | 11% | — | Servmask All-in-one WP Migration BOX ExtensionAIServmask All-in-one WP Migration Onedrive ExtensionAIServmask All-in-one WP Migration Dropbox ExtensionAIServmask All-in-one WP Migration Google Drive ExtensionAI | 19/6/2024 | 17/6/2026 | Missing Authorization vulnerability in ServMask All-in-One WP Migration Box Extension, ServMask All-in-One WP Migration OneDrive Extension, ServMask All-in-One WP Migration Dropbox Extension, ServMask All-in-One WP Migration Google Drive Extension.This issue affects All-in-One WP Migration Box Extension: from n/a… | |
| Analizada | Alta (8.8) | 1.2% | — | Dropbox Desktop | 13/6/2024 | 17/6/2026 | Dropbox Desktop Folder Sharing Mark-of-the-Web Bypass Vulnerability. This vulnerability allows remote attackers to bypass the Mark-of-the-Web protection mechanism on affected installations of Dropbox Desktop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or… | |
| Modificada | Crítica (9.8) | 0.66% | — | Dropbox Samly | 11/2/2024 | 17/6/2026 | In the Samly package before 1.4.0 for Elixir, Samly.State.Store.get_assertion/3 can return an expired session, which interferes with access control because Samly.AuthHandler uses a cached session and does not replace it, even after expiry. | |
| Modificada | Crítica (9.8) | 1.1% | — | Hynotech Dropbox Folder Share | 20/10/2023 | 17/6/2026 | The Dropbox Folder Share for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 1.9.7 via the editor-view.php file. This allows unauthenticated attackers to include and execute arbitrary files on the server, allowing the execution of any PHP code in those files. This can be used to… | |
| Modificada | Alta (7.2) | 0.45% | — | Hynotech Dropbox Folder Share | 16/9/2023 | 17/6/2026 | The Dropbox Folder Share plugin for WordPress is vulnerable to Server-Side Request Forgery in versions up to, and including, 1.9.7 via the 'link' parameter. This can allow unauthenticated attackers to make web requests to arbitrary locations originating from the web application and can be used to query and modify… | |
| Modificada | Crítica (9.8) | 0.70% | — | Dropbox Merou | 27/12/2022 | 17/6/2026 | A vulnerability was found in Dropbox merou. It has been classified as critical. Affected is the function add_public_key of the file grouper/public_key.py of the component SSH Public Key Handler. The manipulation of the argument public_key_str leads to injection. It is possible to launch the attack remotely. The name… | |
| Modificada | Alta (7.8) | 0.88% | — | Dropbox Lepton | 28/2/2022 | 17/6/2026 | Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108. | |
| Modificada | Alta (7.8) | 0.92% | — | Dropbox | 8/7/2019 | 17/6/2026 | Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process. | |
| Modificada | Media (5.5) | 0.96% | — | Dropbox Lepton | 23/4/2019 | 17/6/2026 | read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file. | |
| Modificada | Alta (7.8) | 0.98% | — | Dropbox Lepton | 23/4/2019 | 17/6/2026 | io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check of header payloads that may be… | |
| Modificada | Baja (3.6) | 0.28% | — | Dropbox | 20/6/2018 | 17/6/2026 | An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that… | |
| Modificada | Baja (3.1) | 0.32% | — | Dropbox | 20/6/2018 | 17/6/2026 | An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjunction with the… | |
| Modificada | Media (6.4) | 0.43% | — | Dropbox | 13/6/2018 | 17/6/2026 | An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection mechanism is not used. In other words, an… | |
| Modificada | Media (5.5) | 1.2% | — | Dropbox Lepton | 11/6/2018 | 17/6/2026 | An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application crash) via a malformed file. | |
| Modificada | Media (5.3) | 5.8% | — | Dropbox SDK | 26/9/2017 | 17/6/2026 | Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack. | |
| Modificada | Media (6.1) | 1.5% | — | Wordpress Backup TO Dropbox Project Wordpress Backup TO Dropbox | 7/6/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress. | |
| Modificada | Media (5.5) | 0.92% | — | Dropbox Lepton | 10/5/2017 | 17/6/2026 | Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads. | |
| Modificada | Media (5.5) | 1.2% | — | Dropbox Lepton | 5/4/2017 | 17/6/2026 | The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed JPEG image. | |
| Modificada | Media (6.8) | 4.2% | — | Cdsincdesign Simple Dropbox Upload Form | 30/9/2013 | 16/6/2026 | Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/. |