Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 2.7% | — | Dotnetblogengine Blogengine.net | 21/6/2019 | 17/6/2026 | BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs. | |
| Modificada | Alta (7.2) | 1.3% | — | Dotcms | 18/6/2019 | 17/6/2026 | dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsp. | |
| Modificada | Crítica (9.8) | 3.4% | — | Godotengine Godot | 31/5/2019 | 17/6/2026 | In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly. | |
| Modificada | Media (4.9) | 1.3% | — | Dotcms | 23/5/2019 | 17/6/2026 | dotCMS before 5.1.0 has a path traversal vulnerability exploitable by an administrator to create files. The vulnerability is caused by the insecure extraction of a ZIP archive. | |
| Modificada | Media (6.1) | 1.00% | — | Dotcms | 14/5/2019 | 17/6/2026 | /servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection. | |
| Modificada | Media (6.1) | 1.1% | — | Dnnsoftware Dotnetnuke | 21/3/2019 | 17/6/2026 | DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML. | |
| Modificada | Media (6.1) | 3.7% | 💥 Exploit | Dotcms | 7/3/2019 | 17/6/2026 | dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter. | |
| Modificada | Crítica (9.1) | 2.1% | — | Druide Antidote | 4/3/2019 | 17/6/2026 | Druide Antidote RX, HD, 8 before 8.05.2287, 9 before 9.5.3937 and 10 before 10.1.2147 allows remote attackers to steal NTLM hashes or perform SMB relay attacks upon a direct launch of the product, or upon an indirect launch via an integration such as Chrome, Firefox, Word, Outlook, etc. This occurs because the product… | |
| Modificada | Media (5.4) | 0.60% | — | Dotcms | 26/11/2018 | 17/6/2026 | An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcms/dijit/image/image_tool.jsp. | |
| Modificada | Alta (8.1) | 6.6% | — | Druide Antidote 9 | 24/9/2018 | 17/6/2026 | Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download installation packages. | |
| Modificada | Media (6.1) | 0.84% | — | Dotcms | 12/9/2018 | 17/6/2026 | dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters. | |
| Modificada | Media (5.4) | 0.68% | — | Dotclear | 2/9/2018 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml. | |
| Modificada | Alta (7.5) | 3.8% | 💥 PoC | Godotengine Godot | 20/8/2018 | 17/6/2026 | Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)Serialization functions (core/io/marshalls.cpp) that can result in DoS (packet of death), possible… | |
| Modificada | Alta (7.8) | 1.6% | — | Jetbrains DotpeekJetbrains Resharper Ultimate | 13/8/2018 | 17/6/2026 | JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data. | |
| Modificada | Media (5.5) | 10% | — | Dotnetzip.semverd Project Dotnetzip.semverd | 25/7/2018 | 17/6/2026 | DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'. | |
| Modificada | Alta (8.1) | 6.5% | — | Dotcms | 24/7/2018 | 17/6/2026 | The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, there are no checks on the types of files which the bundle contains. This… | |
| Modificada | Media (6.5) | 2.8% | — | Dotcms | 24/7/2018 | 17/6/2026 | The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to path traversal. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, the filenames of its contents are not properly checked, allowing for writing files to… | |
| Modificada | Alta (8.8) | 1.1% | — | Dotcms | 24/7/2018 | 17/6/2026 | The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS administrator panel contains a cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and… | |
| Modificada | Alta (7.8) | 1.5% | — | Yamldotnet Project Yamldotnet | 13/7/2018 | 17/6/2026 | YamlDotNet version 4.3.2 and earlier contains a Insecure Direct Object Reference vulnerability in The default behavior of Deserializer.Deserialize() will deserialize user-controlled types in the line "currentType = Type.GetType(nodeEvent.Tag.Substring(1), throwOnError: false);" and blindly instantiates them. that can… | |
| Modificada | Crítica (9.8) | 4.5% | — | Godoc GO DOC DOT ORG | 5/7/2018 | 17/6/2026 | In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being fetched by gddo to cause a directory traversal and remote code execution. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Dnnsoftware Dotnetnuke | 3/7/2018 | 17/6/2026 | DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources. | |
| Modificada | Media (6.1) | 0.80% | — | Multidots Advance Search FOR Woocommerce | 1/6/2018 | 17/6/2026 | An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plugin is vulnerable to a stored Cross-site scripting (XSS) vulnerability. A non-authenticated user can save the plugin settings and inject malicious JavaScript code in the Custom CSS textarea field,… | |
| Modificada | Media (6.1) | 0.81% | — | Multidots Woocommerce Quick Reports | 1/6/2018 | 17/6/2026 | The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order. | |
| Modificada | Media (6.5) | 0.53% | — | Multidots WOO Checkout FOR Digital Goods | 31/5/2018 | 17/6/2026 | An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings. The function woo_checkout_settings_page in the file… | |
| Modificada | Media (6.5) | 0.53% | — | Multidots ADD Social Share Messenger Buttons Whatsapp AND Viber | 31/5/2018 | 17/6/2026 | An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings via wp-admin/admin-post.php… |