Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

392 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)2.7%—Dotnetblogengine Blogengine.net21/6/201917/6/2026
BlogEngine.NET 3.3.7.0 and earlier allows XML External Entity Blind Injection, related to pingback.axd and BlogEngine.Core/Web/HttpHandlers/PingbackHandler.cs.
ModificadaAlta (7.2)1.3%—Dotcms18/6/201917/6/2026
dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsp.
ModificadaCrítica (9.8)3.4%—Godotengine Godot31/5/201917/6/2026
In Godot through 3.1, remote code execution is possible due to the deserialization policy not being applied correctly.
ModificadaMedia (4.9)1.3%—Dotcms23/5/201917/6/2026
dotCMS before 5.1.0 has a path traversal vulnerability exploitable by an administrator to create files. The vulnerability is caused by the insecure extraction of a ZIP archive.
ModificadaMedia (6.1)1.00%—Dotcms14/5/201917/6/2026
/servlets/ajax_file_upload?fieldName=binary3 in dotCMS 5.1.1 allows XSS and HTML Injection.
ModificadaMedia (6.1)1.1%—Dnnsoftware Dotnetnuke21/3/201917/6/2026
DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
ModificadaMedia (6.1)3.7%💥 ExploitDotcms7/3/201917/6/2026
dotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the html/portlet/ext/common/page_preview_popup.jsp hostname parameter.
ModificadaCrítica (9.1)2.1%—Druide Antidote4/3/201917/6/2026
Druide Antidote RX, HD, 8 before 8.05.2287, 9 before 9.5.3937 and 10 before 10.1.2147 allows remote attackers to steal NTLM hashes or perform SMB relay attacks upon a direct launch of the product, or upon an indirect launch via an integration such as Chrome, Firefox, Word, Outlook, etc. This occurs because the product…
ModificadaMedia (5.4)0.60%—Dotcms26/11/201817/6/2026
An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcms/dijit/image/image_tool.jsp.
ModificadaAlta (8.1)6.6%—Druide Antidote 924/9/201817/6/2026
Druide Antidote through 9.5.1 on Windows and Linux allows remote code execution through the update mechanism by leveraging use of HTTP to download installation packages.
ModificadaMedia (6.1)0.84%—Dotcms12/9/201817/6/2026
dotCMS V5.0.1 has XSS in the /html/portlet/ext/contentlet/image_tools/index.jsp fieldName and inode parameters.
ModificadaMedia (5.4)0.68%—Dotclear2/9/201817/6/2026
A cross-site scripting (XSS) vulnerability in inc/core/class.dc.core.php in the media manager in Dotclear through 2.14.1 allows remote authenticated users to upload HTML content containing an XSS payload with the file extension .ahtml.
ModificadaAlta (7.5)3.8%💥 PoCGodotengine Godot20/8/201817/6/2026
Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)Serialization functions (core/io/marshalls.cpp) that can result in DoS (packet of death), possible…
ModificadaAlta (7.8)1.6%—Jetbrains DotpeekJetbrains Resharper Ultimate13/8/201817/6/2026
JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data.
ModificadaMedia (5.5)10%—Dotnetzip.semverd Project Dotnetzip.semverd25/7/201817/6/2026
DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.
ModificadaAlta (8.1)6.5%—Dotcms24/7/201817/6/2026
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to arbitrary file upload. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, there are no checks on the types of files which the bundle contains. This…
ModificadaMedia (6.5)2.8%—Dotcms24/7/201817/6/2026
The dotCMS administration panel, versions 3.7.1 and earlier, "Push Publishing" feature in Enterprise Pro is vulnerable to path traversal. When "Bundle" tar.gz archives uploaded to the Push Publishing feature are decompressed, the filenames of its contents are not properly checked, allowing for writing files to…
ModificadaAlta (8.8)1.1%—Dotcms24/7/201817/6/2026
The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS administrator panel contains a cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and…
ModificadaAlta (7.8)1.5%—Yamldotnet Project Yamldotnet13/7/201817/6/2026
YamlDotNet version 4.3.2 and earlier contains a Insecure Direct Object Reference vulnerability in The default behavior of Deserializer.Deserialize() will deserialize user-controlled types in the line "currentType = Type.GetType(nodeEvent.Tag.Substring(1), throwOnError: false);" and blindly instantiates them. that can…
ModificadaCrítica (9.8)4.5%—Godoc GO DOC DOT ORG5/7/201817/6/2026
In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being fetched by gddo to cause a directory traversal and remote code execution.
ModificadaAlta (7.5)13%💥 ExploitDnnsoftware Dotnetnuke3/7/201817/6/2026
DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.
ModificadaMedia (6.1)0.80%—Multidots Advance Search FOR Woocommerce1/6/201817/6/2026
An issue was discovered in the MULTIDOTS Advance Search for WooCommerce plugin 1.0.9 and earlier for WordPress. This plugin is vulnerable to a stored Cross-site scripting (XSS) vulnerability. A non-authenticated user can save the plugin settings and inject malicious JavaScript code in the Custom CSS textarea field,…
ModificadaMedia (6.1)0.81%—Multidots Woocommerce Quick Reports1/6/201817/6/2026
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.
ModificadaMedia (6.5)0.53%—Multidots WOO Checkout FOR Digital Goods31/5/201817/6/2026
An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings. The function woo_checkout_settings_page in the file…
ModificadaMedia (6.5)0.53%—Multidots ADD Social Share Messenger Buttons Whatsapp AND Viber31/5/201817/6/2026
An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishing/social engineering), the attacker can change the plugin settings via wp-admin/admin-post.php…
Orbitaley — Vulnerabilidades