Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

267 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)5.7%—Dropbear SSH Project Dropbear SSHDebian LinuxNetapp H410c Firmware19/5/201717/6/2026
The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled.
ModificadaMedia (5.5)0.92%—Dropbox Lepton10/5/201717/6/2026
Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads.
ModificadaMedia (5.5)1.2%—Dropbox Lepton5/4/201717/6/2026
The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed JPEG image.
ModificadaMedia (5.5)0.49%—Dropbear SSH Project Dropbear SSH3/3/201717/6/2026
The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident.
ModificadaAlta (8.8)4.3%—Dropbear SSH Project Dropbear SSH3/3/201717/6/2026
The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument.
ModificadaCrítica (9.8)5.8%—Dropbear SSH Project Dropbear SSH3/3/201717/6/2026
The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file.
ModificadaCrítica (9.8)10%—Dropbear SSH Project Dropbear SSH3/3/201717/6/2026
Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.
ModificadaMedia (6.4)19%💥 ExploitDropbear SSH Project Dropbear SSH22/3/201617/6/2026
CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data.
ModificadaMedia (5.8)1.2%—Language Switcher Dropdown Project Language Switcher Dropdown6/7/201517/6/2026
Open redirect vulnerability in the Language Switcher Dropdown module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a block.
ModificadaMedia (5.4)0.27%—Lazyer Doodle Drop22/9/201417/6/2026
The Doodle Drop (aka net.lazyer.DoodleDrop) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5)5.7%💥 PoCDropbear SSH Project Dropbear SSH25/10/201316/6/2026
Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.
ModificadaMedia (5)6.4%—Dropbear SSH Project Dropbear SSH25/10/201316/6/2026
The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial of service (memory consumption) via a compressed packet that has a large size when it is decompressed.
ModificadaMedia (6.8)4.2%—Cdsincdesign Simple Dropbox Upload Form30/9/201316/6/2026
Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/.
ModificadaMedia (6.8)0.95%—Metin Saylan Dropdown Menu Widget12/7/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in the Dropdown Menu Widget plugin 1.9.1 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences.
ModificadaAlta (7.5)1.1%—David Alkire Drag & Drop Gallery30/11/201216/6/2026
SQL injection vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (6.8)0.57%—David Alkire Drag & Drop Gallery30/11/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to hijack the authentication of administrators.
ModificadaMedia (5)1.2%—David Alkire Drag & Drop Gallery30/11/201216/6/2026
Unspecified vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to bypass access restrictions via unknown attack vectors.
ModificadaMedia (4.3)0.93%—David Alkire Drag & Drop Gallery30/11/201216/6/2026
Cross-site scripting (XSS) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5.1)1.4%—David Alkire Drag & Drop Gallery30/11/201216/6/2026
Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the directory specified by…
ModificadaAlta (7.1)6.5%—Dropbear SSH Project Dropbear SSHDebian Linux5/6/201216/6/2026
Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows remote authenticated users to execute arbitrary code and bypass command restrictions via multiple crafted command requests, related to "channels concurrency."
ModificadaAlta (7.5)1.4%—Jerome Schneider Ameos Dragndropupload4/10/201116/6/2026
Unspecified vulnerability in the Drag Drop Mass Upload (ameos_dragndropupload) extension 2.0.2 and earlier for TYPO3 allows remote attackers to upload arbitrary files via unknown vectors.
ModificadaMedia (6.9)0.29%—Dropbox20/10/201016/6/2026
dropboxd in Dropbox 0.7.110 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory.
ModificadaMedia (6.9)0.42%—Maildrop4/2/201016/6/2026
main.C in maildrop 2.3.0 and earlier, when run by root with the -d option, uses the gid of root for execution of the .mailfilter file in a user's home directory, which allows local users to gain privileges via a crafted file.
ModificadaAlta (7.5)1.1%—Matthias Karr MK Anydropdownmenu15/1/201016/6/2026
SQL injection vulnerability in the init function in MK-AnydropdownMenu (mk_anydropdownmenu) extension 0.3.28 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaMedia (4.3)2.3%💥 ExploitDragdropcart24/7/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to assets/js/ddcart.php, the (2) prefix parameter to includes/ajax/getstate.php, the search parameter to (3) index.php and (4) search.php, the (5) redirect…