Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 5.7% | — | Dropbear SSH Project Dropbear SSHDebian LinuxNetapp H410c Firmware | 19/5/2017 | 17/6/2026 | The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled. | |
| Modificada | Media (5.5) | 0.92% | — | Dropbox Lepton | 10/5/2017 | 17/6/2026 | Dropbox Lepton 1.2.1 allows DoS (SEGV and application crash) via a malformed lepton file because the code does not ensure setup of a correct number of threads. | |
| Modificada | Media (5.5) | 1.2% | — | Dropbox Lepton | 5/4/2017 | 17/6/2026 | The allocate_channel_framebuffer function in uncompressed_components.hh in Dropbox Lepton 1.2.1 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a malformed JPEG image. | |
| Modificada | Media (5.5) | 0.49% | — | Dropbear SSH Project Dropbear SSH | 3/3/2017 | 17/6/2026 | The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident. | |
| Modificada | Alta (8.8) | 4.3% | — | Dropbear SSH Project Dropbear SSH | 3/3/2017 | 17/6/2026 | The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument. | |
| Modificada | Crítica (9.8) | 5.8% | — | Dropbear SSH Project Dropbear SSH | 3/3/2017 | 17/6/2026 | The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file. | |
| Modificada | Crítica (9.8) | 10% | — | Dropbear SSH Project Dropbear SSH | 3/3/2017 | 17/6/2026 | Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument. | |
| Modificada | Media (6.4) | 19% | 💥 Exploit | Dropbear SSH Project Dropbear SSH | 22/3/2016 | 17/6/2026 | CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data. | |
| Modificada | Media (5.8) | 1.2% | — | Language Switcher Dropdown Project Language Switcher Dropdown | 6/7/2015 | 17/6/2026 | Open redirect vulnerability in the Language Switcher Dropdown module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in a block. | |
| Modificada | Media (5.4) | 0.27% | — | Lazyer Doodle Drop | 22/9/2014 | 17/6/2026 | The Doodle Drop (aka net.lazyer.DoodleDrop) application 1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5) | 5.7% | 💥 PoC | Dropbear SSH Project Dropbear SSH | 25/10/2013 | 16/6/2026 | Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames. | |
| Modificada | Media (5) | 6.4% | — | Dropbear SSH Project Dropbear SSH | 25/10/2013 | 16/6/2026 | The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial of service (memory consumption) via a compressed packet that has a large size when it is decompressed. | |
| Modificada | Media (6.8) | 4.2% | — | Cdsincdesign Simple Dropbox Upload Form | 30/9/2013 | 16/6/2026 | Unrestricted file upload vulnerability in multi.php in Simple Dropbox Upload plugin before 1.8.8.1 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/wpdb/. | |
| Modificada | Media (6.8) | 0.95% | — | Metin Saylan Dropdown Menu Widget | 12/7/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Dropdown Menu Widget plugin 1.9.1 for WordPress allows remote attackers to hijack the authentication of arbitrary users for requests that insert cross-site scripting (XSS) sequences. | |
| Modificada | Alta (7.5) | 1.1% | — | David Alkire Drag & Drop Gallery | 30/11/2012 | 16/6/2026 | SQL injection vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.8) | 0.57% | — | David Alkire Drag & Drop Gallery | 30/11/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to hijack the authentication of administrators. | |
| Modificada | Media (5) | 1.2% | — | David Alkire Drag & Drop Gallery | 30/11/2012 | 16/6/2026 | Unspecified vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to bypass access restrictions via unknown attack vectors. | |
| Modificada | Media (4.3) | 0.93% | — | David Alkire Drag & Drop Gallery | 30/11/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Drag & Drop Gallery module 6.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (5.1) | 1.4% | — | David Alkire Drag & Drop Gallery | 30/11/2012 | 16/6/2026 | Unrestricted file upload vulnerability in upload.php in the Drag & Drop Gallery module 6.x-1.5 and earlier for Drupal allows remote attackers to execute arbitrary PHP code by uploading a file with an executable extension followed by a safe extension, then accessing it via a direct request to the directory specified by… | |
| Modificada | Alta (7.1) | 6.5% | — | Dropbear SSH Project Dropbear SSHDebian Linux | 5/6/2012 | 16/6/2026 | Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows remote authenticated users to execute arbitrary code and bypass command restrictions via multiple crafted command requests, related to "channels concurrency." | |
| Modificada | Alta (7.5) | 1.4% | — | Jerome Schneider Ameos Dragndropupload | 4/10/2011 | 16/6/2026 | Unspecified vulnerability in the Drag Drop Mass Upload (ameos_dragndropupload) extension 2.0.2 and earlier for TYPO3 allows remote attackers to upload arbitrary files via unknown vectors. | |
| Modificada | Media (6.9) | 0.29% | — | Dropbox | 20/10/2010 | 16/6/2026 | dropboxd in Dropbox 0.7.110 places a zero-length directory name in the LD_LIBRARY_PATH, which allows local users to gain privileges via a Trojan horse shared library in the current working directory. | |
| Modificada | Media (6.9) | 0.42% | — | Maildrop | 4/2/2010 | 16/6/2026 | main.C in maildrop 2.3.0 and earlier, when run by root with the -d option, uses the gid of root for execution of the .mailfilter file in a user's home directory, which allows local users to gain privileges via a crafted file. | |
| Modificada | Alta (7.5) | 1.1% | — | Matthias Karr MK Anydropdownmenu | 15/1/2010 | 16/6/2026 | SQL injection vulnerability in the init function in MK-AnydropdownMenu (mk_anydropdownmenu) extension 0.3.28 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 2.3% | 💥 Exploit | Dragdropcart | 24/7/2009 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in DragDropCart allow remote attackers to inject arbitrary web script or HTML via the (1) sid parameter to assets/js/ddcart.php, the (2) prefix parameter to includes/ajax/getstate.php, the search parameter to (3) index.php and (4) search.php, the (5) redirect… |