Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

267 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)8.5%💥 ExploitEggheads EggdropEggheads Eggdrop IRC BOTPhilip Moore Windrop26/5/200916/6/2026
mod/server.mod/servmsg.c in Eggheads Eggdrop and Windrop 1.6.19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted PRIVMSG that causes an empty string to trigger a negative string length copy. NOTE: this issue exists because of an incorrect fix for CVE-2007-2807.
ModificadaAlta (7.5)3.5%—Battlefront Dropteam8/10/200716/6/2026
Multiple format string vulnerabilities in Battlefront Dropteam 1.3.3 and earlier allow remote attackers to execute arbitrary code via format string specifiers in the (1) username, (2) password, and (3) nickname fields in a "0x01" packet.
ModificadaAlta (7.5)4.2%—Battlefront Dropteam8/10/200716/6/2026
Multiple buffer overflows in Battlefront Dropteam 1.3.3 and earlier allow remote attackers to execute arbitrary code via (1) a crafted "0x5c" packet or (2) many 32-bit numbers in a "0x18" packet, or cause a denial of service (crash) via (3) a large "0x4b" packet.
ModificadaMedia (5)3.1%💥 ExploitBattlefront Dropteam8/10/200716/6/2026
Battlefront Dropteam 1.3.3 and earlier sends the client's online account name and password to the game server, which allows malicious game servers to steal account information.
ModificadaMedia (6.8)10.0%💥 ExploitEggheads Eggdrop IRC BOT22/5/200716/6/2026
Stack-based buffer overflow in mod/server.mod/servrmsg.c in Eggdrop 1.6.18, and possibly earlier, allows user-assisted, remote IRC servers to execute arbitrary code via a long private message.
ModificadaMedia (6.4)2.2%💥 ExploitDropafew11/4/200716/6/2026
DropAFew before 0.2.1 does not require authorization for certain privileged actions, which allows remote attackers to (1) view the logged calorie information of arbitrary users via the id parameter in editlogcal.php, (2) add arbitrary links via links.php, or (3) create arbitrary users via newaccount2.php.
ModificadaAlta (7.5)1.1%💥 ExploitDropafew11/4/200716/6/2026
Multiple SQL injection vulnerabilities in DropAFew before 0.2.1 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in the delete action in (a) search.php or (b) search-pda.php, or the (2) calories parameter in a save action in editlogcal.php.
ModificadaAlta (7.5)2.2%—Dropbear SSH Project Dropbear SSH26/2/200716/6/2026
dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to conduct man-in-the-middle attacks.
ModificadaAlta (7.5)1.2%—IAN Bezanson Dropbox16/2/200716/6/2026
Multiple unspecified vulnerabilities in Ian Bezanson DropBox before 0.0.4 beta have unknown impact and attack vectors, possibly related to a variable extraction vulnerability.
ModificadaMedia (6.5)0.94%💥 ExploitMichelle L2J Dropcalc3/2/200716/6/2026
SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users to execute arbitrary SQL commands via the itemid parameter.
ModificadaMedia (5)12%💥 ExploitDropbear SSH Project Dropbear SSH14/3/200616/6/2026
Matt Johnston Dropbear SSH server 0.47 and earlier, as used in embedded Linux devices and on general-purpose operating systems, allows remote attackers to cause a denial of service (connection slot exhaustion) via a large number of connection attempts that exceeds the MAX_UNAUTH_CLIENTS defined value of 30.
ModificadaMedia (6.5)3.4%—Dropbear SSH Project Dropbear SSHDebian Linux12/12/200516/6/2026
Buffer overflow in Dropbear server before 0.47 allows authenticated users to execute arbitrary code via unspecified inputs that cause insufficient memory to be allocated due to an incorrect expression that does not enforce the proper order of operations.
ModificadaAlta (7.5)5.0%💥 ExploitWineggdropshell4/12/200516/6/2026
Multiple buffer overflows in WinEggDropShell remote access trojan (RAT) 1.7 allow remote attackers to execute arbitrary code via (1) a long GET request to the HTTP server, or a long (2) USER or (3) PASS command to the FTP server.
ModificadaAlta (10)1.5%—Maildrop30/8/200516/6/2026
lockmail in maildrop before 1.5.3 does not drop privileges before executing commands, which allows local users to gain privileges via command line arguments.
ModificadaMedia (5)1.6%—Cisco ONS 15216 Optical ADD Drop Multiplexer Software18/7/200516/6/2026
Cisco ONS 15216 Optical Add/Drop Multiplexer (OADM) running firmware 2.2.2 and earlier allows remote attackers to cause a denial of service (management plane session loss) via crafted telnet data.
ModificadaAlta (7.5)3.0%—Dropbear SSH Project Dropbear SSH31/12/200416/6/2026
The DSS verification code in Dropbear SSH Server before 0.43 frees uninitialized variables, which might allow remote attackers to gain access.
ModificadaAlta (7.5)2.0%—Eggheads Eggdrop IRC BOT23/11/200416/6/2026
Share.mod in Eggheads Eggdrop IRC bot 1.6.10 through 1.6.15 can mistakenly assign STAT_OFFERED status to a bot that is not a sharebot, which allows remote attackers to use STAT_OFFERED to promote a bot to a sharebot and conduct unauthorized activities.
Orbitaley — Vulnerabilidades