Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.34% | — | Soapbox Project Soapbox | 24/1/2020 | 16/6/2026 | Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox. | |
| Modificada | Alta (7.5) | 6.0% | — | Shellinabox Project Shellinabox | 21/3/2019 | 17/6/2026 | libhttp/url.c in shellinabox through 2.20 has an implementation flaw in the HTTP request parsing logic. By sending a crafted multipart/form-data HTTP request, an attacker could exploit this to force shellinaboxd into an infinite loop, exhausting available CPU resources and taking the service down. | |
| Modificada | Alta (7.5) | 1.0% | — | Jaxbox Project Jaxbox | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for JaxBox, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (8.1) | 1.7% | — | Pk-app-wonderbox Project Pk-app-wonderbox | 4/6/2018 | 17/6/2026 | pk-app-wonderbox is an integration with wonderbox pk-app-wonderbox downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on the network or… | |
| Modificada | Media (5.5) | 0.97% | — | OX Project OX | 26/2/2018 | 17/6/2026 | In the Ox gem 2.8.1 for Ruby, the process crashes with a stack-based buffer over-read in the read_from_str function in sax_buf.c when a crafted input is supplied to sax_parse. | |
| Modificada | Media (6.1) | 1.1% | — | Geminabox Project Geminabox | 13/11/2017 | 17/6/2026 | Stored cross-site scripting (XSS) vulnerability in "geminabox" (Gem in a Box) before 0.13.10 allows attackers to inject arbitrary web script via the "homepage" value of a ".gemspec" file, related to views/gem.erb and views/index.erb. | |
| Modificada | Alta (7.5) | 1.7% | — | OX Project OX | 27/10/2017 | 17/6/2026 | In the Ox gem 2.8.0 for Ruby, the process crashes with a segmentation fault when a crafted input is supplied to parse_obj. NOTE: the vendor has stated "Ox should handle the error more gracefully" but has not confirmed a security implication. | |
| Modificada | Alta (8.8) | 0.50% | — | Geminabox Project Geminabox | 25/9/2017 | 17/6/2026 | geminabox (aka Gem in a Box) before 0.13.7 has CSRF, as demonstrated by an unintended gem upload. | |
| Modificada | Media (5.4) | 0.68% | — | Geminabox Project Geminabox | 25/9/2017 | 17/6/2026 | geminabox (aka Gem in a Box) before 0.13.6 has XSS, as demonstrated by uploading a gem file that has a crafted gem.homepage value in its .gemspec file. | |
| Modificada | Media (6.1) | 0.93% | — | Mapbox Project Mapbox | 17/7/2017 | 17/6/2026 | Mapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON Name. | |
| Modificada | Media (6.1) | 1.5% | — | Wordpress Backup TO Dropbox Project Wordpress Backup TO Dropbox | 7/6/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress. | |
| Modificada | Media (6.1) | 1.7% | — | Assist Project Assist PluginDatabox Project Databox PluginUserbox Project Userbox Plugin | 14/4/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for Geeklog allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.4) | 2.0% | — | Fedoraproject FedoraShellinabox Project Shellinabox | 12/1/2016 | 17/6/2026 | The HTTPS fallback implementation in Shell In A Box (aka shellinabox) before 2.19 makes it easier for remote attackers to conduct DNS rebinding attacks via the "/plain" URL. | |
| Modificada | Baja (3.5) | 0.87% | — | Colorbox Project Colorbox | 26/10/2015 | 17/6/2026 | The Colorbox module 7.x-2.x before 7.x-2.10 for Drupal allows remote authenticated users with certain permissions to bypass intended access restrictions and "add unexpected content to a Colorbox" via unspecified vectors, possibly related to a link in a comment. | |
| Modificada | Media (6.8) | 1.2% | — | Facebook Like BOX Project Facebook Like BOX | 5/1/2015 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in the Facebook Like Box (cardoza-facebook-like-box) plugin before 2.8.3 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings via unspecified vectors or conduct cross-site scripting… | |
| Modificada | Alta (10) | 3.5% | 💥 Exploit | Oxyproject Oxybox | 7/4/2009 | 16/6/2026 | Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbitrary PHP code into oxyhistory.php via the oxymsg parameter. |