Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.84% | — | Opendolphin | 15/11/2018 | 17/6/2026 | OpenDolphin 2.7.0 and earlier allows authenticated attackers to bypass authentication to create and/or delete other users accounts via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.0% | — | Opendolphin | 15/11/2018 | 17/6/2026 | OpenDolphin 2.7.0 and earlier allows authenticated attackers to obtain other users credentials such as a user ID and/or its password via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.3% | — | Opendolphin | 15/11/2018 | 17/6/2026 | OpenDolphin 2.7.0 and earlier allows authenticated users to gain administrative privileges and perform unintended operations. | |
| Modificada | Media (5.3) | 0.85% | — | Changyou Dolphin | 12/12/2017 | 17/6/2026 | The Dolphin Browser for Android 12.0.2 suffers from an insecure parsing implementation of the Intent URI scheme. This vulnerability could allow attackers to abuse this implementation through a malicious Intent URI, in order to invoke private Activities within the Dolphin Browser. | |
| Modificada | Alta (8.8) | 0.96% | — | Changyou Dolphin | 11/12/2017 | 17/6/2026 | The Backup and Restore feature in Mobotap Dolphin Browser for Android 12.0.2 suffers from an arbitrary file write vulnerability when attempting to restore browser settings from a malicious Dolphin Browser backup file. This arbitrary file write vulnerability allows an attacker to overwrite a specific executable in the… | |
| Modificada | Media (5.9) | 0.63% | — | Changyou Dolphin WEB Browser | 15/5/2017 | 17/6/2026 | The MoboTap Dolphin Web Browser - Fast Private Internet Search app 9.23.0 through 9.23.2 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 0.94% | — | Boonex Dolphin | 19/6/2014 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in administration/profiles.php in Dolphin 7.1.4 and earlier allows remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the members[] parameter, related to CVE-2014-3810. | |
| Modificada | Media (6.5) | 1.7% | — | Boonex Dolphin | 19/6/2014 | 17/6/2026 | SQL injection vulnerability in administration/profiles.php in BoonEx Dolphin 7.1.4 and earlier allows remote authenticated administrators to execute arbitrary SQL commands via the members[] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-4333. | |
| Modificada | Media (4.3) | 1.1% | — | Dolphin-browser Dolphin Browser HDDolphin-browser Dolphin FOR PAD | 15/6/2012 | 16/6/2026 | The Dolphin Browser HD application before 7.6 and Dolphin for Pad application before 1.0.1 for Android do not properly implement the WebView class, which allows remote attackers to obtain sensitive information via a crafted application. | |
| Modificada | Alta (10) | 1.4% | — | Dolphin-browser Dolphin Browser Mini | 7/3/2012 | 16/6/2026 | Unspecified vulnerability in the Dolphin Browser Mini (com.dolphin.browser) application 2.2 for Android has unknown impact and attack vectors. | |
| Modificada | Alta (10) | 1.4% | — | Dolphin-browser Dolphin Browser CN | 7/3/2012 | 16/6/2026 | Unspecified vulnerability in the Dolphin Browser CN (com.dolphin.browser.cn) application 6.3.1 and 7.2.1 for Android has unknown impact and attack vectors. | |
| Modificada | Alta (10) | 1.4% | — | Dolphin-browser Dolphin Browser HD | 7/3/2012 | 16/6/2026 | Unspecified vulnerability in the Dolphin Browser HD (mobi.mgeek.TunnyBrowser) application 6.2.0, 7.2.1, 7.3.0, and 7.4.0 for Android has unknown impact and attack vectors. | |
| Modificada | Media (4.3) | 4.3% | 💥 Exploit | Boonex Dolphin | 23/2/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Boonex Dolphin before 7.0.8 allow remote attackers to inject arbitrary web script or HTML via the (1) explain parameter to explanation.php or the (2) photos_only, (3) online_only, or (4) mode parameters to viewFriends.php. | |
| Modificada | Media (5) | 1.2% | — | Boonex Dolphin | 23/9/2011 | 16/6/2026 | Dolphin 7.0.4 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by xmlrpc/BxDolXMLRPCProfileView.php and certain other files. | |
| Modificada | Media (5) | 1.2% | — | Dolphin Browser | 6/5/2010 | 16/6/2026 | Dolphin Browser 2.5.0 on the HTC Hero allows remote attackers to cause a denial of service (application crash) via JavaScript that writes <marquee> sequences in an infinite loop. | |
| Modificada | Media (5) | 3.1% | 💥 Exploit | Attachmax Dolphin | 24/9/2008 | 16/6/2026 | Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers to obtain sensitive information via a direct request, which invokes the phpinfo function. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 3.0% | 💥 Exploit | Attachmax Dolphin | 24/9/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rel_path parameter. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Attachmax Dolphin | 24/9/2008 | 16/6/2026 | SQL injection vulnerability in search.php Attachmax Dolphin 2.1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the category parameter in a Search action to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (9.3) | 6.5% | 💥 Exploit | Boonex Dolphin | 14/7/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the (1) dir[plugins] parameter to (a) HTMLSax3.php and (b) safehtml.php in plugins/safehtml/ and the (2) sIncPath parameter to (c)… | |
| Modificada | Media (5.1) | 1.5% | — | Boonex Dolphin | 20/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in templates/tmpl_dfl/scripts/index.php in BoonEx Dolphin 5.2 allows remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter. NOTE: it is possible that this issue overlaps CVE-2006-4189. | |
| Modificada | Media (5.1) | 6.3% | — | Boonex Dolphin | 17/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Dolphin 5.1 allow remote attackers to execute arbitrary PHP code via a URL in the dir[inc] parameter in (1) index.php, (2) aemodule.php, (3) browse.php, (4) cc.php, (5) click.php, (6) faq.php, (7) gallery.php, (8) im.php, (9) inbox.php, (10) join_form.php, (11)… |