Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Fastify Bearer-auth | 14/7/2022 | 17/6/2026 | @fastify/bearer-auth is a Fastify plugin to require bearer Authorization headers. @fastify/bearer-auth prior to versions 7.0.2 and 8.0.1 does not securely use crypto.timingSafeEqual. A malicious attacker could estimate the length of one valid bearer token. According to the corresponding RFC 6750, the bearer token has… | |
| Modificada | Media (6.1) | 1.5% | — | Smartbear Swagger-ui-dist | 11/3/2022 | 17/6/2026 | The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the… | |
| Modificada | Media (4.3) | 42% | 💥 PoC | Smartbear Swagger UI | 11/3/2022 | 17/6/2026 | Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this… | |
| Modificada | Media (6.1) | 0.78% | — | Smartbear Collaborator | 10/3/2022 | 9/7/2026 | SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack. | |
| Modificada | Crítica (9.8) | 2.1% | — | Beardev Joomsport | 6/7/2021 | 17/6/2026 | The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have a suitable gadget chain to exploit this,… | |
| Modificada | Media (5.5) | 0.54% | — | Taidii Diibear | 17/3/2021 | 17/6/2026 | The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and media files via logcat because of excessive logging. | |
| Modificada | Alta (7.8) | 0.24% | — | Taidii Diibear | 17/3/2021 | 17/6/2026 | The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Shared Preferences and the SQLite database because of insecure data storage. | |
| Modificada | Media (6.8) | 0.24% | — | Taidii Diibear | 17/3/2021 | 17/6/2026 | The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an Android backup because of insecure application configuration. | |
| Modificada | Media (5.5) | 0.28% | — | Smartbear Swagger-codegen | 11/3/2021 | 17/6/2026 | swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix-Like systems, the system temporary directory is shared between… | |
| Modificada | Alta (7) | 0.41% | — | Smartbear Swagger-codegen | 11/3/2021 | 17/6/2026 | swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix like systems, the system's temporary directory is shared… | |
| Modificada | Alta (8.1) | 1.9% | — | Dropbear SSH Project Dropbear SSH | 25/2/2021 | 17/6/2026 | scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685. | |
| Modificada | Alta (8.8) | 3.8% | — | Smartbear Collaborator | 11/1/2021 | 17/6/2026 | In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's UpdateMemento class accepts a serialized Java object directly from the user without properly sanitizing it. A malicious object can be… | |
| Modificada | Media (5.3) | 1.2% | — | Dropbear SSH Project Dropbear SSH | 30/12/2020 | 17/6/2026 | Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599. | |
| Modificada | Crítica (9.8) | 13% | — | Smartbear Readyapi | 20/5/2020 | 17/6/2026 | An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component. | |
| Modificada | Alta (7.5) | 2.2% | — | Iktm Bearftp | 12/2/2020 | 17/6/2026 | Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to achieve denial of service via a Slowloris approach by sending a large volume of small packets. | |
| Modificada | Crítica (9.8) | 75% | 💥 Exploit | Polarbear CMS Project Polarbear CMS | 11/2/2020 | 16/6/2026 | A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code. | |
| Modificada | Alta (7.8) | 4.8% | 💥 PoC | Smartbear ReadyapiSmartbear Soapui | 5/2/2020 | 17/6/2026 | An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allows an attacker to execute arbitrary Groovy Language code (Java scripting language) on the victim machine by inducing it to open a malicious… | |
| Modificada | Alta (7.5) | 14% | 💥 Exploit | Iktm Bearftp | 29/1/2020 | 17/6/2026 | IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to the PASV mode port. | |
| Modificada | Media (6.1) | 4.0% | 💥 PoC | Smartbear Swagger-uiRedhat Jboss FuseRedhat Openshift | 20/12/2019 | 17/6/2026 | swagger-ui has XSS in key names | |
| Modificada | Crítica (9.8) | 5.7% | 💥 PoC | Smartbear Swagger UIOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Platform+2 | 10/10/2019 | 17/6/2026 | A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of… | |
| Modificada | Media (6.1) | 5.7% | 💥 Exploit | API Bearer Auth Project API Bearer Auth | 15/9/2019 | 17/6/2026 | In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS. | |
| Modificada | Crítica (9.8) | 21% | 💥 Exploit | Beardev Joomsport | 5/8/2019 | 17/6/2026 | The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter. | |
| Modificada | Alta (8.8) | 9.8% | 💥 Exploit | Smartbear Readyapi | 3/5/2019 | 17/6/2026 | The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file. | |
| Modificada | Alta (7.5) | 1.5% | — | Dropbear SSH Project Dropbear SSH | 21/3/2019 | 17/6/2026 | It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts. | |
| Modificada | Media (5.3) | 2.7% | — | Debian LinuxDropbear SSH Project Dropbear SSH | 21/8/2018 | 17/6/2026 | The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a similar issue to CVE-2018-15473 in an unrelated codebase. |