Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.5%—Fastify Bearer-auth14/7/202217/6/2026
@fastify/bearer-auth is a Fastify plugin to require bearer Authorization headers. @fastify/bearer-auth prior to versions 7.0.2 and 8.0.1 does not securely use crypto.timingSafeEqual. A malicious attacker could estimate the length of one valid bearer token. According to the corresponding RFC 6750, the bearer token has…
ModificadaMedia (6.1)1.5%—Smartbear Swagger-ui-dist11/3/202217/6/2026
The swagger-ui-dist package before 4.1.3 for Node.js could allow a remote attacker to hijack the clicking action of the victim. By persuading a victim to visit a malicious Web site, a remote attacker could exploit this vulnerability to hijack the victim's click actions and possibly launch further attacks against the…
ModificadaMedia (4.3)42%💥 PoCSmartbear Swagger UI11/3/202217/6/2026
Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this…
ModificadaMedia (6.1)0.78%—Smartbear Collaborator10/3/20229/7/2026
SmartBear CodeCollaborator v6.1.6102 was discovered to contain a vulnerability in the web UI which would allow an attacker to conduct a clickjacking attack.
ModificadaCrítica (9.8)2.1%—Beardev Joomsport6/7/202117/6/2026
The joomsport_md_load AJAX action of the JoomSport WordPress plugin before 5.1.8, registered for both unauthenticated and unauthenticated users, unserialised user input from the shattr POST parameter, leading to a PHP Object Injection issue. Even though the plugin does not have a suitable gadget chain to exploit this,…
ModificadaMedia (5.5)0.54%—Taidii Diibear17/3/202117/6/2026
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to view private chat messages and media files via logcat because of excessive logging.
ModificadaAlta (7.8)0.24%—Taidii Diibear17/3/202117/6/2026
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from Shared Preferences and the SQLite database because of insecure data storage.
ModificadaMedia (6.8)0.24%—Taidii Diibear17/3/202117/6/2026
The Taidii Diibear Android application 2.4.0 and all its derivatives allow attackers to obtain user credentials from an Android backup because of insecure application configuration.
ModificadaMedia (5.5)0.28%—Smartbear Swagger-codegen11/3/202117/6/2026
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix-Like systems, the system temporary directory is shared between…
ModificadaAlta (7)0.41%—Smartbear Swagger-codegen11/3/202117/6/2026
swagger-codegen is an open-source project which contains a template-driven engine to generate documentation, API clients and server stubs in different languages by parsing your OpenAPI / Swagger definition. In swagger-codegen before version 2.4.19, on Unix like systems, the system's temporary directory is shared…
ModificadaAlta (8.1)1.9%—Dropbear SSH Project Dropbear SSH25/2/202117/6/2026
scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685.
ModificadaAlta (8.8)3.8%—Smartbear Collaborator11/1/202117/6/2026
In SmartBear Collaborator Server through 13.3.13302, use of the Google Web Toolkit (GWT) API introduces a post-authentication Java deserialization vulnerability. The application's UpdateMemento class accepts a serialized Java object directly from the user without properly sanitizing it. A malicious object can be…
ModificadaMedia (5.3)1.2%—Dropbear SSH Project Dropbear SSH30/12/202017/6/2026
Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599.
ModificadaCrítica (9.8)13%—Smartbear Readyapi20/5/202017/6/2026
An issue was discovered in SmartBear ReadyAPI SoapUI Pro 3.2.5. Due to unsafe use of an Java RMI based protocol in an unsafe configuration, an attacker can inject malicious serialized objects into the communication, resulting in remote code execution in the context of a client-side Network Licensing Protocol component.
ModificadaAlta (7.5)2.2%—Iktm Bearftp12/2/202017/6/2026
Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to achieve denial of service via a Slowloris approach by sending a large volume of small packets.
ModificadaCrítica (9.8)75%💥 ExploitPolarbear CMS Project Polarbear CMS11/2/202016/6/2026
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arbitrary code.
ModificadaAlta (7.8)4.8%💥 PoCSmartbear ReadyapiSmartbear Soapui5/2/202017/6/2026
An issue was discovered in SmartBear ReadyAPI through 2.8.2 and 3.0.0 and SoapUI through 5.5. When opening a project, the Groovy "Load Script" is automatically executed. This allows an attacker to execute arbitrary Groovy Language code (Java scripting language) on the victim machine by inducing it to open a malicious…
ModificadaAlta (7.5)14%💥 ExploitIktm Bearftp29/1/202017/6/2026
IKTeam BearFTP before 0.2.0 allows remote attackers to achieve denial of service via a large volume of connections to the PASV mode port.
ModificadaMedia (6.1)4.0%💥 PoCSmartbear Swagger-uiRedhat Jboss FuseRedhat Openshift20/12/201917/6/2026
swagger-ui has XSS in key names
ModificadaCrítica (9.8)5.7%💥 PoCSmartbear Swagger UIOracle Banking ApisOracle Banking Digital ExperienceOracle Banking Platform+210/10/201917/6/2026
A Cascading Style Sheets (CSS) injection vulnerability in Swagger UI before 3.23.11 allows attackers to use the Relative Path Overwrite (RPO) technique to perform CSS-based input field value exfiltration, such as exfiltration of a CSRF token value. In other words, this product intentionally allows the embedding of…
ModificadaMedia (6.1)5.7%💥 ExploitAPI Bearer Auth Project API Bearer Auth15/9/201917/6/2026
In the api-bearer-auth plugin before 20190907 for WordPress, the server parameter is not correctly filtered in the swagger-config.yaml.php file, and it is possible to inject JavaScript code, aka XSS.
ModificadaCrítica (9.8)21%💥 ExploitBeardev Joomsport5/8/201917/6/2026
The BearDev JoomSport plugin 3.3 for WordPress allows SQL injection to steal, modify, or delete database information via the joomsport_season/new-yorkers/?action=playerlist sid parameter.
ModificadaAlta (8.8)9.8%💥 ExploitSmartbear Readyapi3/5/201917/6/2026
The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
ModificadaAlta (7.5)1.5%—Dropbear SSH Project Dropbear SSH21/3/201917/6/2026
It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.
ModificadaMedia (5.3)2.7%—Debian LinuxDropbear SSH Project Dropbear SSH21/8/201817/6/2026
The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a similar issue to CVE-2018-15473 in an unrelated codebase.
Orbitaley — Vulnerabilidades