Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

160 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.0%—Bearadmin Project Bearadmin24/5/201817/6/2026
An issue was discovered in BearAdmin 0.5. There is admin/admin_log/index.html?user_id= SQL injection because admin\controller\AdminLog.php constructs a MySQL query improperly.
ModificadaMedia (6.5)1.6%—Bearadmin Project Bearadmin24/5/201817/6/2026
An issue was discovered in BearAdmin 0.5. Remote attackers can download arbitrary files via /admin/databack/download.html?name= directory traversal sequences, as demonstrated by name=../application/database.php to read the MySQL credentials in the configuration.
ModificadaCrítica (9.8)3.8%—Mcafee Tunnelbear26/4/201817/6/2026
TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service establishes a NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "OpenVPNConnect" method accepts a server…
ModificadaAlta (7.8)1.6%—Smartbear Soapui19/2/201817/6/2026
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
ModificadaMedia (4.7)0.32%—Dropbear SSH Project Dropbear SSHDebian Linux19/5/201717/6/2026
Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are followed.
ModificadaAlta (8.8)5.7%—Dropbear SSH Project Dropbear SSHDebian LinuxNetapp H410c Firmware19/5/201717/6/2026
The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled.
ModificadaMedia (6.1)1.0%—Smartbear Swagger-ui10/4/201717/6/2026
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
ModificadaMedia (5.5)0.49%—Dropbear SSH Project Dropbear SSH3/3/201717/6/2026
The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident.
ModificadaAlta (8.8)4.3%—Dropbear SSH Project Dropbear SSH3/3/201717/6/2026
The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument.
ModificadaCrítica (9.8)5.8%—Dropbear SSH Project Dropbear SSH3/3/201717/6/2026
The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file.
ModificadaCrítica (9.8)10%—Dropbear SSH Project Dropbear SSH3/3/201717/6/2026
Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.
ModificadaMedia (6.4)19%💥 ExploitDropbear SSH Project Dropbear SSH22/3/201617/6/2026
CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data.
ModificadaAlta (7.5)2.3%—Fisher-price Smart TOY Bear4/2/201617/6/2026
The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 802.11 network's coverage area and entering an account number.
ModificadaMedia (5.4)0.27%—Bearidlock Bear ID Lock16/10/201417/6/2026
The Bear ID Lock (aka com.wBearIDLock) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Bearhugmedia Monster Makeup18/9/201417/6/2026
The Monster Makeup (aka com.bearhugmedia.android_monster) application 1.0.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (9.3)7.7%💥 ExploitEviware SoapuiSmartbear Soapui25/1/201417/6/2026
The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.
ModificadaAlta (7.8)2.5%—Gummybearstudios FTP Drive + Http Server25/11/201316/6/2026
Directory traversal vulnerability in Gummy Bear Studios FTP Drive + HTTP Server 1.0.4 and earlier allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request.
ModificadaMedia (5)5.7%💥 PoCDropbear SSH Project Dropbear SSH25/10/201316/6/2026
Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames.
ModificadaMedia (5)6.4%—Dropbear SSH Project Dropbear SSH25/10/201316/6/2026
The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial of service (memory consumption) via a compressed packet that has a large size when it is decompressed.
ModificadaMedia (6.8)3.5%💥 ExploitBugbear Flatout15/9/201216/6/2026
Buffer overflow in Bugbear Entertainment FlatOut 2005 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field in a bed file.
ModificadaAlta (7.1)6.5%—Dropbear SSH Project Dropbear SSHDebian Linux5/6/201216/6/2026
Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows remote authenticated users to execute arbitrary code and bypass command restrictions via multiple crafted command requests, related to "channels concurrency."
ModificadaMedia (4.3)1.2%—Joomlabear MOD Joomulus6/1/201016/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Joomulus (mod_joomulus) module 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action to (1) tagcloud_ell.swf, (2) tagcloud_eng.swf, (3) tagcloud_por.swf, (4) tagcloud_rus.swf, and possibly (5)…
ModificadaAlta (7.5)0.93%💥 ExploitBearrivernet.net I-pos Internet PAY Online Store10/6/200816/6/2026
SQL injection vulnerability in index.asp in I-Pos Internet Pay Online Store 1.3 Beta and earlier allows remote attackers to execute arbitrary SQL commands via the item parameter.
ModificadaMedia (4.3)1.5%💥 ExploitBrown Bear Software Calcium29/5/200816/6/2026
Cross-site scripting (XSS) vulnerability in Calcium40.pl in Brown Bear Software Calcium 3.10 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the CalendarName parameter in a ShowIt action.
ModificadaAlta (7.5)2.2%—Dropbear SSH Project Dropbear SSH26/2/200716/6/2026
dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to conduct man-in-the-middle attacks.
Orbitaley — Vulnerabilidades