Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
160 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.0% | — | Bearadmin Project Bearadmin | 24/5/2018 | 17/6/2026 | An issue was discovered in BearAdmin 0.5. There is admin/admin_log/index.html?user_id= SQL injection because admin\controller\AdminLog.php constructs a MySQL query improperly. | |
| Modificada | Media (6.5) | 1.6% | — | Bearadmin Project Bearadmin | 24/5/2018 | 17/6/2026 | An issue was discovered in BearAdmin 0.5. Remote attackers can download arbitrary files via /admin/databack/download.html?name= directory traversal sequences, as demonstrated by name=../application/database.php to read the MySQL credentials in the configuration. | |
| Modificada | Crítica (9.8) | 3.8% | — | Mcafee Tunnelbear | 26/4/2018 | 17/6/2026 | TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service establishes a NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "OpenVPNConnect" method accepts a server… | |
| Modificada | Alta (7.8) | 1.6% | — | Smartbear Soapui | 19/2/2018 | 17/6/2026 | The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file. | |
| Modificada | Media (4.7) | 0.32% | — | Dropbear SSH Project Dropbear SSHDebian Linux | 19/5/2017 | 17/6/2026 | Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are followed. | |
| Modificada | Alta (8.8) | 5.7% | — | Dropbear SSH Project Dropbear SSHDebian LinuxNetapp H410c Firmware | 19/5/2017 | 17/6/2026 | The server in Dropbear before 2017.75 might allow post-authentication root remote code execution because of a double free in cleanup of TCP listeners when the -a option is enabled. | |
| Modificada | Media (6.1) | 1.0% | — | Smartbear Swagger-ui | 10/4/2017 | 17/6/2026 | Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section. | |
| Modificada | Media (5.5) | 0.49% | — | Dropbear SSH Project Dropbear SSH | 3/3/2017 | 17/6/2026 | The dbclient and server in Dropbear SSH before 2016.74, when compiled with DEBUG_TRACE, allows local users to read process memory via the -v argument, related to a failed remote ident. | |
| Modificada | Alta (8.8) | 4.3% | — | Dropbear SSH Project Dropbear SSH | 3/3/2017 | 17/6/2026 | The dbclient in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via a crafted (1) -m or (2) -c argument. | |
| Modificada | Crítica (9.8) | 5.8% | — | Dropbear SSH Project Dropbear SSH | 3/3/2017 | 17/6/2026 | The dropbearconvert command in Dropbear SSH before 2016.74 allows attackers to execute arbitrary code via a crafted OpenSSH key file. | |
| Modificada | Crítica (9.8) | 10% | — | Dropbear SSH Project Dropbear SSH | 3/3/2017 | 17/6/2026 | Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument. | |
| Modificada | Media (6.4) | 19% | 💥 Exploit | Dropbear SSH Project Dropbear SSH | 22/3/2016 | 17/6/2026 | CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-command restrictions via crafted X11 forwarding data. | |
| Modificada | Alta (7.5) | 2.3% | — | Fisher-price Smart TOY Bear | 4/2/2016 | 17/6/2026 | The API on Fisher-Price Smart Toy Bear devices allows remote attackers to obtain sensitive information or modify data by leveraging presence in an 802.11 network's coverage area and entering an account number. | |
| Modificada | Media (5.4) | 0.27% | — | Bearidlock Bear ID Lock | 16/10/2014 | 17/6/2026 | The Bear ID Lock (aka com.wBearIDLock) application 0.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Bearhugmedia Monster Makeup | 18/9/2014 | 17/6/2026 | The Monster Makeup (aka com.bearhugmedia.android_monster) application 1.0.0.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (9.3) | 7.7% | 💥 Exploit | Eviware SoapuiSmartbear Soapui | 25/1/2014 | 17/6/2026 | The WSDL/WADL import functionality in SoapUI before 4.6.4 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file. | |
| Modificada | Alta (7.8) | 2.5% | — | Gummybearstudios FTP Drive + Http Server | 25/11/2013 | 16/6/2026 | Directory traversal vulnerability in Gummy Bear Studios FTP Drive + HTTP Server 1.0.4 and earlier allows remote attackers to read arbitrary files via a ..%2f (encoded dot dot slash) in a GET request. | |
| Modificada | Media (5) | 5.7% | 💥 PoC | Dropbear SSH Project Dropbear SSH | 25/10/2013 | 16/6/2026 | Dropbear SSH Server before 2013.59 generates error messages for a failed logon attempt with different time delays depending on whether the user account exists, which allows remote attackers to discover valid usernames. | |
| Modificada | Media (5) | 6.4% | — | Dropbear SSH Project Dropbear SSH | 25/10/2013 | 16/6/2026 | The buf_decompress function in packet.c in Dropbear SSH Server before 2013.59 allows remote attackers to cause a denial of service (memory consumption) via a compressed packet that has a large size when it is decompressed. | |
| Modificada | Media (6.8) | 3.5% | 💥 Exploit | Bugbear Flatout | 15/9/2012 | 16/6/2026 | Buffer overflow in Bugbear Entertainment FlatOut 2005 allows user-assisted remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long string in the title field in a bed file. | |
| Modificada | Alta (7.1) | 6.5% | — | Dropbear SSH Project Dropbear SSHDebian Linux | 5/6/2012 | 16/6/2026 | Use-after-free vulnerability in Dropbear SSH Server 0.52 through 2012.54, when command restriction and public key authentication are enabled, allows remote authenticated users to execute arbitrary code and bypass command restrictions via multiple crafted command requests, related to "channels concurrency." | |
| Modificada | Media (4.3) | 1.2% | — | Joomlabear MOD Joomulus | 6/1/2010 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Joomulus (mod_joomulus) module 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the tagcloud parameter in a tags action to (1) tagcloud_ell.swf, (2) tagcloud_eng.swf, (3) tagcloud_por.swf, (4) tagcloud_rus.swf, and possibly (5)… | |
| Modificada | Alta (7.5) | 0.93% | 💥 Exploit | Bearrivernet.net I-pos Internet PAY Online Store | 10/6/2008 | 16/6/2026 | SQL injection vulnerability in index.asp in I-Pos Internet Pay Online Store 1.3 Beta and earlier allows remote attackers to execute arbitrary SQL commands via the item parameter. | |
| Modificada | Media (4.3) | 1.5% | 💥 Exploit | Brown Bear Software Calcium | 29/5/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Calcium40.pl in Brown Bear Software Calcium 3.10 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the CalendarName parameter in a ShowIt action. | |
| Modificada | Alta (7.5) | 2.2% | — | Dropbear SSH Project Dropbear SSH | 26/2/2007 | 16/6/2026 | dbclient in Dropbear SSH client before 0.49 does not sufficiently warn the user when it detects a hostkey mismatch, which might allow remote attackers to conduct man-in-the-middle attacks. |