Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
392 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Dnnsoftware Dotnetnuke | 2/6/2022 | 17/6/2026 | The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of possible attacks. In the most common… | |
| Modificada | Crítica (9.8) | 3.3% | — | Amazon Echo DOT Firmware | 24/2/2022 | 17/6/2026 | Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically proximate attackers), aka an "Alexa versus… | |
| Modificada | Crítica (9.8) | 2.1% | — | Skratchdot Object-path-set | 4/2/2022 | 17/6/2026 | The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-OBJECTPATHSET-607908 | |
| Modificada | Alta (7.5) | 0.53% | — | Transloadit Tusdotnet | 22/11/2021 | 17/6/2026 | The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content. | |
| Modificada | Alta (8.1) | 0.46% | — | Dotnetfoundation Piranha CMS | 16/11/2021 | 17/6/2026 | In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known. | |
| Modificada | Crítica (9.8) | 1.1% | — | Starkbank Ecdsa-dotnet | 9/11/2021 | 17/6/2026 | The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages. | |
| Modificada | Crítica (9.8) | 1.3% | — | Dotty Project Dotty | 3/11/2021 | 17/6/2026 | This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays. | |
| Modificada | Media (5.4) | 0.65% | — | Dotnetfoundation Piranha CMS | 25/10/2021 | 17/6/2026 | In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution. | |
| Modificada | Crítica (9.8) | 5.7% | — | Dotcms | 8/9/2021 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src/main/java/com/dotmarketing/filters/CMSFilter.java". | |
| Modificada | Alta (8.8) | 2.0% | — | Dotcms | 18/8/2021 | 17/6/2026 | Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files. | |
| Modificada | Media (4.2) | 0.28% | — | Amazon Echo DOT Firmware | 24/7/2021 | 17/6/2026 | Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks. NOTE: reportedly, there were vendor marketing statements about safely removing personal content via a… | |
| Modificada | Media (4.8) | 0.56% | — | Dotcms | 9/7/2021 | 17/6/2026 | A reflected cross site scripting (XSS) vulnerability in dotAdmin/#/c/links of dotCMS 21.05.1 allows attackers to execute arbitrary commands or HTML via a crafted payload. | |
| Modificada | Media (4.8) | 0.56% | — | Dotcms | 9/7/2021 | 17/6/2026 | A reflected cross site scripting (XSS) vulnerability in dotAdmin/#/c/containers of dotCMS 21.05.1 allows attackers to execute arbitrary commands or HTML via a crafted payload. | |
| Modificada | Media (4.8) | 0.50% | — | Dotcms | 9/7/2021 | 17/6/2026 | A stored cross site scripting (XSS) vulnerability in dotAdmin/#/c/c_Images of dotCMS 21.05.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' and 'Filename' parameters. | |
| Modificada | Media (5.4) | 0.84% | — | Dotcms | 23/4/2021 | 17/6/2026 | Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" component. | |
| Modificada | Crítica (9.8) | 2.0% | — | Ffmpegdotjs Project Ffmpegdotjs | 18/4/2021 | 17/6/2026 | This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization. | |
| Modificada | Alta (7.8) | 1.5% | — | Godotengine Godot Engine | 8/2/2021 | 17/6/2026 | A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA image files. Depending on the context of the application, attack vector can be local or remote, and can lead to code execution and/or system crash. | |
| Modificada | Alta (7.8) | 1.5% | — | Godotengine Godot Engine | 8/2/2021 | 17/6/2026 | An integer overflow issue exists in Godot Engine up to v3.2 that can be triggered when loading specially crafted.TGA image files. The vulnerability exists in ImageLoaderTGA::load_image() function at line: const size_t buffer_size = (tga_header.image_width * tga_header.image_height) * pixel_size; The bug leads to… | |
| Modificada | Crítica (9.8) | 3.3% | — | Dotty Project Dotty | 2/2/2021 | 17/6/2026 | Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code execution. | |
| Modificada | Alta (8.8) | 1.2% | — | Dotcms | 30/12/2020 | 17/6/2026 | dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection attacks. A user must be an authenticated… | |
| Modificada | Media (4.8) | 0.62% | — | Dotcms | 21/12/2020 | 9/7/2026 | DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a stored XSS attack and stealing cookies using XSS. | |
| Modificada | Alta (8.8) | 73% | 💥 Exploit | Flexdotnetcms Project Flexdotnetcms | 12/11/2020 | 17/6/2026 | An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or… | |
| Modificada | Alta (8.1) | 1.8% | — | Flexdotnetcms Project Flexdotnetcms | 12/11/2020 | 17/6/2026 | Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files outside the web root. The files can be accessed via directory traversal, i.e., by entering a .. (dot dot) path such as ..\..\..\..\..\<file>… | |
| Modificada | Alta (7.8) | 0.54% | — | Hindotech HK1 BOX S905x3 Firmware | 5/11/2020 | 17/6/2026 | The HK1 Box S905X3 TV Box contains a vulnerability that allows a local unprivileged user to escalate to root using the /system/xbin/su binary via a serial port (UART) connection or using adb. | |
| Modificada | Alta (7.5) | 1.1% | — | Dotplant2 | 18/9/2020 | 17/6/2026 | An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This vulnerability only affects products that are no… |