Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
–

392 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.1%—Dnnsoftware Dotnetnuke2/6/202217/6/2026
The AppCheck research team identified a Server-Side Request Forgery (SSRF) vulnerability within the DNN CMS platform, formerly known as DotNetNuke. SSRF vulnerabilities allow the attacker to exploit the target system to make network requests on their behalf, allowing a range of possible attacks. In the most common…
ModificadaCrítica (9.8)3.3%—Amazon Echo DOT Firmware24/2/202217/6/2026
Improper Neutralization of audio output from 3rd and 4th Generation Amazon Echo Dot devices allows arbitrary voice command execution on these devices via a malicious skill (in the case of remote attackers) or by pairing a malicious Bluetooth device (in the case of physically proximate attackers), aka an "Alexa versus…
ModificadaCrítica (9.8)2.1%—Skratchdot Object-path-set4/2/202217/6/2026
The package object-path-set before 1.0.2 are vulnerable to Prototype Pollution via the setPath method, as it allows an attacker to merge object prototypes into it. *Note:* This vulnerability derives from an incomplete fix in https://security.snyk.io/vuln/SNYK-JS-OBJECTPATHSET-607908
ModificadaAlta (7.5)0.53%—Transloadit Tusdotnet22/11/202117/6/2026
The client in tusdotnet through 2.5.0 relies on SHA-1 to prevent spoofing of file content.
ModificadaAlta (8.1)0.46%—Dotnetfoundation Piranha CMS16/11/202117/6/2026
In PiranhaCMS, versions 4.0.0-alpha1 to 9.2.0 are vulnerable to cross-site request forgery (CSRF) when performing various actions supported by the management system, such as deleting a user, deleting a role, editing a post, deleting a media folder etc., when an ID is known.
ModificadaCrítica (9.8)1.1%—Starkbank Ecdsa-dotnet9/11/202117/6/2026
The verify function in the Stark Bank .NET ECDSA library (ecdsa-dotnet) 1.3.1 fails to check that the signature is non-zero, which allows attackers to forge signatures on arbitrary messages.
ModificadaCrítica (9.8)1.3%—Dotty Project Dotty3/11/202117/6/2026
This affects the package dotty before 0.1.2. A type confusion vulnerability can lead to a bypass of CVE-2021-25912 when the user-provided keys used in the path parameter are arrays.
ModificadaMedia (5.4)0.65%—Dotnetfoundation Piranha CMS25/10/202117/6/2026
In PiranhaCMS, versions 7.0.0 to 9.1.1 are vulnerable to stored XSS due to the page title improperly sanitized. By creating a page with a specially crafted page title, a low privileged user can trigger arbitrary JavaScript execution.
ModificadaCrítica (9.8)5.7%—Dotcms8/9/202117/6/2026
Unrestricted Upload of File with Dangerous Type in DotCMS v5.2.3 and earlier allow remote attackers to execute arbitrary code via the component "/src/main/java/com/dotmarketing/filters/CMSFilter.java".
ModificadaAlta (8.8)2.0%—Dotcms18/8/202117/6/2026
Incorrect Access Control in DotCMS versions before 5.1 allows remote attackers to gain privileges by injecting client configurations via vtl (velocity) files.
ModificadaMedia (4.2)0.28%—Amazon Echo DOT Firmware24/7/202117/6/2026
Amazon Echo Dot devices through 2021-07-02 sometimes allow attackers, who have physical access to a device after a factory reset, to obtain sensitive information via a series of complex hardware and software attacks. NOTE: reportedly, there were vendor marketing statements about safely removing personal content via a…
ModificadaMedia (4.8)0.56%—Dotcms9/7/202117/6/2026
A reflected cross site scripting (XSS) vulnerability in dotAdmin/#/c/links of dotCMS 21.05.1 allows attackers to execute arbitrary commands or HTML via a crafted payload.
ModificadaMedia (4.8)0.56%—Dotcms9/7/202117/6/2026
A reflected cross site scripting (XSS) vulnerability in dotAdmin/#/c/containers of dotCMS 21.05.1 allows attackers to execute arbitrary commands or HTML via a crafted payload.
ModificadaMedia (4.8)0.50%—Dotcms9/7/202117/6/2026
A stored cross site scripting (XSS) vulnerability in dotAdmin/#/c/c_Images of dotCMS 21.05.1 allows authenticated attackers to execute arbitrary web scripts or HTML via a crafted payload entered into the 'Title' and 'Filename' parameters.
ModificadaMedia (5.4)0.84%—Dotcms23/4/202117/6/2026
Cross Site Scripting (XSS) in dotCMS v5.1.5 allows remote attackers to execute arbitrary code by injecting a malicious payload into the "Task Detail" comment window of the "/dotAdmin/#/c/workflow" component.
ModificadaCrítica (9.8)2.0%—Ffmpegdotjs Project Ffmpegdotjs18/4/202117/6/2026
This affects all versions of package ffmpegdotjs. If attacker-controlled user input is given to the trimvideo function, it is possible for an attacker to execute arbitrary commands. This is due to use of the child_process exec function without input sanitization.
ModificadaAlta (7.8)1.5%—Godotengine Godot Engine8/2/202117/6/2026
A stack overflow issue exists in Godot Engine up to v3.2 and is caused by improper boundary checks when loading .TGA image files. Depending on the context of the application, attack vector can be local or remote, and can lead to code execution and/or system crash.
ModificadaAlta (7.8)1.5%—Godotengine Godot Engine8/2/202117/6/2026
An integer overflow issue exists in Godot Engine up to v3.2 that can be triggered when loading specially crafted.TGA image files. The vulnerability exists in ImageLoaderTGA::load_image() function at line: const size_t buffer_size = (tga_header.image_width * tga_header.image_height) * pixel_size; The bug leads to…
ModificadaCrítica (9.8)3.3%—Dotty Project Dotty2/2/202117/6/2026
Prototype pollution vulnerability in 'dotty' versions 0.0.1 through 0.1.0 allows attackers to cause a denial of service and may lead to remote code execution.
ModificadaAlta (8.8)1.2%—Dotcms30/12/202017/6/2026
dotCMS before 20.10.1 allows SQL injection, as demonstrated by the /api/v1/containers orderby parameter. The PaginatorOrdered classes that are used to paginate results of a REST endpoints do not sanitize the orderBy parameter and in some cases it is vulnerable to SQL injection attacks. A user must be an authenticated…
ModificadaMedia (4.8)0.62%—Dotcms21/12/20209/7/2026
DotCMS Add Template with admin panel 20.11 is affected by cross-site Scripting (XSS) to gain remote privileges. An attacker could compromise the security of a website or web application through a stored XSS attack and stealing cookies using XSS.
ModificadaAlta (8.8)73%💥 ExploitFlexdotnetcms Project Flexdotnetcms12/11/202017/6/2026
An unrestricted file upload issue in FlexDotnetCMS before v1.5.9 allows an authenticated remote attacker to upload and execute arbitrary files by using the FileManager to upload malicious code (e.g., ASP code) in the form of a safe file type (e.g., a TXT file), and then using the FileEditor (in v1.5.8 and prior) or…
ModificadaAlta (8.1)1.8%—Flexdotnetcms Project Flexdotnetcms12/11/202017/6/2026
Incorrect Access Control in the FileEditor (/Admin/Views/FileEditor/) in FlexDotnetCMS before v1.5.11 allows an authenticated remote attacker to read and write to existing files outside the web root. The files can be accessed via directory traversal, i.e., by entering a .. (dot dot) path such as ..\..\..\..\..\<file>…
ModificadaAlta (7.8)0.54%—Hindotech HK1 BOX S905x3 Firmware5/11/202017/6/2026
The HK1 Box S905X3 TV Box contains a vulnerability that allows a local unprivileged user to escalate to root using the /system/xbin/su binary via a serial port (UART) connection or using adb.
ModificadaAlta (7.5)1.1%—Dotplant218/9/202017/6/2026
An issue was discovered in DotPlant2 before 2020-09-14. In class Pay2PayPayment in payment/Pay2PayPayment.php, there is an XXE vulnerability in the checkResult function. The user input ($_POST['xml']) is used for simplexml_load_string without sanitization. NOTE: This vulnerability only affects products that are no…
Orbitaley — Vulnerabilidades