Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.79% | — | Villatheme Dropshipping AND Fulfillment FOR Aliexpress AND Woocommerce | 14/10/2022 | 17/6/2026 | Sensitive Data Exposure in Villatheme ALD - AliExpress Dropshipping and Fulfillment for WooCommerce premium plugin <= 1.1.0 on WordPress. | |
| Modificada | Alta (7.5) | 1.5% | — | Dropbear SSH Project Dropbear SSHDebian Linux | 12/10/2022 | 17/6/2026 | An issue was discovered in Dropbear through 2020.81. Due to a non-RFC-compliant check of the available authentication methods in the client-side SSH code, it is possible for an SSH server to change the login process in its favor. This attack can bypass additional security measures such as FIDO2 tokens or SSH-Askpass.… | |
| Modificada | Alta (7.2) | 2.0% | 💥 PoC | Backdropcms Backdrop CMS | 7/10/2022 | 17/6/2026 | Backdrop CMS 1.22.0 has Unrestricted File Upload vulnerability via 'themes' that allows attackers to Remote Code Execution. Note: Third parties dispute this and argue that advanced permissions are required. | |
| Modificada | Media (5.4) | 0.50% | — | Inkdrop Markdown Nice | 9/9/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Markdown-Nice v1.8.22 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Community Posting field. | |
| Modificada | Media (5.3) | 0.62% | — | Backdropcms Backdrop CMS | 1/8/2022 | 9/7/2026 | An issue in the login and reset password functionality of Backdrop CMS v1.22.0 allows attackers to enumerate usernames via password reset requests and distinct responses returned based on usernames. | |
| Modificada | Media (4.8) | 0.59% | — | Pieforms Drag & Drop Builder | 8/6/2022 | 17/6/2026 | The Drag & Drop Builder, Human Face Detector, Pre-built Templates, Spam Protection, User Email Notifications & more! WordPress plugin before 1.4.9.4 does not sanitise and escape some of its form fields, which could allow high privilege users such as admin to perform Cross-Site Scripting attacks when unfiltered_html is… | |
| Modificada | Media (5.4) | 0.60% | — | Dropdown Menu Widget Project Dropdown Menu Widget | 4/4/2022 | 17/6/2026 | The Dropdown Menu Widget WordPress plugin through 1.9.7 does not have authorisation and CSRF checks when saving its settings, allowing low privilege users such as subscriber to update them. Due to the lack of sanitisation and escaping, it could also lead to Stored Cross-Site Scripting issues | |
| Modificada | Media (5.4) | 14% | 💥 Exploit | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 28/3/2022 | 17/6/2026 | The Drag and Drop Multiple File Upload WordPress plugin before 1.3.6.3 allows SVG files to be uploaded by default via the dnd_codedropz_upload AJAX action, which could lead to Stored Cross-Site Scripting issue | |
| Modificada | Alta (7.8) | 0.88% | — | Dropbox Lepton | 28/2/2022 | 17/6/2026 | Dropbox Lepton v1.2.1-185-g2a08b77 was discovered to contain a heap-buffer-overflow in the function aligned_dealloc():src/lepton/bitops.cc:108. | |
| Modificada | Media (5.4) | 0.62% | — | Backdropcms Backdrop | 15/2/2022 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the Add Link function of BackdropCMS v1.21.1 allows attackers to execute arbitrary web scripts or HTML. | |
| Modificada | Alta (8.8) | 1.8% | — | Backdropcms Backdrop | 3/2/2022 | 17/6/2026 | A Cross Site Request Forgery (CSRF) vulnerability exists in Backdrop CMS 1.20, which allows Remote Attackers to gain Remote Code Execution (RCE) on the Hosting Webserver via uploading a maliciously add-on with crafted PHP file. NOTE: the vendor disputes this because the attack requires a session cookie of a… | |
| Modificada | Media (5.4) | 0.57% | — | Dropouts AIR Share | 22/10/2021 | 17/6/2026 | Dropouts Technologies LLP Air Share v1.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the devicename parameter. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the devicename information. | |
| Modificada | Alta (7.5) | 1.7% | — | Dropouts Super Backup | 22/10/2021 | 17/6/2026 | Dropouts Technologies LLP Super Backup v2.0.5 was discovered to contain an issue in the path parameter of the `list` and `download` module which allows attackers to perform a directory traversal via a change to the path variable to request the local list command. | |
| Modificada | Media (6.1) | 0.74% | — | Dropouts Super Backup | 22/10/2021 | 17/6/2026 | Dropouts Technologies LLP Super Backup v2.0.5 was discovered to contain a cross-site scripting (XSS) vulnerability in the path parameter of the `list` and `download` module. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted GET request. | |
| Modificada | Media (6.1) | 0.74% | — | Dropouts AIR Share | 22/10/2021 | 17/6/2026 | Dropouts Technologies LLP Air Share v1.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the path parameter of the `list` and `download` exception-handling. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted GET request. | |
| Modificada | Media (6.1) | 0.90% | — | Webodid Dropdown AND Scrollable Text | 10/9/2021 | 17/6/2026 | The Dropdown and scrollable Text WordPress plugin is vulnerable to Reflected Cross-Site Scripting via the content parameter found in the ~/index.php file which allows attackers to inject arbitrary web scripts, in versions up to and including 2.0. | |
| Modificada | Alta (7.8) | 0.96% | — | Inkdrop | 28/6/2021 | 17/6/2026 | Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet containing an invalid iframe into Inkdrop. | |
| Modificada | Alta (8.1) | 1.9% | — | Dropbear SSH Project Dropbear SSH | 25/2/2021 | 17/6/2026 | scp.c in Dropbear before 2020.79 mishandles the filename of . or an empty filename, a related issue to CVE-2018-20685. | |
| Modificada | Media (5.3) | 1.2% | — | Dropbear SSH Project Dropbear SSH | 30/12/2020 | 17/6/2026 | Dropbear 2011.54 through 2018.76 has an inconsistent failure delay that may lead to revealing valid usernames, a different issue than CVE-2018-15599. | |
| Modificada | Crítica (9.8) | 3.0% | — | Eggheads Eggdrop Docker Image | 8/12/2020 | 17/6/2026 | The official eggdrop Docker images before 1.8.4rc2 contain a blank password for a root user. Systems using the Eggdrop Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access with a blank password. | |
| Modificada | Media (6.5) | 1.6% | — | Droppy Project Droppy | 2/11/2020 | 17/6/2026 | This affects all versions of package droppy. It is possible to traverse directories to fetch configuration files from a droopy server. | |
| Modificada | Crítica (9.8) | 79% | 💥 Exploit | Codedropz Drag AND Drop Multiple File Upload - Contact Form 7 | 8/6/2020 | 17/6/2026 | The drag-and-drop-multiple-file-upload-contact-form-7 plugin before 1.3.3.3 for WordPress allows Unrestricted File Upload and remote code execution by setting supported_type to php% and uploading a .php% file. | |
| Modificada | Alta (8.8) | 5.2% | — | Dropwizard Validation | 10/4/2020 | 17/6/2026 | dropwizard-validation before versions 2.0.3 and 1.3.21 has a remote code execution vulnerability. A server-side template injection was identified in the self-validating feature enabling attackers to inject arbitrary Java EL expressions, leading to Remote Code Execution (RCE) vulnerability. If you are using a… | |
| Modificada | Alta (8.8) | 3.0% | 💥 PoC | Dropwizard ValidationOracle Blockchain Platform | 24/2/2020 | 17/6/2026 | Dropwizard-Validation before 1.3.19, and 2.0.2 may allow arbitrary code execution on the host system, with the privileges of the Dropwizard service account, by injecting arbitrary Java Expression Language expressions when using the self-validating feature. The issue has been fixed in dropwizard-validation 1.3.19 and… | |
| Modificada | Media (4.8) | 0.55% | — | Backdropcms Backdrop CMS | 19/12/2019 | 17/6/2026 | An issue was discovered in Backdrop CMS 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying file type descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when viewing the list of file types, aka XSS.… |