Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
267 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.5% | — | Backdropcms Backdrop CMS | 19/12/2019 | 17/6/2026 | An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing non-configuration scripts to potentially be uploaded… | |
| Modificada | Media (4.8) | 0.55% | — | Backdropcms Backdrop CMS | 19/12/2019 | 17/6/2026 | An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when configuring… | |
| Modificada | Media (4.8) | 0.55% | — | Backdropcms Backdrop CMS | 19/12/2019 | 17/6/2026 | An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying content type names in the content creation interface. An attacker could potentially craft a specialized content type name, then have an editor execute scripting when creating… | |
| Modificada | Alta (8.8) | 1.4% | — | Teardrop Project Teardrop | 10/10/2019 | 17/6/2026 | The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates. | |
| Modificada | Crítica (9.8) | 2.6% | — | Backdropcms Backdrop CMS | 8/8/2019 | 17/6/2026 | Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, potentially allowing non-configuration scripts to be uploaded to the server. (This attack is… | |
| Modificada | Media (6.1) | 0.79% | — | Backdropcms Backdrop Core | 8/8/2019 | 17/6/2026 | In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged in and uses the search functionality. (This issue is mitigated by the attacker needing permissions to create administrative menu links, such… | |
| Modificada | Media (6.1) | 0.85% | — | Backdropcms Backdrop | 8/8/2019 | 17/6/2026 | Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a specialized label, then have an administrator execute scripting when administering a layout. (This issue is mitigated by… | |
| Modificada | Alta (7.8) | 0.92% | — | Dropbox | 8/7/2019 | 17/6/2026 | Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process. | |
| Modificada | Media (5.5) | 0.96% | — | Dropbox Lepton | 23/4/2019 | 17/6/2026 | read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file. | |
| Modificada | Alta (7.8) | 0.98% | — | Dropbox Lepton | 23/4/2019 | 17/6/2026 | io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check of header payloads that may be… | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Alta (7.5) | 1.5% | — | Dropbear SSH Project Dropbear SSH | 21/3/2019 | 17/6/2026 | It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts. | |
| Modificada | Alta (7.5) | 9.7% | 💥 Exploit | Airdrop Project Airdrop | 15/3/2019 | 17/6/2026 | The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that makes many socket connections through a configured port. | |
| Modificada | Media (4.8) | 0.74% | — | Backdropcms Backdrop CMS | 20/12/2018 | 17/6/2026 | Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on blocks and layouts. that can result in Execution of JavaScript from an unexpected source.. This attack appear to be exploitable via A user must be directed to an affected page while… | |
| Modificada | Media (5.3) | 2.7% | — | Debian LinuxDropbear SSH Project Dropbear SSH | 21/8/2018 | 17/6/2026 | The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a similar issue to CVE-2018-15473 in an unrelated codebase. | |
| Modificada | Alta (7.5) | 1.4% | — | Netkilleradvancedtokenairdrop Project Netkilleradvancedtokenairdrop | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for NetkillerAdvancedTokenAirDrop, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 0.99% | — | Airdroppercryptics | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for AirdropperCryptics, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Baja (3.6) | 0.28% | — | Dropbox | 20/6/2018 | 17/6/2026 | An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that… | |
| Modificada | Baja (3.1) | 0.32% | — | Dropbox | 20/6/2018 | 17/6/2026 | An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjunction with the… | |
| Modificada | Media (6.4) | 0.43% | — | Dropbox | 13/6/2018 | 17/6/2026 | An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection mechanism is not used. In other words, an… | |
| Modificada | Media (5.5) | 1.2% | — | Dropbox Lepton | 11/6/2018 | 17/6/2026 | An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application crash) via a malformed file. | |
| Modificada | Alta (8.8) | 0.48% | — | Droppy Project Droppy | 31/5/2018 | 17/6/2026 | Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafted page that can send requests as the context of the currently logged in user. For example this means the malicious user could add a new admin account under his control and delete… | |
| Modificada | Media (5.3) | 5.8% | — | Dropbox SDK | 26/9/2017 | 17/6/2026 | Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack. | |
| Modificada | Media (6.1) | 1.5% | — | Wordpress Backup TO Dropbox Project Wordpress Backup TO Dropbox | 7/6/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress. | |
| Modificada | Media (4.7) | 0.32% | — | Dropbear SSH Project Dropbear SSHDebian Linux | 19/5/2017 | 17/6/2026 | Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are followed. |