Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

267 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)1.5%—Backdropcms Backdrop CMS19/12/201917/6/2026
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, allowing non-configuration scripts to potentially be uploaded…
ModificadaMedia (4.8)0.55%—Backdropcms Backdrop CMS19/12/201917/6/2026
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying certain block descriptions created by administrators. An attacker could potentially craft a specialized description, then have an administrator execute scripting when configuring…
ModificadaMedia (4.8)0.55%—Backdropcms Backdrop CMS19/12/201917/6/2026
An issue was discovered in Backdrop CMS 1.13.x before 1.13.5 and 1.14.x before 1.14.2. It doesn't sufficiently filter output when displaying content type names in the content creation interface. An attacker could potentially craft a specialized content type name, then have an editor execute scripting when creating…
ModificadaAlta (8.8)1.4%—Teardrop Project Teardrop10/10/201917/6/2026
The Teardrop theme 1.8.1 for WordPress has insufficient restrictions on option updates.
ModificadaCrítica (9.8)2.6%—Backdropcms Backdrop CMS8/8/201917/6/2026
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 allows the upload of entire-site configuration archives through the user interface or command line. It does not sufficiently check uploaded archives for invalid data, potentially allowing non-configuration scripts to be uploaded to the server. (This attack is…
ModificadaMedia (6.1)0.79%—Backdropcms Backdrop Core8/8/201917/6/2026
In Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3, some menu links within the administration bar may be crafted to execute JavaScript when the administrator is logged in and uses the search functionality. (This issue is mitigated by the attacker needing permissions to create administrative menu links, such…
ModificadaMedia (6.1)0.85%—Backdropcms Backdrop8/8/201917/6/2026
Backdrop CMS 1.12.x before 1.12.8 and 1.13.x before 1.13.3 doesn't sufficiently filter output when displaying certain block labels created by administrators. An attacker could potentially craft a specialized label, then have an administrator execute scripting when administering a layout. (This issue is mitigated by…
ModificadaAlta (7.8)0.92%—Dropbox8/7/201917/6/2026
Dropbox.exe (and QtWebEngineProcess.exe in the Web Helper) in the Dropbox desktop application 71.4.108.0 store cleartext credentials in memory upon successful login or new account creation. These are not securely freed in the running process.
ModificadaMedia (5.5)0.96%—Dropbox Lepton23/4/201917/6/2026
read_ujpg in jpgcoder.cc in Dropbox Lepton 1.2.1 allows attackers to cause a denial-of-service (application runtime crash because of an integer overflow) via a crafted file.
ModificadaAlta (7.8)0.98%—Dropbox Lepton23/4/201917/6/2026
io/ZlibCompression.cc in the decompression component in Dropbox Lepton 1.2.1 allows attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact by crafting a jpg image file. The root cause is a missing check of header payloads that may be…
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaAlta (7.5)1.5%—Dropbear SSH Project Dropbear SSH21/3/201917/6/2026
It was found that dropbear before version 2013.59 with GSSAPI leaks whether given username is valid or invalid. When an invalid username is given, the GSSAPI authentication failure was incorrectly counted towards the maximum allowed number of password attempts.
ModificadaAlta (7.5)9.7%💥 ExploitAirdrop Project Airdrop15/3/201917/6/2026
The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that makes many socket connections through a configured port.
ModificadaMedia (4.8)0.74%—Backdropcms Backdrop CMS20/12/201817/6/2026
Backdrop CMS version 1.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Sanitization of custom class names used on blocks and layouts. that can result in Execution of JavaScript from an unexpected source.. This attack appear to be exploitable via A user must be directed to an affected page while…
ModificadaMedia (5.3)2.7%—Debian LinuxDropbear SSH Project Dropbear SSH21/8/201817/6/2026
The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a similar issue to CVE-2018-15473 in an unrelated codebase.
ModificadaAlta (7.5)1.4%—Netkilleradvancedtokenairdrop Project Netkilleradvancedtokenairdrop9/7/201817/6/2026
The mintToken function of a smart contract implementation for NetkillerAdvancedTokenAirDrop, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)0.99%—Airdroppercryptics9/7/201817/6/2026
The mintToken function of a smart contract implementation for AirdropperCryptics, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaBaja (3.6)0.28%—Dropbox20/6/201817/6/2026
An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that…
ModificadaBaja (3.1)0.32%—Dropbox20/6/201817/6/2026
An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjunction with the…
ModificadaMedia (6.4)0.43%—Dropbox13/6/201817/6/2026
An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection mechanism is not used. In other words, an…
ModificadaMedia (5.5)1.2%—Dropbox Lepton11/6/201817/6/2026
An issue was discovered in Dropbox Lepton 1.2.1. The validateAndCompress function in validation.cc allows remote attackers to cause a denial of service (SIGFPE and application crash) via a malformed file.
ModificadaAlta (8.8)0.48%—Droppy Project Droppy31/5/201817/6/2026
Droppy versions <3.5.0 does not perform any verification for cross-domain websocket requests. An attacker is able to make a specially crafted page that can send requests as the context of the currently logged in user. For example this means the malicious user could add a new admin account under his control and delete…
ModificadaMedia (5.3)5.8%—Dropbox SDK26/9/201717/6/2026
Dropbox SDK for Android before 1.6.2 might allow remote attackers to obtain sensitive information via crafted malware or via a drive-by download attack.
ModificadaMedia (6.1)1.5%—Wordpress Backup TO Dropbox Project Wordpress Backup TO Dropbox7/6/201717/6/2026
Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress.
ModificadaMedia (4.7)0.32%—Dropbear SSH Project Dropbear SSHDebian Linux19/5/201717/6/2026
Dropbear before 2017.75 might allow local users to read certain files as root, if the file has the authorized_keys file format with a command= option. This occurs because ~/.ssh/authorized_keys is read with root privileges and symlinks are followed.
Orbitaley — Vulnerabilidades