Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
50 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Shadowsock Project Shadowsock | 7/6/2018 | 17/6/2026 | shadowsock was a malicious module published with the intent to hijack environment variables. It has been unpublished by npm. | |
| Modificada | Media (5.3) | 1.6% | — | Shadow Project Shadow | 15/2/2018 | 17/6/2026 | An issue was discovered in shadow 4.5. newgidmap (in shadow-utils) is setuid and allows an unprivileged user to be placed in a user namespace where setgroups(2) is permitted. This allows an attacker to remove themselves from a supplementary group, which may allow access to certain filesystem paths if the administrator… | |
| Modificada | Alta (7.8) | 1.3% | — | Shadowsocks-libevDebian Linux | 27/10/2017 | 17/6/2026 | In manager.c in ss-manager in shadowsocks-libev 3.1.0, improper parsing allows command injection via shell metacharacters in a JSON configuration request received via 127.0.0.1 UDP traffic, related to the add_server, build_config, and construct_command_line functions. | |
| Modificada | Crítica (9.8) | 2.7% | — | Shadow Project ShadowDebian Linux | 4/8/2017 | 17/6/2026 | In shadow before 4.5, the newusers tool could be made to manipulate internal data structures in ways unintended by the authors. Malformed input may lead to crashes (with a buffer overflow or other memory corruption) or other unspecified behaviors. This crosses a privilege boundary in, for example, certain web-hosting… | |
| Modificada | Alta (7.8) | 0.41% | — | Shadow Project Shadow | 17/2/2017 | 17/6/2026 | Integer overflow in shadow 4.2.1 allows local users to gain privileges via crafted input to newuidmap. | |
| Modificada | Media (6.4) | 2.3% | — | Debian Shadow | 19/2/2011 | 16/6/2026 | Multiple CRLF injection vulnerabilities in (1) chfn and (2) chsh in shadow 1:4.1.4 allow local users to add new users or groups to /etc/passwd via the GECOS field. | |
| Modificada | Media (4) | 2.2% | — | Digital Extreme PariahEpic Games Unreal TournamentGroove Games WarpathHuman Head Studios Dead Mans Hand+2 | 19/8/2009 | 16/6/2026 | The Unreal engine, as used in Unreal Tournament 3 1.3, Unreal Tournament 2003 and 2004, Dead Man's Hand, Pariah, WarPath, Postal2, and Shadow Ops, allows remote authenticated users to cause a denial of service (server exit) via multiple file downloads from the server, which triggers an assertion failure when the… | |
| Modificada | Alta (9.3) | 5.8% | — | Mini-stream Shadow Stream Recorder | 17/4/2009 | 16/6/2026 | Stack-based buffer overflow in Mini-stream Shadow Stream Recorder 3.0.1.7 allows remote attackers to execute arbitrary code via a long URI in a playlist (.m3u) file. | |
| Modificada | Alta (7.2) | 0.95% | — | Debian Shadow | 9/12/2008 | 16/6/2026 | /bin/login in shadow 4.0.18.1 in Debian GNU/Linux, and probably other Linux distributions, allows local users in the utmp group to overwrite arbitrary files via a symlink attack on a temporary file referenced in a line (aka ut_line) field in a utmp entry. | |
| Modificada | Alta (7.5) | 2.9% | — | Shadowed Works Shadowed Portal | 31/12/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 allows remote attackers to execute arbitrary PHP code via a URL in the mod_root parameter. | |
| Modificada | Alta (7.5) | 7.0% | — | Shadowed Portal | 19/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter in (1) footer.php and (2) header.php. NOTE: the provenance of this information is unknown; the details are obtained from third party information. The… | |
| Modificada | Alta (7.5) | 9.5% | — | Shadowed Portal | 15/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in bottom.php in Shadowed Portal 5.599 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. | |
| Modificada | Media (5.1) | 3.4% | — | Premod Shadow | 9/9/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/functions_portal.php in Premod Shadow 2.7.1 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the phpbb_root_path parameter. | |
| Modificada | Alta (7.5) | 8.0% | — | Shadows Rising RPG | 24/8/2006 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[gameroot] parameter to (1) core/includes/security.inc.php, (2) core/includes/smarty.inc.php, (3) qcms/includes/smarty.inc.php or (4)… | |
| Modificada | Baja (3.7) | 0.44% | — | Debian Shadow | 28/5/2006 | 16/6/2026 | useradd in shadow-utils before 4.0.3, and possibly other versions before 4.0.8, does not provide a required argument to the open function when creating a new user mailbox, which causes the mailbox to be created with unpredictable permissions and possibly allows attackers to read or modify the mailbox. | |
| Modificada | Baja (2.1) | 0.34% | — | Debian Base-configDebian Shadow | 19/4/2006 | 16/6/2026 | The Debian installer for the (1) shadow 4.0.14 and (2) base-config 2.53.10 packages includes sensitive information in world-readable log files, including preseeded passwords and pppoeconf passwords, which might allow local users to gain privileges. | |
| Modificada | Baja (2.6) | 2.0% | — | Shadowed Portal | 11/4/2006 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Pages module in Shadowed Portal allows remote attackers to inject arbitrary web script or HTML via the page parameter to load.php. | |
| Modificada | Alta (7.5) | 2.4% | — | MOD Auth Shadow | 13/10/2005 | 16/6/2026 | The mod_auth_shadow module 1.0 through 1.5 and 2.0 for Apache with AuthShadow enabled uses shadow authentication for all locations that use the require group directive, even when other authentication mechanisms are specified, which might allow remote authenticated users to bypass security restrictions. | |
| Modificada | Media (5) | 1.7% | — | Funlabs 4X4 Off-road Adventure IIIFunlabs Cabelas BIG Game Hunter 2004 SeasonFunlabs Cabelas BIG Game Hunter 2005Funlabs Cabelas Dangerous Hunts+5 | 2/5/2005 | 16/6/2026 | Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service (crash from invalid memory access) via a malformed join packet with values that… | |
| Modificada | Media (5) | 3.1% | — | Funlabs 4X4 Off-road Adventure IIIFunlabs Cabelas BIG Game Hunter 2004 SeasonFunlabs Cabelas BIG Game Hunter 2005Funlabs Cabelas Dangerous Hunts+5 | 2/5/2005 | 16/6/2026 | Multiple games developed by FUN labs, including 4X4 Off-road Adventure III, Big Game Hunter, Dangerous Hunts, Deer Hunt, Revolution, Secret Service, Shadow Force, and US Most Wanted, allow remote attackers to cause a denial of service via an empty UDP packet to the server, which cannot detect that a new packet has… | |
| Modificada | Media (4.6) | 0.35% | — | Debian Shadow | 1/3/2005 | 16/6/2026 | Unknown vulnerability in the passwd_check function in Shadow 4.0.4.1, and possibly other versions before 4.0.5, allows local users to conduct unauthorized activities when an error from a pam_chauthtok function call is not properly handled. | |
| Modificada | Alta (7.5) | 1.6% | — | MOD Auth Shadow | 3/2/2004 | 16/6/2026 | The mod_auth_shadow module 1.4 and earlier does not properly enforce the expiration of a user account and password, which could allow remote authenticated users to bypass intended access restrictions. | |
| Modificada | Alta (7.5) | 2.1% | — | Nswc Cider Shadow | 15/3/2002 | 16/6/2026 | Multiple CGI scripts in CIDER SHADOW 1.5 and 1.6 allows remote attackers to execute arbitrary commands via certain form fields. | |
| Modificada | Media (5) | 1.9% | — | Shadow OP Software Dragon Server | 16/6/2000 | 16/6/2026 | Dragon FTP server allows remote attackers to cause a denial of service via a long USER command. | |
| Modificada | Media (5) | 4.6% | — | Shadow OP Software Dragon Server | 16/6/2000 | 16/6/2026 | Dragon telnet server allows remote attackers to cause a denial of service via a long username. |